Security Expert (SOX & Cloud)
PNC Financial Services Group
Position Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company's success. As a Security Expert within PNC's Security Ops organization, you will be based in Pittsburgh, PA or Dallas, TX or Houston, TX or Phoenix, AZ. Identity & Access Management (IAM) Governance Security Expert Lead - SOX & Cloud Overview
The IAM Governance Security Expert Lead is responsible for executing and enforcing identity governance controls in a SOX-regulated, cloud-first environment. This role focuses on hands-on operation of Identity Governance and Administration (IGA) tooling, access certification execution, Separation of Duties (SoD) enforcement, and audit-ready evidence production across cloud platforms and critical financial applications. The position works closely with Audit, Finance IT, IAM Engineering, and application owners to ensure access controls are compliant, consistent, and defensible. Key Responsibilities
Identity Governance & Administration (IGA) - Cloud-First
• Operate and administer the enterprise IGA platform integrated with cloud and SaaS systems.
• Execute and monitor joiner, mover, leaver processes with emphasis on audit traceability.
• Support automated provisioning and deprovisioning across Azure/Entra ID, AWS, GCP, and SaaS platforms.
• Maintain role-based and attribute-based access models for SOX in-scope applications.
• Conduct periodic access certifications for workforce, privileged, and service accounts.
• Validate identity and entitlement data accuracy across authoritative sources.
Separation of Duties (SoD) - SOX Focused
• Execute defined SoD rulesets for financial, ERP, and cloud administrative roles.
• Identify, analyze, and document SoD conflicts and violations.
• Track mitigations, compensating controls, and approved exceptions.
• Support proactive SoD reviews during role design, access requests, and onboarding.
• Partner with application owners to remediate recurring SoD issues.
SOX Controls, Audit & Compliance
• Execute IAM controls mapped to SOX IT General Controls (ITGCs).
• Produce audit-ready evidence for internal and external audits.
• Support audit walkthroughs, testing, and remediation activities.
• Maintain control narratives, procedures, and supporting documentation.
• Assist in annual SOX scoping and system coverage validation.
Cloud IAM & Privileged Access Governance
• Support governance of cloud administrative roles and high-risk entitlements.
• Validate alignment between IGA certifications and cloud IAM configurations.
• Assist with governance of non-human identities where in SOX scope.
• Monitor access changes affecting cloud-hosted financial systems.
Required Qualifications
• Bachelor's degree or equivalent experience in Information Security, IT, or related field.
• 5+ years of experience in IAM, Identity Governance, or ITGC execution.
• Hands-on experience with IGA platforms and access certifications.
• Strong understanding of SOX ITGC requirements related to user access and SoD.
• Experience supporting external audits and producing defensible evidence.
• Familiarity with cloud-based identity platforms and SaaS access models.
Preferred Qualifications
• Experience with ERP and financial systems (SAP, Oracle, Workday, NetSuite).
• IAM or security certifications (CISSP, CISM, CRISC, SailPoint, Saviynt).
• Exposure to privileged access governance in cloud environments.
• Understanding of zero trust and modern identity security principles.
