General Summary
The IT SOX Compliance Senior Manager plays a critical role in ensuring that the Company’s IT environment maintains strong internal controls. This role is responsible for strategic leadership and oversight of the IT SOX compliance program as well as partnering with cross functional teams to mitigate risks.
This position requires working onsite in Alameda, California 80% of the time.
Specific Duties and Responsibilities
• Responsible for strategic leadership, oversight, and day-to-day management of the IT SOX compliance program. *
• Oversee IT risk assessment and scoping process to ensure alignment with financial reporting risks. *
• Review control documentation and collaborate with control owners to ensure execution of processes and documentation are adequate.
• Partner with internal audit, external audit, and control owners to coordinate ITGC and ITAC control testing and timely resolution of control related matters. *
• Support new systems implementations and technology changes to ensure SOX requirements are incorporated. *
• Provide training and guidance to IT control owners on SOX expectations, documentation standards, and audit readiness. *
• Identify opportunities to improve the sox program through automation, metrics, tools, and process improvements. *
• Adhere to the Company’s Quality Management System (QMS) as well as domestic and global quality system regulations, standards, and procedures. *
• Understand relevant security, privacy, and compliance principles and adhere to the regulations, standards, and procedures that are applicable to the Company. *
• Ensure other members of the department follow the QMS, regulations, standards, and procedures. *
• Perform other work-related duties as assigned.
*Indicates an essential function of the role
Position Qualifications
Minimum education and experience:
• Bachelor’s degree in accounting or information systems, with 8+ years' experience in IT SOX compliance, Information Security or IT Risk Management, or an equivalent combination of education and experience.
Preferred Qualifications:
• CISA, CIA, or CPA certification is strongly preferred
• Deep knowledge of SOX 404, ITGCs, ITACs, and COSO-based internal control frameworks
• Expertise in SAP environments, including knowledge of SAP Security and Basis
• Experience evaluating technology risk within a Big 4 public accounting firm preferred
• Experience implementing or managing GRC platforms
• Technical understanding of IT operations including cloud security architectures, DevOps practices, and complex logical access management
• Strong oral, written and interpersonal communication skills
• High degree of accuracy, attention to detail and strong problem-solving skills
Working Conditions
• General office environment
• Willingness and ability to work on site in Alameda, CA.
• May have business travel from 0-5%
• Requires some lifting and moving of up to 25 pounds
• Must be able to move between buildings and floors
• Must be able to remain stationary and use a computer or other standard office equipment, such as a printer or copy machine, for an extensive period of time each day
• Must be able to read, prepare emails, and produce documents and spreadsheets
• Must be able to move within the office and access file cabinets or supplies, as needed
• Must be able to communicate and exchange accurate information with employees at all levels on a daily basis
Annual Base Salary Range: $165,000 - $230,000
We offer a competitive compensation package plus a benefits and equity program, when
applicable. Individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location.
Skills Required
- Bachelor's degree in accounting or information systems (or equivalent)
- 8+ years' experience in IT SOX compliance, information security, or IT risk management
- Willingness and ability to work onsite in Alameda, CA approximately 80% of the time
- Deep knowledge of SOX 404, ITGCs, ITACs, and COSO internal control frameworks
- CISA, CIA, or CPA certification
- Expertise in SAP environments, including SAP Security and Basis
- Experience implementing or managing GRC platforms
- Experience evaluating technology risk at a Big Four public accounting firm
- Technical understanding of IT operations including cloud security architectures, DevOps practices, and complex logical access management
- Strong oral, written, and interpersonal communication skills
- High degree of accuracy, attention to detail, and strong problem-solving skills
- Ability to lift and move up to 25 pounds and move between buildings/floors
Penumbra Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Penumbra and has not been reviewed or approved by Penumbra.
-
Healthcare Strength — Company materials describe comprehensive medical, dental, and vision coverage with immediate eligibility, alongside life and disability insurance. Feedback suggests health coverage quality is a standout element of the package.
-
Parental & Family Support — Company sources indicate fully paid parental leave and on-site support for nursing parents in key locations. Feedback suggests family support policies compare favorably within med‑tech employers.
-
Leave & Time Off Breadth — Company postings outline paid holidays, sick leave, and vacation that increases with tenure. Feedback suggests time‑off provisions are broadly competitive when weighing total package value.
Penumbra Insights
What We Do
Penumbra, Inc., headquartered in Alameda, California, is a global healthcare company focused on innovative therapies. Penumbra designs, develops, manufactures and markets novel products and has a broad portfolio that addresses challenging medical conditions in markets with significant unmet need. Penumbra sells its products to hospitals and healthcare providers primarily through its direct sales organization in the United States, most of Europe, Canada and Australia, and through distributors in select international markets. The Penumbra logo is a trademark of Penumbra, Inc. Members of the Penumbra team agree that this is where their work has meaning -- we are transforming the treatment of some of the world's most devastating conditions. Penumbra is where everyone's ideas matter, and where learning and growth are constant.








