SOX and Compliance Analyst
McKesson • Cork, Ireland • Full Time • $56,300–$93,800 / year
Posted on Wed, Sep 30, 2026
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care.
What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.
McKesson is seeking a SOX and Compliance Analyst to support enterprise governance, risk, and compliance initiatives across SAP, Identity Governance, Cybersecurity, and Internal Controls. This role will be responsible for administering SAP GRC platforms, supporting SOX compliance activities, managing user access governance processes through SailPoint, producing cybersecurity compliance reporting, and partnering with internal and external auditors to strengthen the organization's control environment.
The ideal candidate combines technical expertise, compliance knowledge, and analytical problem-solving skills to improve control effectiveness, reduce risk, and support regulatory compliance across the enterprise. This position operates within McKesson's Governance, Risk, and Compliance (GRC) organization and collaborates with Information Security, Internal Audit, Application Teams, and Business Stakeholders.
What You'll Do
- Administer and support SAP GRC Access Control and Process Control solutions, including user provisioning, access requests, emergency access management, and Segregation of Duties (SoD) monitoring.
- Execute SOX ITGC and automated control testing activities, including evidence collection, documentation, validation, and issue tracking.
- Support SailPoint Identity Governance & Administration (IGA) processes, user access reviews, certification campaigns, role management, and provisioning workflows.
- Develop and maintain cybersecurity compliance dashboards, risk reports, vulnerability tracking metrics, and executive reporting.
- Partner with Information Security teams to monitor remediation efforts for identified vulnerabilities and control deficiencies.
- Coordinate internal and external audit activities, provide audit evidence, and support walkthroughs and testing requests.
- Track control exceptions and drive remediation plans through closure while ensuring compliance with internal policies and regulatory requirements.
- Identify opportunities to improve governance, compliance, automation, and operational effectiveness across GRC processes.
Basic Requirements
- 4+ years of experience in IT Governance, Risk & Compliance (GRC), IT Audit, SOX Compliance, Cybersecurity Compliance, Identity & Access Management, or related fields.
- Bachelor's degree in Information Systems, Information Security, Computer Science, Accounting, Risk Management, Business Administration, or a related field; or equivalent combination of education and experience.
- Hands-on experience administering SAP GRC Access Control and/or SAP Process Control.
- Experience performing SOX controls testing, audit support, evidence collection, and compliance documentation.
- Experience supporting SailPoint Identity Governance & Administration (IGA) or similar IAM platforms.
- Knowledge of IT General Controls (ITGC), access governance, Segregation of Duties (SoD), and regulatory compliance frameworks.
- Experience working with cybersecurity compliance reporting, risk metrics, vulnerability management, or security control monitoring.
- Strong analytical, communication, documentation, and stakeholder management skills.
Preferred Skills/Experience
- Experience with SAP S/4HANA environments and SAP security concepts.
- Knowledge of NIST, ISO 27001, COBIT, PCI-DSS, HIPAA, or other cybersecurity and compliance frameworks.
- Experience using Integrated Risk Management (IRM), GRC Automation, or Regulatory Technology (RegTech) platforms.
- Professional certifications such as CISA, CRISC, CISSP, CGEIT, SAP GRC, Security+, or SailPoint certifications.
- Experience developing compliance dashboards and executive-level reporting.
- Knowledge of vulnerability management tools and remediation tracking processes.
- Experience supporting large-scale audit programs across complex enterprise environments.
- Proven track record of driving process improvements and compliance automation initiatives.
- Technical experience across SAP Basis, HANA/Oracle/MSSQL database administration, SAP BusinessObjects, Linux administration, and Windows administration.
- Platform experience across SAP RISE, SAP Business Technology Platform (BTP), and other SAP SaaS deployments.
- Experience with hyperscaler platforms, including Microsoft Azure and Google Cloud Platform (GCP).
- Advanced Identity and Access Management experience, including SSO/MFA and authentication protocols or technologies such as OpenID, SAML, Kerberos, SPNego, LDAP, Active Directory, Okta, and SAP Identity Provider.
- Privileged Access Management experience across OS, database, and application layers in SAP and non-SAP environments, including CyberArk.
- Expertise in Identity Governance and Administration (IGA), SAP GRC, and SailPoint.
- Experience with SOX/SOC controls across OS, database, and application layers in SAP and non-SAP environments.
At McKesson, we care about the well-being of the patients and communities we serve, and that starts with caring for our people. That’s why we have a Total Rewards package that includes comprehensive benefits to support physical, mental, and financial well-being. Our Total Rewards offerings serve the different needs of our diverse employee population and ensure they are the healthiest versions of themselves.
