Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Expert (SOX & Cloud)

PNC Financial Services Group

Position Overview

At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company's success. As a Security Expert within PNC's Security Ops organization, you will be based in Pittsburgh, PA or Dallas, TX or Houston, TX or Phoenix, AZ.

Identity & Access Management (IAM) Governance Security Expert Lead - SOX & Cloud

Overview
The IAM Governance Security Expert Lead is responsible for executing and enforcing identity governance controls in a SOX-regulated, cloud-first environment. This role focuses on hands-on operation of Identity Governance and Administration (IGA) tooling, access certification execution, Separation of Duties (SoD) enforcement, and audit-ready evidence production across cloud platforms and critical financial applications. The position works closely with Audit, Finance IT, IAM Engineering, and application owners to ensure access controls are compliant, consistent, and defensible.

Key Responsibilities
Identity Governance & Administration (IGA) - Cloud-First
• Operate and administer the enterprise IGA platform integrated with cloud and SaaS systems.
• Execute and monitor joiner, mover, leaver processes with emphasis on audit traceability.
• Support automated provisioning and deprovisioning across Azure/Entra ID, AWS, GCP, and SaaS platforms.
• Maintain role-based and attribute-based access models for SOX in-scope applications.
• Conduct periodic access certifications for workforce, privileged, and service accounts.
• Validate identity and entitlement data accuracy across authoritative sources.
Separation of Duties (SoD) - SOX Focused
• Execute defined SoD rulesets for financial, ERP, and cloud administrative roles.
• Identify, analyze, and document SoD conflicts and violations.
• Track mitigations, compensating controls, and approved exceptions.
• Support proactive SoD reviews during role design, access requests, and onboarding.
• Partner with application owners to remediate recurring SoD issues.
SOX Controls, Audit & Compliance
• Execute IAM controls mapped to SOX IT General Controls (ITGCs).
• Produce audit-ready evidence for internal and external audits.
• Support audit walkthroughs, testing, and remediation activities.
• Maintain control narratives, procedures, and supporting documentation.
• Assist in annual SOX scoping and system coverage validation.
Cloud IAM & Privileged Access Governance
• Support governance of cloud administrative roles and high-risk entitlements.
• Validate alignment between IGA certifications and cloud IAM configurations.
• Assist with governance of non-human identities where in SOX scope.
• Monitor access changes affecting cloud-hosted financial systems.
Required Qualifications
• Bachelor's degree or equivalent experience in Information Security, IT, or related field.
• 5+ years of experience in IAM, Identity Governance, or ITGC execution.
• Hands-on experience with IGA platforms and access certifications.
• Strong understanding of SOX ITGC requirements related to user access and SoD.
• Experience supporting external audits and producing defensible evidence.
• Familiarity with cloud-based identity platforms and SaaS access models.
Preferred Qualifications
• Experience with ERP and financial systems (SAP, Oracle, Workday, NetSuite).
• IAM or security certifications (CISSP, CISM, CRISC, SailPoint, Saviynt).
• Exposure to privileged access governance in cloud environments.
• Understanding of zero trust and modern identity security principles.
Key Competencies
• SOX and audit discipline
• Attention to detail and execution rigor
• Clear documentation and evidence management
• Cross-functional collaboration
• Influence through subject-matter expertise

PNC is an in-office company that fosters a supportive culture where employees can thrive and achieve balance. We encourage candidates to connect with their recruiter and hiring manager to understand workplace expectations and ensure the role aligns with their goals.

PNC will not provide sponsorship for employment visas or participate in STEM OPT for this position.

Job Description
  • Provides technical and thought leadership, analysis, and guidance in multiple security disciplines. Supports activities, process, and tools needed to improve overall security posture of the organization. Provides unique subject matter expertise.
  • Reviews and defines controls, aligning the controls of a specific Security area to the enterprise framework. Devises control implementation strategy.
  • Advises on more complex security procedures and products for clients, security administrators and network operations. Participates in enforcement of control security risks and threats; potential of one more controls subject to manager discretion. Shares knowledge with staff.
  • Conducts security assessments and other information security routines consistently. Investigates and recommends corrective actions for data security related to established guidelines.
  • Develops policies and procedures to standardize security functions and eliminate potential vulnerabilities and threats. Oversees that business needs are being met during development.
  • Shares knowledge, leads and mentors are the discretion of management.
PNC Employees take pride in our reputation and to continue building upon that we expect our employees to be:
  • Customer Focused - Knowledgeable of the values and practices that align customer needs and satisfaction as primary considerations in all business decisions and able to leverage that information in creating customized customer solutions.
  • Managing Risk - Assessing and effectively managing all of the risks associated with their business objectives and activities to ensure they adhere to and support PNC's Enterprise Risk Management Framework.