Key Competencies
• SOX and audit discipline
• Attention to detail and execution rigor
• Clear documentation and evidence management
• Cross-functional collaboration
• Influence through subject-matter expertise PNC is an in-office company that fosters a supportive culture where employees can thrive and achieve balance. We encourage candidates to connect with their recruiter and hiring manager to understand workplace expectations and ensure the role aligns with their goals. PNC will not provide sponsorship for employment visas or participate in STEM OPT for this position. Job Description
Access Control (AC), AI Agents, Building Architecture, Cloud Security, Customer Solutions, Disaster Recovery Planning, Information Security, Network Security, Physical Security, Risk Assessments, Security Technologies Competencies
Analytical Thinking, Effective Communications, Information Security Management, Information Security Technologies, IT Environment, IT Standards, Procedures & Policies, Knowledge of Organization, Problem Solving Work Experience
Roles at this level typically require a university / college degree. Higher level education such as a Masters degree, or PhD is desirable. Industry experience is typically 8 + years. Specific certifications are often required. In lieu of a degree, a comparable combination of education, job specific certification(s), and experience (including military service) may be considered. Education
Bachelors Certifications
No Required Certification(s) Licenses
No Required License(s) Benefits PNC offers a comprehensive range of benefits to help meet your needs now and in the future. Depending on your eligibility, options for full-time employees include: medical/prescription drug coverage (with a Health Savings Account feature), dental and vision options; employee and spouse/child life insurance; short and long-term disability protection; 401(k) with PNC match, pension and stock purchase plans; dependent care reimbursement account; back-up child/elder care; adoption, surrogacy, and doula reimbursement; educational assistance, including select programs fully paid; a robust wellness program with financial incentives. In addition, PNC generally provides the following paid time off, depending on your eligibility: maternity and/or parental leave; up to 11 paid holidays each year; 9 occasional absence days each year, unless otherwise required by law; between 15 to 25 vacation days each year, depending on career level; and years of service. To learn more about these and other programs, including benefits for full time and part-time employees, visit pncthrive.com. Disability Accommodations Statement If an accommodation is required to participate in the application process, please contact us via email at View email address on click.appcast.io. Please include "accommodation request" in the subject line title and be sure to include your name, the job ID, and your preferred method of contact in the body of the email. Emails not related to accommodation requests will not receive responses. Applicants may also call View phone number on click.appcast.io and say "Workday" for accommodation assistance. All information provided will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
At PNC we foster an inclusive and accessible workplace. We provide reasonable accommodations to employment applicants and qualified individuals with a disability who need an accommodation to perform the essential functions of their positions. Equal Employment Opportunity (EEO) PNC provides equal employment opportunity to qualified persons regardless of race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, veteran status, or other categories protected by law. This position is subject to the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA) and, for any registered role, the Secure and Fair Enforcement for Mortgage Licensing Act of 2008 (SAFE Act) and/or the Financial Industry Regulatory Authority (FINRA), which prohibit the hiring of individuals with certain criminal history. California Residents Refer to the California Consumer Privacy Act Privacy Notice to gain understanding of how PNC may use or disclose your personal information in our hiring practices.
The IAM Governance Security Expert Lead is responsible for executing and enforcing identity governance controls in a SOX-regulated, cloud-first environment. This role focuses on hands-on operation of Identity Governance and Administration (IGA) tooling, access certification execution, Separation of Duties (SoD) enforcement, and audit-ready evidence production across cloud platforms and critical financial applications. The position works closely with Audit, Finance IT, IAM Engineering, and application owners to ensure access controls are compliant, consistent, and defensible. Key Responsibilities
Identity Governance & Administration (IGA) - Cloud-First
• Operate and administer the enterprise IGA platform integrated with cloud and SaaS systems.
• Execute and monitor joiner, mover, leaver processes with emphasis on audit traceability.
• Support automated provisioning and deprovisioning across Azure/Entra ID, AWS, GCP, and SaaS platforms.
• Maintain role-based and attribute-based access models for SOX in-scope applications.
• Conduct periodic access certifications for workforce, privileged, and service accounts.
• Validate identity and entitlement data accuracy across authoritative sources.
Separation of Duties (SoD) - SOX Focused
• Execute defined SoD rulesets for financial, ERP, and cloud administrative roles.
• Identify, analyze, and document SoD conflicts and violations.
• Track mitigations, compensating controls, and approved exceptions.
• Support proactive SoD reviews during role design, access requests, and onboarding.
• Partner with application owners to remediate recurring SoD issues.
SOX Controls, Audit & Compliance
• Execute IAM controls mapped to SOX IT General Controls (ITGCs).
• Produce audit-ready evidence for internal and external audits.
• Support audit walkthroughs, testing, and remediation activities.
• Maintain control narratives, procedures, and supporting documentation.
• Assist in annual SOX scoping and system coverage validation.
Cloud IAM & Privileged Access Governance
• Support governance of cloud administrative roles and high-risk entitlements.
• Validate alignment between IGA certifications and cloud IAM configurations.
• Assist with governance of non-human identities where in SOX scope.
• Monitor access changes affecting cloud-hosted financial systems.
Required Qualifications
• Bachelor's degree or equivalent experience in Information Security, IT, or related field.
• 5+ years of experience in IAM, Identity Governance, or ITGC execution.
• Hands-on experience with IGA platforms and access certifications.
• Strong understanding of SOX ITGC requirements related to user access and SoD.
• Experience supporting external audits and producing defensible evidence.
• Familiarity with cloud-based identity platforms and SaaS access models.
