Role: IAM Audit Analyst
Location: Chicago, IL Work Model: Hybrid - Anchor Days: Wednesday is mandatory; contractor selects 2 additional days per week
Duration: 04 Months
JD:
- The IAM Audit Analyst leads audit engagements (internal/external) focused on Identity and Access Management (IAM), IT controls, and cybersecurity.
- This role involves overseeing audit request execution, evaluating evidence, and working closely with 1LOD/2LOD to define scope and develop effective evidence testing documentation.
- You will bring technical expertise in risk, controls, and IAM technologies, ensuring strong governance and compliance across access management processes.
Key Responsibilities
Lead projects related to:
- Identity and Access Management (IAM) controls
- IT General Controls (ITGC)
- Information security / cybersecurity
- Application and system implementation reviews
- IT governance and operational processes
- Provide oversight and guidance to stakeholders on IAM Audit requests and Evidence Requests
- Partner with Implementation owners to:
- Define audit scope and objectives
- Develop appropriate testing strategies based on risk assessment
- Assist in developing evidence testing timelines based on scope and risk
- Finalize and review audit planning and scoping documentation
- Conduct and review walkthroughs and testing of:
- Application controls
- Interface controls
- IAM processes (provisioning, de-provisioning, access reviews, PAM)
- Ensure work meets departmental standards and quality requirements
- Analyze and review implementation plans, and follow up on milestones for issues identified by 1LOD, 2LOD, and Audit teams
- Work with various stakeholders across business, technology, risk, and control functions tdrive issue resolution, remediation tracking, and governance alignment
- Communicate audit status and findings tbusiness stakeholders and leadership
- Draft audit findings, reports, and recommendations for:
- Status updates
- Memos
- Final Closure Packages
- Identify and evaluate risks, control gaps, and remediation actions
- Coordinate with other teams (regional, business unit, specialist teams) to ensure comprehensive coverage of risk areas
Required Skills & Qualifications:
- 5-10 years of experience in:
- IT Audit / Risk / Controls
- IAM-focused audits or security controls
Strong knowledge of:
- Audit standards, methodologies, and procedures
- IT systems, applications, and cybersecurity risks
- Identity and Access Management (IAM) principles, including:
- User lifecycle management
- Role-based access control (RBAC)
- Privileged Access Management (PAM)
- Experience with IAM technologies such as:
- SailPoint, Saviynt, Okta, Azure AD, CyberArk (or similar)
- Understanding of IT General Controls (ITGC) and compliance frameworks (SOX, ISO, etc.)
- Ability to lead and execute:
- Walkthroughs
- Design and operational effectiveness testing
- Strong analytical, documentation, and reporting skills
- Excellent communication and stakeholder management skills
Key Competencies
- Strong risk and control mindset
- Ability to lead audit engagements independently
- Attention to detail with a strategic perspective
- Flexibility, creative thinking, and sound business judgment
- Team-player with ability to thrive in high-pressure environments
Preferred Qualifications:
Certifications such as:
- CISA, CISSP, CRISC (ISACA, ISC2, or equivalent)
Experience in:
- IAM governance and access certification programs
- Cloud IAM environments (Azure, AWS, GCP)
- Ability to manage:
- Multiple projects simultaneously
- Tight deadlines with strong prioritization
|