Qualifications

Successful candidates must demonstrate appropriate knowledge, skills, and abilities for a role. Listed below are skills, competencies, work experience, education, and required certifications/licensures needed to be successful in this position.

Preferred Skills
Access Control (AC), AI Agents, Building Architecture, Cloud Security, Customer Solutions, Disaster Recovery Planning, Information Security, Network Security, Physical Security, Risk Assessments, Security Technologies

Competencies
Analytical Thinking, Effective Communications, Information Security Management, Information Security Technologies, IT Environment, IT Standards, Procedures & Policies, Knowledge of Organization, Problem Solving

Work Experience
Roles at this level typically require a university / college degree. Higher level education such as a Masters degree, or PhD is desirable. Industry experience is typically 8 + years. Specific certifications are often required. In lieu of a degree, a comparable combination of education, job specific certification(s), and experience (including military service) may be considered.

Education
Bachelors

Certifications
No Required Certification(s)

Licenses
No Required License(s)

Benefits

PNC offers a comprehensive range of benefits to help meet your needs now and in the future. Depending on your eligibility, options for full-time employees include: medical/prescription drug coverage (with a Health Savings Account feature), dental and vision options; employee and spouse/child life insurance; short and long-term disability protection; 401(k) with PNC match, pension and stock purchase plans; dependent care reimbursement account; back-up child/elder care; adoption, surrogacy, and doula reimbursement; educational assistance, including select programs fully paid; a robust wellness program with financial incentives.

In addition, PNC generally provides the following paid time off, depending on your eligibility: maternity and/or parental leave; up to 11 paid holidays each year; 9 occasional absence days each year, unless otherwise required by law; between 15 to 25 vacation days each year, depending on career level; and years of service.

To learn more about these and other programs, including benefits for full time and part-time employees, visit pncthrive.com.

Disability Accommodations Statement

If an accommodation is required to participate in the application process, please contact us via email at View email address on click.appcast.io. Please include "accommodation request" in the subject line title and be sure to include your name, the job ID, and your preferred method of contact in the body of the email. Emails not related to accommodation requests will not receive responses. Applicants may also call View phone number on click.appcast.io and say "Workday" for accommodation assistance. All information provided will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.


At PNC we foster an inclusive and accessible workplace. We provide reasonable accommodations to employment applicants and qualified individuals with a disability who need an accommodation to perform the essential functions of their positions.

Equal Employment Opportunity (EEO)

PNC provides equal employment opportunity to qualified persons regardless of race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, veteran status, or other categories protected by law.

This position is subject to the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA) and, for any registered role, the Secure and Fair Enforcement for Mortgage Licensing Act of 2008 (SAFE Act) and/or the Financial Industry Regulatory Authority (FINRA), which prohibit the hiring of individuals with certain criminal history.

California Residents

Refer to the California Consumer Privacy Act Privacy Notice to gain understanding of how PNC may use or disclose your personal information in our hiring practices.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Security Expert (SOX & Cloud) in Houston, TX vacancy
  • Heath-Consultants-Incorporate in Houston, TX is seeking a Senior Cloud Security Engineer to enhance cybersecurity across cloud and hybrid environments. This role involves designing and implementing security controls, securing Azure workloads, and managing IAM solutions... 
    Cloud

    Heath-Consultants-Incorporate

    Houston, TX
    3 days ago
  • $118.7k - $218.6k

    Cloud Security Architect - Senior Consultant Deloitte & Touche LLP is seeking a Cloud Security Architect (Senior Consultant) located in Houston...  ...01, ISO27018, NIST CSF, NIST800‑53, PCIDSS, SOC2, HIPAA, PCI, SOX, GLBA. Information for Applicants with a Need for... 
    Cloud
    Part time
    Work experience placement
    Visa sponsorship

    Itlearn360

    Houston, TX
    3 days ago
  •  ...IT Security & Compliance Analyst The IT Security & Compliance Analyst supports and operationalizes...  ...security events using SIEM, EDR, email, cloud, and endpoint security tools....  ...Support internal and external audits including SOX ITGC, ISO 27001, NIST CSF, NIST 800-171,... 
    Cloud

    Bristow Group

    Houston, TX
    14 days ago
  • $105k - $160k

     ...Azure Security Engineer Work with a top 20 CPA and advisory firm that accounts for anything...  .... Be the go-to Microsoft security expert on a team that values innovation and expertise...  ...a recognized leader in government and cloud security (FedRAMP 3PAO, CMMC C3PAO,... 
    Cloud
    Full time
    Work at office
    Local area
    Remote work
    Flexible hours

    Aprio

    Houston, TX
    6 days ago
  •  ...consulting firm specializing in software security and is the global leader in helping organizations...  ..., mobile application security, and cloud services aimed at addressing the...  ...end-to-end software security program, our expert consultants have both the depth of knowledge... 
    Cloud
    Local area
    Worldwide

    IPsoft Inc.

