Sr. Sox And Compliance Analyst, Sap Applications
McKesson • Full Time
Posted on Thu, Sep 10, 2026
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care. What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you. McKesson is seeking a Sr. SOX and Compliance Analyst, SAP Applications to support and advance enterprise governance, risk, and compliance programs. This role partners across Security, Audit, Technology, and Business teams to strengthen internal controls, reduce risk, and maintain compliance with regulatory and organizational requirements. The ideal candidate brings hands-on expertise with SAP GRC Access Control and Process Control, SOX compliance testing, SailPoint identity governance integration, cybersecurity risk assessments, and IT General Controls (ITGC). This position plays a key role in driving control effectiveness, audit readiness, and continuous compliance improvement across the enterprise. What You'll Do Lead SAP GRC Access Control and SAP Process Control configuration, administration, and continuous optimization. Execute SOX control testing activities, including evidence collection, documentation, control evaluation, and audit support. Partner with Identity and Access Management teams to integrate and enhance SailPoint governance processes for SAP environments. Conduct cybersecurity vulnerability assessments and resiliency testing to identify, assess, and mitigate technology risks. Monitor IT General Controls (ITGCs) and coordinate remediation activities for identified control deficiencies. Analyze compliance risks, perform root-cause investigations, and recommend corrective actions to improve control effectiveness. Develop compliance reports, risk metrics, and executive-ready presentations that communicate trends, findings, and remediation progress. Collaborate with internal and external auditors, technology teams, and business stakeholders to support regulatory and compliance requirements. Basic Requirements 7+ years of experience in Governance, Risk & Compliance (GRC), IT Audit, Information Security, SOX Compliance, or related disciplines. Bachelor's degree in Information Systems, Cybersecurity, Accounting, Risk Management, Business Administration, or a related field, or equivalent experience. Hands-on experience administering and configuring SAP GRC Access Control and/or SAP Process Control. Experience performing SOX controls testing, audit evidence collection, documentation, and remediation validation. Experience with IT General Controls (ITGC) testing, monitoring, and compliance reporting. Experience supporting Identity Governance and Administration (IGA) programs, including SailPoint or similar platforms. Knowledge of cybersecurity risk management, vulnerability assessment, and security control frameworks. Strong analytical, problem-solving, communication, and stakeholder management skills. Technical foundation across SAP Basis, HANA, Oracle, MSSQL DBA, Business Objects, Linux administration, and Windows administration. Experience with SAP platform models, including SAP RISE, SAP BTP, and other SAP SaaS deployments. Experience working with hyperscaler platforms, including Microsoft Azure and Google Cloud Platform (GCP). Advanced Identity and Access Management experience, including SSO, MFA, OpenID, SAML, Kerberos, SPNego, LDAP, Active Directory, Okta, and SAP Identity Provider. Privileged Access Management experience across operating system, database, and application layers in SAP and non-SAP environments, including CyberArk. Expertise in Identity Governance and Administration (IGA), SAP GRC, and SailPoint. Experience with SOX and SOC controls across operating system, database, and application layers in SAP and non-SAP environments. Preferred Skills/Experience Experience in large-scale enterprise SAP environments. Knowledge of SAP authorization concepts, Segregation of Duties (SoD), access risk analysis, and emergency access management. Experience supporting external audits, internal audits, and regulatory examinations. Relevant certifications such as CISA, CRISC, CISSP, CIA, SAP GRC, Security+, or SailPoint certifications. Experience with continuous controls monitoring and risk analytics tools. Familiarity with NIST, COBIT, ISO 27001, COSO, and related governance frameworks. Experience leading compliance initiatives, cross-functional projects, or remediation programs. Healthcare, pharmaceutical, distribution, or regulated-industry experience. At McKesson, we care about the well-being of the patients and communities we serve, and that starts with caring for our people. That’s why we have a Total Rewards package that includes comprehensive benefits to support physical, mental, and financial well-being. Our Total Rewards offerings serve the different needs of our diverse employee population and ensure they are the healthiest versions of themselves. As part of Total Rewards, we are proud to offer a competitive compensation package at McKesson. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. Our Base Pay Range for this position €72,000 - €120,000 McKesson has become aware of online recruiting-related scams in which individuals who are not affiliated with or authorized by McKesson are using McKesson’s (or affiliated entities, like CoverMyMeds or RxCrossroads) name in fraudulent emails, job postings or social media messages. In light of these scams, please bear the following in mind: McKesson Talent Advisors will never solicit money or credit card information in connection with a McKesson job application. McKesson Talent Advisors do not communicate with candidates via online chatrooms or using email accounts such as Gmail or Hotmail. Note that McKesson does rely on a virtual assistant (Gia) for certain recruiting-related communications with candidates. McKesson job postings are posted on our career site: careers.mckesson.com .
