About this role
Job title: Lead Analyst - GRC
About the Role Lead Analyst - GRC will drive SOX scoping and IT risk assessments, ensuring financial systems and new SaaS implementations are evaluated for SOX impact. He/she will design, document, and operate IT General Controls (ITGCs) and coordinate monitoring across access, change, and operations controls. This role partners with management and audit teams to remediate issues and improve the IT control environment within Mattel’s GRC program.
What You'll Do
- Lead SOX scoping and IT risk assessments to ensure all financially relevant systems and tools, including new SaaS implementations, are appropriately identified and evaluated for SOX compliance impact.
- Design, document, and maintain effective IT General Controls (ITGCs) to mitigate financial reporting risk and strengthen the overall IT control environment.
- Coordinate control execution and perform ongoing monitoring activities across logical access controls, change management controls, and IT operations controls to ensure consistent performance, timely issue identification, and sustain compliance with SOX requirements.
- Partner closely with management, Internal Audit, and External Audit to support walkthroughs, control execution, issue resolution, and status reporting.
- Address IT control deficiencies by partnering with management to perform thorough root cause and impact analyses, and to develop, document, and drive remediation plans through timely completion.
- Provide ongoing training and advisory support to management and control owners on IT SOX compliance requirements, control execution standards, and best practices to strengthen accountability and enhance the overall effectiveness of the IT control environment.
- Recommend and implement process improvements to increase efficiency and reduce manual errors.
- Perform other duties as assigned or necessary.
What We're Looking For
- Demonstrated a growth mindset by staying curious and continuously learning, embracing challenges, and improving themselves.
- Bachelor’s degree preferred or equivalent experience
- 10+ years experience in IT Audit, Risk management, Compliance or Consulting (i.e. Big 4 or equivalent)
- In-depth knowledge of IT GRC platforms (e.g., AuditBoard).
- Professional certifications such as Certified Internal Auditor (CIA) and Certified Information Systems Auditor (CISA) are preferred and considered strong assets for the role.
- Good working knowledge of data quality frameworks, validation methods, and governance best practices.
- Soft Skills: Strong project management skills to lead IT risk assessments, drive stakeholder engagement, and effectively manage timelines, dependencies, and deliverables across multiple workstreams. Excellent communication skills, both written and verbal. Ability to work in a fast-paced and collaborative environment. Proven ability to manage a team with diverse skills and tenure. Self-motivating and independent.
Nice to Have
- Hands-on experience with SQL for data transformation and complex querying
- Experience with Agile Methodologies like Scrum and Kanban
- Python for scripting, data processing, and integration logic