    Houston, TX
    1 day ago
  •  ...skills , and a proven track record in SOX controls , Change Management , and enterprise...  ...role will partner closely with business, security, compliance, and Data engineering teams...  ...modernization initiatives including cloud migration and platform consolidation.... 
    Cloud
    Immediate start
    Remote work
    Worldwide

    Wesco

    Houston, TX
    5 days ago
  •  ...Description: Architects and manage the Azure cloud infrastructure for end user device...  ...privacy and integrity. Ensure consistent, secure, reliable, resilient cloud services are available...  ...: Serve as a cloud solution expert during engagement with stakeholders.... 
    Cloud

    United IT Solutions

    Houston, TX
    2 days ago
  •  ...Job Title: Senior Security Analyst Contract Type: Time Type: Job Description: The Senior Security Analyst is a...  ...activities, and contributes to the secure rollout of the Group's multi-cloud strategy (e.g. Azure, AWS). Operating at the center of a... 
    Cloud
    Contract work

    Gunvor

    Houston, TX
    4 days ago
  •  ...global trading company located in Houston is seeking a Senior Security Analyst to lead cybersecurity efforts that protect critical trading...  ...8+ years in cybersecurity, with significant experience in cloud security, incident response, and security engineering. The ideal... 
    Cloud

    Gunvor Group

    Houston, TX
    4 days ago
  •  ...Central About the Job: Full Time Job Function The Linux Security Analyst is an onsite role at our Houston office. This role will...  .... ~ Knowledge of fundamental security practices in networks, cloud, and endpoints. ~ Awareness of compliance frameworks (ISO 270... 
    Cloud
    Full time
    Temporary work
    Work experience placement
    Work at office
    Local area

    Foxconn Industrial Internet

    Houston, TX
    2 days ago
  •  ...Job Title: Senior Security Analyst Location: Houston, TX (Hybrid 4:1) Reports To: IT...  ...we embrace an entrepreneurial spirit; as Experts in Tomorrow, we anticipate what's next; and...  ...stakeholders. Experience with cloud IR, logging, and detection. Additional... 
    Cloud
    Full time
    Local area

    Tokio Marine HCC

    Houston, TX
    4 days ago
  •  ...Central About the Job: Full Time Job Function The IT Security Analyst supports the protection of enterprise systems, networks...  ...Support daily security operations across network, endpoint, and cloud environments. Assist with the administration of firewalls,... 
    Cloud
    Full time
    Temporary work
    Work experience placement
    Local area

    Foxconn Industrial Internet

    Houston, TX
    14 hours ago
  • Gunvor USA LLC is seeking a Senior Security Analyst in Houston to lead cybersecurity initiatives and ensure operational resilience in a...  ...environment. This role emphasizes advanced threat detection and cloud security. The ideal candidate will have over 8 years of... 
    Cloud

    Gunvor USA LLC

    Houston, TX
    3 days ago
  •  ...About the Job: Full Time Job Function The Senior IT Security Analyst is responsible for safeguarding enterprise systems, networks...  ...operations, including monitoring of network, endpoint, and cloud environments. Administer and support enterprise network security... 
    Cloud
    Full time
    Temporary work
    For contractors
    Work experience placement
    Local area

    Foxconn Industrial Internet

    Houston, TX
    2 days ago
  •  ...OT Security Analyst We're hiring for an OT Security Analyst to work out of our Corporate Office in Houston while working a Hybrid work...  ...Analyst implements security systems in on-premises and cloud OT networks. Key duties include assessing current measures, network... 
    Cloud
    Contract work
    For contractors
    Work at office
    Worldwide

    Noble Corporation

    Houston, TX
    a month ago
  •  ...Senior Ot Security Analyst We're hiring a Senior OT Security Analyst to work at our Corporate...  ...systems for both on-premises and cloud OT networks. Key duties include assessing...  ...vulnerabilities, participating in projects to provide expert security guidance, and responding quickly... 
    Cloud
    Contract work
    For contractors
    Work at office
    Worldwide

    Noble Corporation

    Houston, TX
    2 days ago
  •  ...Security Analyst This role requires daily onsite attendance in Houston. Remote work and visa sponsorship are not available. Join...  ...experience (multi-tenant environments, ticket-driven workflows) Cloud security exposure (Azure, AWS, M365 security stack)... 
    Cloud
    Remote work
    Day shift

    Datavox

    Houston, TX
    23 days ago
  •  ...Purpose: We are seeking a highly skilled and motivated IT Security Analyst with a minimum of five years of professional...  ...solutions, including Cisco AMP/Secure Endpoint, Umbrella, Duo, and Cloud Email Security Appliances. Leverage Cylance to detect, investigate... 
    Cloud
    Work at office
    Immediate start
    Flexible hours

