About the Role
The IT Audit & SOX Compliance Analyst will be a key member of Hershey's Global Internal Audit team, supporting the organization's efforts to maintain a strong control environment, ensure SOX 404 compliance, and strengthen IT and cybersecurity risk management practices across global operations.
In this role, you will partner with business, finance, and IT stakeholders worldwide to assess the effectiveness of IT General Controls (ITGCs), application controls, cybersecurity controls, and financial reporting processes. You will participate in global audit engagements, control readiness assessments, SOX activities, and special projects related to technology risk, cybersecurity, and operational assurance.
This is a fully remote position based in the Philippines. Occasional office presence may be required when senior leadership or executive management visit the local office. The role follows a mid-shift schedule (2:00 PM to 11:00 PM) and may require up to 5% international travel.
Your Responsibilities
Support SOX 404 Compliance
- Execute SOX 404 testing for IT General Controls (ITGCs) and application controls across assigned business processes and functions.
- Partner with Internal Controls teams and business stakeholders to provide guidance on control execution, documentation quality, evidence requirements, and remediation plans.
- Support quarterly and annual SOX compliance activities, including walkthroughs, readiness reviews, management assistance requests, and coordination with external auditors.
- Serve as a resource for SOX enablement tools such as Workiva and ServiceNow, providing support and guidance to business users.
Perform Control Readiness Assessments
- Evaluate the readiness and effectiveness of key IT General Controls and application controls.
- Identify risks impacting financial reporting, governance, business continuity, cybersecurity, and regulatory compliance.
- Collaborate with IT and business stakeholders to understand processes, assess controls, communicate findings, and recommend practical remediation actions.
- Maintain audit project plans and provide timely updates on project progress, risks, and dependencies.
- Prepare concise, executive-level reporting to communicate key risks and recommended improvements.
Execute IT and Cybersecurity Audits
- Participate in global IT audit engagements, including infrastructure security, application security, vulnerability management, and cybersecurity reviews.
- Support Internal Audit's annual IT risk assessment process by identifying emerging technology and cybersecurity risks.
- Execute audit procedures using recognized frameworks such as COBIT, COSO, and NIST.
- Document audit work in accordance with IIA standards and internal audit methodology.
- Develop recommendations that strengthen controls and mitigate identified risks.
Provide Financial & Operational IT Assurance
- Assess the design and operating effectiveness of controls related to:
- User access management
- Segregation of duties
- Change management
- Operating system and database security
- Interface controls
- Data integrity and transmission controls
- Third-party service provider risk management
- Prepare audit findings and reports for management and senior leadership.
- Support special projects including cybersecurity assessments, system implementation reviews, third-party risk reviews, data analytics initiatives, and other management requests.
Your Background
Education
- Bachelor's Degree in Accounting, Information Technology, Information Systems, Computer Science, Cybersecurity, or a related field.
Experience
- Minimum of 2 years of experience in IT Audit, Cybersecurity Audit, IT Compliance, SOX 404 testing, Internal Audit, or related areas.
- Experience performing IT controls testing, risk assessments, audit procedures, and control evaluations.
- Exposure to system implementation reviews and enterprise technology environments is preferred.
Technical Skills
- Strong understanding of:
- IT General Controls (ITGCs)
- Application Controls
- SOX 404 compliance and testing
- Risk and control frameworks
- Working knowledge of COBIT, COSO, NIST, or similar frameworks.
- Experience with ERP systems such as SAP, Microsoft Dynamics, NetSuite, or similar platforms is an advantage.
- Ability to prepare audit documentation and communicate findings effectively.
Certifications
- Strong preference for CISA (Certified Information Systems Auditor).
- CPA (Certified Public Accountant) highly preferred.
- Additional certifications such as CIA, CRISC, or other relevant audit and risk credentials are advantageous.
Personal Attributes
- High integrity and strong professional ethics.
- Excellent communication and stakeholder management skills.
- Strong analytical thinking, problem-solving, and decision-making abilities.
- Ability to independently manage multiple priorities in a global environment.
- Strong collaboration and influencing skills with stakeholders across all organizational levels.
- Commitment to continuous learning and professional development.
- Flexibility to work in a mid-shift environment and support a global business.
Job Overview
This role performs assigned audit tasks and recurring processes that support the evaluation of financial, operational, and basic IT controls. The position follows established procedures to complete testing, gather evidence, and document results under general supervision. It identifies routine issues within defined audit areas and prepares clear, structured workpapers. The role contributes to audit planning and risk assessment by compiling information and supporting analysis.
Accountabilities
1. Execute Assigned Audit Testing Across Financial, Operational, and IT Controls
The role performs defined audit and SOX 404 testing steps by strictly following established procedures. It gathers evidence through walkthroughs and validation activities without modifying test design. It documents outcomes clearly to support senior reviewer evaluation.
2. Prepare Workpapers and Organize Documentation for Reviewer Evaluation
The role prepares accurate workpapers that detail testing performed, evidence obtained, and initial results. It identifies routine issues such as process deviations or missing documentation. It organizes materials to support the development of audit observations by senior team members.
3. Compile Data to Support Risk Assessments and Planning
The role collects data and performs preliminary reconciliation activities to support risk assessment of financial, operational, and IT processes. It identifies recurring issues or exceptions that may inform later stages of testing. It compiles information into structured formats for use by senior auditors in audit planning.
4. Assist With Fraud Detection and Compliance Testing Under Guidance
The role performs assigned steps to identify anomalies, exceptions, or deviations from compliance requirements. It flags potential indicators of fraud and escalates them to senior auditors for further evaluation. It documents findings to support additional testing or review.
5. Support Follow-Up and Remediation Validation Activities
The role assists with follow-up testing to determine whether corrective actions were implemented as designed. It follows established procedures to validate updated controls or processes within assigned areas. It summarizes results for senior team members to incorporate into broader remediation analyses.
Minimum Education & Requirements
1+ years




