C-SOX Auditor (Calgary)

C-SOX Auditor (Calgary)

11 Aug
|
Johnson Service Group
|
Calgary

11 Aug

Johnson Service Group

Calgary

Job Overview: The C-SOX Auditor reports to the Lead Auditor, Internal Audit, who reports to the Director, Internal Audit.

The Director, Internal Audit reports functionally to the Audit Committee of the Board and administratively to the Vice-President, Finance and Compliance.

This reporting structure helps ensure the independence and objectivity of the Internal Audit function.

The C-SOX Auditor provides independent, risk-based, and objective assurance over the organization''s Internal Controls Over Financial Reporting (ICFR) as part of its annual C-SOX audit, with a focus on business controls and non-IT controls.

Must Haves: Professional CPA or CIA certification is required.

Post secondary education within Business or IT discipline. 8+ years of experience in internal audit or related governance , risk, and control roles with focus on non-IT controls. SOC, SOX, C-SOX or similar experience.

Robust knowledge and application of IIA Standards ; ability to conduct peer reviews.

Solid verbal and written communications skills.

Proven ability to resolve challenges proactively and prevent unnecessary escalation.

Proven ability to resolve challenges proactively, preventing unnecessary escalation.

Proficiency with technology to enhance audit efficiency e.g. data analysis Nice to Haves: CISA would be an asset.

Electricity Industry experience Experience with Workday, Service

Now Accountabilities include but are not limited to: Assess and document the design, implementation, and operating effectiveness of C-SOX controls for the 2026 audit period, including entity-level controls, expenditures, capital, payroll, operating reserves, revenue and settlements, credit, treasury, financial close and reporting, and relevant automated controls.

For each control, prepare complete design assessment documentation that clearly identifies: The financial reporting risk and relevant financial statement assertion.

The control objective and how the control addresses the identified risk.





The control owner and individuals responsible for performing and reviewing the control.

Whether the control is preventive or detective, and manual, automated or IT dependent.

The control frequency, timing, precision, thresholds and level of aggregation.

The reports, data, systems and other information used in performing the control.

The evidence retained to demonstrate performance and review.

The criteria used to conclude whether the control is appropriately designed.

Any control-design gaps, recommendations and management responses.

Confirm that each control has been implemented through inquiry, observation, inspection of supporting evidence and walkthroughs.

Document the transaction selected for the walkthrough from initiation through processing, recording and financial reporting.

Develop and document an operating-effectiveness testing plan for each control, including: Defined population and audit period.

Population completeness and accuracy procedures.

Sampling methodology and sample-size rationale.

Items selected and selection method.

Attributes and criteria tested.

Evidence inspected.

Test results and exceptions identified.

Additional or extended testing performed.

Final conclusion on operating effectiveness.

Coordinate with the IT auditor on IT change testing to ensure significant changes during the test period impacting business control design are included in the IT change testing.

If exceptions are noted in the completeness, accuracy and validity of information produced, coordinate recommendation(s)



with the IT auditor to address control deficiencies Prepare workpapers that meet internal audit methodology and applicable IIA Standards and contain sufficient, reliable, relevant, and useful evidence so that an experienced auditor with no previous connection to the work can understand and reperform the procedures and reach the same conclusion.

Cross-reference all risks, controls, procedures, samples, supporting evidence, exceptions and conclusions to the C-SOX risk and control matrix and supporting workpapers.

Identify and document all exceptions, including the nature, cause, frequency, affected population, financial reporting risk, and potential magnitude.

Assess whether exceptions represent isolated errors or control exceptions in accordance with established assessment ratings.

Discuss potential exceptions with the control performer, the Lead Auditor and control owner, while maintaining Internal Audits independent assessment and conclusion.

Obtain and document factual confirmation, management responses, remediation actions, accountable owners and target completion dates.

Coordinate with the Lead Auditor to ensure quality control over assigned workpapers, including evidence of preparer and reviewer sign-off, review-note clearance and timely resolution of documentation gaps.

Maintain the C-SOX status dashboard, showing planned and completed testing, outstanding information requests, exceptions, remediation status, overdue actions and controls at risk of not being completed within the reporting timetable.

Prepare clear summaries of control deficiencies, recurring issues, improvement opportunities, automation opportunities and matters requiring escalation to management.

Immediately escalate missing evidence, scope limitations, suspected management override, repeated exceptions, potential fraud indicators and matters that could affect managements certification. #LI-MS1

📌 C-SOX Auditor (Calgary)
🏢 Johnson Service Group
📍 Calgary

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: c-sox auditor (calgary) / calgary

Subscribe to this job alert:

Get the latest job offers by email for: c-sox auditor (calgary) / calgary