Preferred Qualifications
• Experience with ERP and financial systems (SAP, Oracle, Workday, NetSuite).
• IAM or security certifications (CISSP, CISM, CRISC, SailPoint, Saviynt).
• Exposure to privileged access governance in cloud environments.
• Understanding of zero trust and modern identity security principles.
Key Competencies
• SOX and audit discipline
• Attention to detail and execution rigor
• Clear documentation and evidence management
• Cross-functional collaboration
• Influence through subject-matter expertise PNC is an in-office company that fosters a supportive culture where employees can thrive and achieve balance. We encourage candidates to connect with their recruiter and hiring manager to understand workplace expectations and ensure the role aligns with their goals. PNC will not provide sponsorship for employment visas or participate in STEM OPT for this position. Job Description
- Provides technical and thought leadership, analysis, and guidance in multiple security disciplines. Supports activities, process, and tools needed to improve overall security posture of the organization. Provides unique subject matter expertise.
- Reviews and defines controls, aligning the controls of a specific Security area to the enterprise framework. Devises control implementation strategy.
- Advises on more complex security procedures and products for clients, security administrators and network operations. Participates in enforcement of control security risks and threats; potential of one more controls subject to manager discretion. Shares knowledge with staff.
- Conducts security assessments and other information security routines consistently. Investigates and recommends corrective actions for data security related to established guidelines.
- Develops policies and procedures to standardize security functions and eliminate potential vulnerabilities and threats. Oversees that business needs are being met during development.
- Shares knowledge, leads and mentors are the discretion of management.
- Customer Focused - Knowledgeable of the values and practices that align customer needs and satisfaction as primary considerations in all business decisions and able to leverage that information in creating customized customer solutions.
- Managing Risk - Assessing and effectively managing all of the risks associated with their business objectives and activities to ensure they adhere to and support PNC's Enterprise Risk Management Framework.
Access Control (AC), AI Agents, Building Architecture, Cloud Security, Customer Solutions, Disaster Recovery Planning, Information Security, Network Security, Physical Security, Risk Assessments, Security Technologies Competencies
Analytical Thinking, Effective Communications, Information Security Management, Information Security Technologies, IT Environment, IT Standards, Procedures & Policies, Knowledge of Organization, Problem Solving Work Experience
Roles at this level typically require a university / college degree. Higher level education such as a Masters degree, or PhD is desirable. Industry experience is typically 8 + years. Specific certifications are often required. In lieu of a degree, a comparable combination of education, job specific certification(s), and experience (including military service) may be considered. Education
Bachelors Certifications
No Required Certification(s) Licenses
No Required License(s) Benefits PNC offers a comprehensive range of benefits to help meet your needs now and in the future. Depending on your eligibility, options for full-time employees include: medical/prescription drug coverage (with a Health Savings Account feature), dental and vision options; employee and spouse/child life insurance; short and long-term disability protection; 401(k) with PNC match, pension and stock purchase plans; dependent care reimbursement account; back-up child/elder care; adoption, surrogacy, and doula reimbursement; educational assistance, including select programs fully paid; a robust wellness program with financial incentives. In addition, PNC generally provides the following paid time off, depending on your eligibility: maternity and/or parental leave; up to 11 paid holidays each year; 9 occasional absence days each year, unless otherwise required by law; between 15 to 25 vacation days each year, depending on career level; and years of service. To learn more about these and other programs, including benefits for full time and part-time employees, visit pncthrive.com. Disability Accommodations Statement If an accommodation is required to participate in the application process, please contact us via email at View email address on click.appcast.io. Please include "accommodation request" in the subject line title and be sure to include your name, the job ID, and your preferred method of contact in the body of the email. Emails not related to accommodation requests will not receive responses. Applicants may also call View phone number on click.appcast.io and say "Workday" for accommodation assistance. All information provided will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