More live compliance_analyst roles
- Compliance Analyst at Full Circle Communities — Chicago, IL, US
- Fiscal Compliance Analyst at State of Nebraska — Lincoln, Nebraska, United States
- Compliance Analyst at United States Lottery — Charlotte, North Carolina, United States
- Compliance Analyst — Charlotte, North Carolina, United States
- Compliance Analyst at Not Specified — Charlotte, NC, US
- Senior Security Compliance Analyst - PCI DSS & SOC 2 at Entrust — New York, US
- Facility Compliance Analyst at C3 Industries — St. Louis, Missouri, United States
- Compliance Analyst at Clark Construction Group — San Francisco, California, US
- Quality and Compliance Analyst at Expeditors — Peabody, Massachusetts, United States
- Core and Employee Compliance Analyst at Jain Global — New York, New York, United States
- Trading Compliance Analyst at Jain Global — New York, New York, United States
- Compliance Analyst, Audit Assurance at Integrity Marketing Group — Dallas, TX, United States
- Digital Systems Compliance Analyst at North Carolina Education Lottery — Raleigh, North Carolina, United States
- AI Governance & Compliance Analyst at Beeline — Jacksonville, Florida, United States
- Export/Import Compliance Analyst, Sr at Curtiss-Wright — Mississauga, Ontario, Canada
- Investment Compliance Analyst at Moneta Group Investment Advisors — Clayton, MO, US
- Channel Compliance Analyst at onsemi — Carmona, Cavite, Philippines, Philippines
- Sox And Compliance Analyst at McKesson — Cork
- Investment Compliance Analyst, Associate 2 at State Street Corporation — Bangalore, India
- Sea Regional Coe Statutory Compliance Analyst at Stanley Black & Decker — Jalan Taman, Malaysia
- FQHC Compliance Analyst — Hendersonville, North Carolina, United States
- HCS Compliance Analyst II - Hospital Compliance — Morrisville, North Carolina, US
- 340B Program Compliance Analyst Certified — Morrisville, North Carolina, US
- Compliance Analyst III - Compliance and Privacy — Morrisville, North Carolina, United States
- Compliance Analyst, Regulatory Requests at MojoRank — Chicago, Illinois, United States
- Trade Compliance Analyst at FlightSafety — Broken Arrow, Ohio, United States
- Compliance Analyst at Nassau — Hartford, Connecticut, US
- Senior International Trade Compliance Analyst at Northrop Grumman — Warner Robins, Georgia, United States
- Sr. Principal International Trade Compliance Analyst at Northrop Grumman — Warner Robins, GA, United States
- Senior Principal International Trade Compliance Analyst at Northrop Grumman — Warner Robins, Georgia, United States
- Compliance Analyst at The Walt Disney Company — Celebration, Florida, United States
- Senior It Compliance Analyst at AbbVie — North Chicago, IL, US
- Customs Compliance Analyst (Temporary) at LG — Englewood Cliffs, New Jersey, United States
- Cybersecurity & IT Risk and Compliance Analyst at The Manitoba Public Insurance Corporation — Winnipeg, Manitoba, Canada