    ManhattanLife

    Jersey Village, TX
    14 hours ago
  •  ...NAVA Software solutions is looking for a Security & Infrastructure Manager Details:...  ...position will focus heavily on Microsoft Azure cloud infrastructure, Microsoft 365/O365 tenant...  ...solutions, and ensuring adherence to SOX and NIST CSF 2.0 frameworks. Core... 
    Cloud
    Contract work
    Work at office
    Remote work

    Nava Software Solutions

    Houston, TX
    1 day ago
  •  ...stations. CCSS is an app is on prem and we are moving it to Azure cloud. (Data Lake, Data Bricks, Tableau- Full Stack) ~ Tier 1...  ...can morph their career in a number of paths such as No SQL Expert, Cloud Computing expert, or Big Data architect. Any gaps will be... 
    Cloud

    Netorbit

    Houston, TX
    3 days ago
  • Microsoft Security Analyst Attractivate Consulting Solutions Location: Remote/Hybrid About Us: Attractivate Consulting Solutions specializes...  ...Knowledge of compliance frameworks (NIST, ISO 27001) Cloud security experience (AWS, GCP) CMMC knowledge and experience... 
    Cloud
    Remote work

    Attractivate Consulting Solutions

    Houston, TX
    14 hours ago
  •  ...Job Title : Lead Cloud Engineer Location : Houston, TX Job Description: Architects...  ...and integrity. Ensure consistent, secure, reliable, resilient cloud services are available...  ...: • Serve as a cloud solution expert during engagement with stakeholders. •... 
    Cloud
    Work experience placement

    United IT Solutions

    Houston, TX
    2 days ago
  • Security Operations Center (SOC) - IT Security & Compliance Role Overview The Cybersecurity Analyst is a member of the IT Security & Compliance...  ...events across the organization’s hybrid on-premises and cloud environments. This role focuses on detection, analysis, and... 
    Cloud

    The Jupiter Group, Inc

    Houston, TX
    3 days ago
  • $18.5 per hour

     ...remaining at the forefront of innovation. Every day, we work to secure what our clients value most, from their families to their assets...  ...their reputation to their networks, and from their money to their cloud. As the 3rd largest security services provider, our 175k+ team... 
    Cloud
    Hourly pay
    Full time
    Temporary work
    For contractors
    Remote work
    All shifts

    Prosegur Security USA

    Houston, TX
    1 day ago
  • Senior Manager, Information Security Reporting to the Head of Information Security & Governance...  ..., including information technology, cloud operations, product engineering, processional...  ...security and compliance including SOX and SSAE 16, ISO 27001/2, and PCI. Solid... 
    Cloud
    Work at office
    Home office
    Shift work

    Uniting Holding

    Houston, TX
    4 days ago
  •  ...Summary We are seeking a Senior Network Security Analyst to help maintain a strong level...  .... Serves as the subject matter expert for security best practices, policies, and...  ...Gen Firewall, Web Application Firewall, Cloud Security. Working Conditions... 
    Cloud
    Full time
    For contractors
    For subcontractor
    Remote work
    Flexible hours

    CenterPoint Energy

    Houston, TX
    11 days ago
  • We are hiring an OT Security Analyst to work out of our Corporate Office in Houston on a hybrid work schedule. ESSENTIAL FUNCTIONS Gain...  ...opportunities to standardize and simplify security tools, using native cloud features when possible. Monitor industry trends, threats,... 
    Cloud
    Work at office

    Noble Corporation

    Houston, TX
    3 days ago
  •  ...Job Description The IT/OT Principal Security Architect is a senior individual contributor responsible for designing, assessing, and...  ...across IT and OT networks, systems, applications, and cloud platforms. Develop target-state architectures and integration... 
    Cloud
    Remote work

    Oceaneering

    Houston, TX
    1 day ago
  •  ...Job Title Skill Set SAP BO, Linux Shell Scripting Informatica, Oracle PlSql AZURE Cloud ADF, Databricks Data Modelling, EDW Domain Understanding – Trading Business Communication Stakeholder Management Ownership, Accountability Primary Skills: Informatica, Oracle... 
    Cloud

    Omni Inclusive

    Houston, TX
    4 days ago
  •  ...preferred (associate’s or bachelor’s) 3-5 years of experience in IT security Experience with intrusion detection (IDS) and intrusion...  ...Experience with log analysis and log management Experience with Cloud Security Management interfaces Experience with enterprise... 
    Cloud
    Work at office
    Visa sponsorship
    Weekend work

    MetroNational

    Houston, TX
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Expert (SOX & Cloud). Be the first to apply!