At PNC we foster an inclusive and accessible workplace. We provide reasonable accommodations to employment applicants and qualified individuals with a disability who need an accommodation to perform the essential functions of their positions. Equal Employment Opportunity (EEO) PNC provides equal employment opportunity to qualified persons regardless of race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, veteran status, or other categories protected by law. This position is subject to the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA) and, for any registered role, the Secure and Fair Enforcement for Mortgage Licensing Act of 2008 (SAFE Act) and/or the Financial Industry Regulatory Authority (FINRA), which prohibit the hiring of individuals with certain criminal history. California Residents Refer to the California Consumer Privacy Act Privacy Notice to gain understanding of how PNC may use or disclose your personal information in our hiring practices.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Expert (SOX & Cloud) in Pittsburgh, PA vacancy
- ...engineering, data modeling, or similar roles. Expert-level SQL skills (optimization &... ...schemas, one big table). Experience with cloud data warehouses (Snowflake, BigQuery, Redshift... ..., privacy, compliance (GDPR, CCPA, SOX). Familiarity with BI tools (Tableau, Looker...CloudRemote work
- ...Vertilocity Job Description Job Title: Security Analyst Overview of position: We are seeking a dynamic and experienced Security... ...files, folder structure, email from backup tools Local and cloud virtualization of backups to validate restoration works and...CloudLocal area
- ...Job Title Security Analyst Job Description The most security-conscious organizations trust Telos Corporation to protect their... ...what you can bring to our solutions in the areas of cyber, cloud and enterprise security. Be a part of the Telos culture and...CloudFull timeLocal areaImmediate start
- ...interest in learning technologies such as: Artificial Intelligence & Machine Learning (e.g., generative AI, predictive analytics); Cloud Computing Platforms (e.g., AWS, Azure, Google Cloud); Blockchain & Distributed Ledger Technologies; Data Engineering & Analytics Tools...CloudWork at officeRemote work
- ...Azure Security Specialist Location: Pittsburgh, PA Position Type: Contract Rate: DOE US Citizen, Green Card, TN, GC EAD and... ...Service Identities, Azure AD, Azure AD B2C, Open ID Connect Cloud Security – Azure Key Vault, HSTS, SSL/TLS Ingress Control, Certificate...CloudContract work
- ...Job Description Title: Sr. IT Security Analyst Reports To: Director, IT Security Operations Location: Pittsburgh, PA... ...perform cybersecurity monitoring of American Eagle Outfitter's cloud environments ensuring proper monitoring coverage that correlates...CloudFull timePart timeWork experience placementSummer workCasual workWork at officeLocal area
$178.3k - $407k
...tech consulting services in artificial intelligence, big data and cloud engineering. We always support and enable big ideas with the... ...production. Familiarity with regulated-industry constraints (SOX, HIPAA, GDPR) and how AI design interacts with audit, retention,...CloudSummer holidayFlexible hours- ...Administrator • Duties and responsibilities include, but are not limited to, the following: • Deploy and maintain Azure resources and other cloud technologies in support of enterprise applications. • Implementation and support for PaaS services • Azure Data Factory ARM...CloudContract work
- ...organization, including data center networking, virtualization, and cloud computing. Configuring and managing network devices such as routers, switches, and firewalls. Implementing network security measures to protect the organization's data and ensure compliance...CloudContract work
- ...Databricks for advanced data processing and analytics, and Terraform for infrastructure automation and management. Familiarity with cloud-based environments, version control systems, and CI pipelines will further enhance your ability to deliver high-quality solutions. Experience...CloudRemote work
- ...critical applications. Your day-to-day tasks will involve managing cloud resources, orchestrating continuous integration and delivery... ...operations teams, as well as a track record of implementing scalable and secure solutions, will position you to make a significant impact in...CloudRemote work
- ...Build, configure, and optimize Databricks environments across cloud platforms (AWS, Azure, or GCP) Develop migration strategies from... ...Spark, Delta Lake, and related ecosystem tools Establish security, governance, and performance best practices Troubleshoot complex...CloudImmediate start
- ...ML Engineer to lead development of enterprise-grade AI and GenAI solutions. This role bridges data engineering, ML engineering, and cloud architecture to deliver scalable AI systems. Key Responsibilities: ~ Build and scale ML pipelines and GenAI applications ~...CloudFull timeContract workRemote work
- ...is focused on on-prem systems, with some exposure to hybrid and cloud environments. Deep cloud migration experience is not required.... ...Infrastructure • Availability • Automation • Integration • Security • Windows • Documentation • Maintenance • Engineering...Cloud