As part of Total Rewards, we are proud to offer a competitive compensation package at McKesson. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered.
Our Base Pay Range for this position
€56,300 - €93,800McKesson has become aware of online recruiting-related scams in which individuals who are not affiliated with or authorized by McKesson are using McKesson’s (or affiliated entities, like CoverMyMeds or RxCrossroads) name in fraudulent emails, job postings or social media messages. In light of these scams, please bear the following in mind:
McKesson Talent Advisors will never solicit money or credit card information in connection with a McKesson job application.
McKesson Talent Advisors do not communicate with candidates via online chatrooms or using email accounts such as Gmail or Hotmail. Note that McKesson does rely on a virtual assistant (Gia) for certain recruiting-related communications with candidates.
McKesson job postings are posted on our career site: careers.mckesson.com.
More live compliance_analyst roles
- Senior Technical Risk & Compliance Analyst at LinkedIn — Mountain View, CA, US
- Senior Compliance Analyst (All Genders) (Vollzeit, Unbefristet) at AbbVie — Wiesbaden, HE, DE
- Senior It Risk And Compliance Analyst at Copeland — Pune, India
- Senior Global Trade Compliance Analyst at KLA — Singapore, Singapore
- Placement Student - Trade Compliance Analyst at Cummins — Darlington, County Durham, United Kingdom
- State Filing & Compliance Analyst at Core Specialty Insurance Services — Cincinnati, Ohio, United States
- Compliance Analyst, Core Compliance at Bridgewater Associates — Westport, Connecticut, United States
- Compliance Analyst, IRB at University of Toledo — Toledo, Ohio, US
- Compliance Analyst at Summit 7 Systems (Remote)
- Partner 16, Compliance Analyst at a16z — Menlo Park, California, United States; San Francisco, California, United States
- Financial Compliance Analyst at Booz Allen Hamilton — Washington, District of Columbia, United States
- Senior Trade Compliance Analyst at ICON Consultants (Remote)
- IT Compliance Analyst at Intercontinental Exchange Holdings — New York, New York, US
- Senior Compliance Analyst, EMEA at Themis Solutions — Dublin, Ireland
- Product Regulatory Compliance Analyst at Avery Dennison — Oegstgeest, ZH, NL
- BSA & Compliance Analyst at P1Fcu — Idaho, United States
- Information Assurance Compliance Analyst at HII — Virginia Beach, VA, US
- Regulatory Compliance Analyst, Residential Mortgage at Intercontinental Exchange Holdings — Jacksonville, Florida, United States
- Sr. Life & Annuity Compliance Analyst - Advertising at National Life Insurance — Addison, Texas, United States
- Senior Technical Compliance Analyst at Quality Technology Services — Overland Park, Kansas, United States
- Contracts Operations and Compliance Analyst at Hanwha Defense USA — Arlington, VA, US
- Compliance Analyst at Amazon — Tempe, Arizona, US
- Compliance Analyst at Momentum Engineering — Annapolis Junction, Maryland, United States
- Senior Investment Compliance Analyst at City of New York — New York City, NY, United States
- Compliance Analyst at AXIS — Dublin, Ireland
- Senior Compliance Analyst - Technology Operations at Dow Jones & Company — New York City, NY, US
- Sr. Internal Controls & Compliance Analyst at Constellation Brands — 2 Locations
- Lead Compliance Analyst - Transamerica Asset Management at Transamerica — 3 Locations
- Trade Compliance Analyst at Stanley Black & Decker (Remote)
- Tax Compliance Analyst at LV Petroleum — Las Vegas, Nevada, United States
- Sr. Trade Compliance Analyst at Constellation Brands — Chicago, Illinois, United States
- Compliance Analyst at Calgary Board of Education — Calgary, Alberta, Canada
- Compliance Analyst at Leggett & Platt — Winston-Salem, North Carolina, US
- Sr. Life & Annuity Compliance Analyst - Advertising at National Life Insurance Company — Addison, TX; Montpelier, VT
- Contracts Compliance Analyst at Becton Dickinson Medical Devices — San Diego, California, United States
- Compliance Analyst I at AutoNation — Not Specified
- Enterprise Governance Risk and Compliance Analyst at Randolph-Brooks Federal Credit Union — San Antonio, Texas, United States
- Compliance Analyst, Audit at Carson Group — Omaha, Nebraska, United States
What the data says about this job
- McKesson's roles typically close in 22 days; the market median is 14 days. Time to close
- 6% of McKesson's 33 tracked postings are more than six months old. Posting hygiene
Measured from employers' own postings and public filings. How we measure