The Identity Process and Compliance Analyst will evaluate, improve, document, and maintain the processes and controls that govern identity and access management (IAM). This role will interpret applicable requirements and recognized good practices, compare them with current procedures and runbooks, identify gaps, and help the IAM organization implement sustainable improvements. The analyst will partner with IAM leadership, identity architecture, audit and compliance teams, organizational change management, and technology owners to make identity processes usable, auditable, and ready for operational adoption. This is a remote role within the United States.
Responsibilities:
• Review IAM policies, standards, procedures, runbooks, control narratives, approval workflows, and operating practices.
• Translate regulatory requirements, audit observations, control objectives, industry frameworks, and recognized good practices into practical IAM process requirements.
• Assess identity processes supporting joiner, mover, and leaver activities; access requests and approvals; privileged and emergency access; access reviews; exceptions; service accounts; and offboarding.
• Identify gaps across documented processes, actual operating practices, system capabilities, and required controls.
• Recommend practical, risk-based improvements with clear ownership and implementation sequencing.
• Draft and update policies, standards, procedures, runbooks, process maps, control descriptions, work instructions, approval matrices, and evidence requirements.
• Partner with IAM leadership and organizational change management to review, approve, communicate, and support adoption of process changes.
• Coordinate process reviews with stakeholders across IAM, infrastructure, applications, human resources, security operations, audit, compliance, and business teams.
• Support audit preparation and execution by maintaining control evidence, traceability, issue logs, remediation plans, and responses to findings.
• Participate in control testing and assess whether processes operate consistently with approved requirements.
• Define process metrics, control indicators, risk indicators, and reporting requirements for IAM leadership.
• Track policy, procedure, and runbook currency, including owners, review dates, and version control.
• Convert identity governance and security findings into process changes, change requests, training needs, and sustained operating practices.
Qualifications:
• 5 or more years of experience in IT process analysis, cybersecurity governance, IT audit, risk and compliance, IAM governance, or a related discipline.
• Demonstrated experience analyzing written procedures and operating practices to identify gaps and recommend improvements.
• Experience documenting process flows, controls, procedures, runbooks, requirements, evidence needs, and remediation plans.
• Working understanding of identity lifecycle management, access requests, approvals, privileged access, access reviews, segregation of duties, and least privilege.
• Ability to interpret complex requirements and convert them into clear, usable instructions for technical and non-technical audiences.
• Strong facilitation, interviewing, writing, organization, and stakeholder-management skills.
• Preferred: Experience with North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP), electric utilities, critical infrastructure, Sarbanes-Oxley Act (SOX), IT general controls, National Institute of Standards and Technology (NIST), ISO 27001, COBIT, or comparable governance frameworks.
• Preferred: Experience supporting audits, control testing, evidence collection, findings remediation, or compliance reporting.
• Preferred: Experience with IAM platforms such as Saviynt, SailPoint, Microsoft Entra ID Governance, CyberArk, or BeyondTrust.
• Preferred: CISA, CRISC, CISSP, CISM, ITIL, NERC CIP training, or a comparable certification.
• Preferred: Experience supporting organizational change management, communications, training, or process adoption.
Tools and Technologies:
• Saviynt
• SailPoint
• Microsoft Entra ID Governance
• CyberArk
• BeyondTrust
• NERC CIP
• NIST
• ISO 27001
• COBIT
• IT general controls and audit evidence repositories
• Process mapping, documentation, and reporting tools