- ...-performance, customer service-oriented work environment Responsible for the vision, design, installation, and administration of cloud computing and data storage resources and related management software in support of data intensive global operations specifications...Cloud
- ...IAM), Unity Catalog, secret scopes, audit logging, and network/security configuration within Databricks. • Experience managing large-... ...Azure DevOps, GitHub Actions, or Jenkins. • Working knowledge of cloud platforms (Azure/AWS/GCP), including networking concepts like...Cloud
- ...complex business challenges. Our services span AI, IT staffing, cloud computing, engineering, mobility, testing, and more. Certified... ...Level 3 and ISO standards, V2Soft is committed to quality and security. Beyond our work, we actively support local communities and non...CloudLocal areaWorldwide
- ...incorporated into applications and used internally for business development. ~ Work with the Cloud Architecture team and other stakeholders to ensure the ongoing security and confidentiality of sensitive healthcare information. ~ Work with the Executive,...CloudFull time
$125.5k - $230.2k
...Engineering to lead our team in designing and implementing complex cloud analytics solutions with a strong focus on Databricks. The... ...that drive business value. Ensure the quality, integrity, and security of data throughout the data lifecycle, implementing best...CloudSummer holidayFlexible hours- ...Implement data governance, quality, and security best practices within the data platform.... ...Engineer with a strong focus on data. ~ Expert-level proficiency in Scala for data processing... ...and manipulation. ~ Experience with cloud platforms (AWS, Azure, GCP) and their...Cloud
$106.9k - $176.5k
...highly skilled Senior Consultant Data Engineer with expertise in cloud data engineering, specifically Databricks. The ideal candidate... ..., and storage. Ensure data quality, integrity, and security throughout the data lifecycle. Provide technical guidance and...CloudSummer holidayFlexible hours- ...Arista Networks is an industry leader in data-driven, client-to-cloud networking for large data center, campus and routing... ...Monitoring Fabric and Network Detection & Response (NDR) and End Point Security solutions. Meet with key influencers, decision-makers, and C...Cloud
$125.5k - $230.2k
...Data Architect – Manager, you will have an expert understanding of data architecture and... ...Technical Skills Applications Integration Cloud Computing and Cloud Computing... ...governance policies and practices, including data security, quality, and lifecycle management. Stay...CloudSummer holidayFlexible hours- ...building and optimizing scalable data solutions within a modern cloud-based big data environment. This role focuses on designing high... .../Kimball) Ensure data quality, integrity, governance, and security across the data platform Technical Qualifications ~10+...CloudFull timeContract work3 days per week
- ...systems data) Integrate data from different sources (databases, clouds or on-premises) and Engineer workflows for efficient ETL/ELT... ...data infrastructure in compliance with data governance and security best practices Requirements Bachelor's degree in computer...Cloud
- ...around platform reliability, automation, performance tuning, and security. Platform Administration & Engineering Oversee end-to-end... ..., and related database ecosystems. Hands-on experience with cloud data platforms such as Azure Data Lake, Synapse Analytics,...Cloud
- ...Engineer, you will work independently or as part of a team to deliver cloud-based technology solutions across products, projects, and... ...new features for digital products. • Own the maintenance and security of existing solutions, platforms, and frameworks; design new...Cloud
- ...powers our baseball operations and enterprise systems. The reliable, secure, and scalable solutions you build will enable our analysts, data... ...to work efficiently and confidently from the clubhouse to the cloud. You will work to ensure our systems are always available,...CloudWork at office
- ...strategy of the enterprise data platform while ensuring reliable, secure, and scalable day-to-day operations. This role combines deep... ...system design reviews. Guide engineering best practices. Drive cloud cost-optimization efforts. Partner with business leaders to...CloudFor contractorsVisa sponsorshipWork visaFlexible hours
- ...organization. If you enjoy working with large datasets, modern cloud tools, and solving complex data challenges, this is a chance to... ...concepts ~ Understanding of cloud cost optimization, security, and access control best practices Benefits ~ Medical,...CloudRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Expert (SOX & Cloud). Be the first to apply!
Related searches
- network security consultant Pittsburgh, PA
- security specialist Pittsburgh, PA
- security systems specialist Pittsburgh, PA
- security coordinator Pittsburgh, PA
- security consultant Pittsburgh, PA
- entry level security analyst Pittsburgh, PA
- security advisor Pittsburgh, PA
- entry level information security analyst Pittsburgh, PA
- security analyst remote Pittsburgh, PA
- senior information security analyst Pittsburgh, PA


