IAM Audit Analyst
Contract
Chicago, IL, hybrid
must have Analytical Skills, Audit, IAM
Education Requirements:
- High School diploma or equivalent
Preferred Education:
- Bachelor's degree
Preferred Certifications:
- CISA, CISSP, CRISC (ISACA, ISC2, or equivalent)
Required Skills for the IAM Audit Analyst:
- 5–10 years of experience in: IT Audit / Risk / Controls; IAM-focused audits or security controls
- Strong knowledge of: Audit standards, methodologies, and procedures; IT systems, applications, and cybersecurity risks
- Identity and Access Management (IAM) principles, including: User lifecycle management; Role-based access control (RBAC); Privileged Access Management (PAM)
- Experience with IAM technologies such as: SailPoint, Saviynt, Okta, Azure AD, CyberArk (or similar);
- Understanding of IT General Controls (ITGC) and compliance frameworks (SOX, ISO, etc.)
- Ability to lead and execute: Walkthroughs; Design and operational effectiveness testing
- Strong analytical, documentation, and reporting skills
- Excellent communication and stakeholder management skills
- Strong risk and control mindset
- Ability to lead audit engagements independently
- Attention to detail with a strategic perspective
- Flexibility, creative thinking, and sound business judgment
- Team-player with ability to thrive in high-pressure environments
Preferred Skills:
- Experience in: IAM governance and access certification programs; Cloud IAM environments (Azure, AWS, Google Cloud Platform)
- Ability to manage: Multiple projects simultaneously; Tight deadlines with strong prioritization
IAM Audit Analyst Overview:
The IAM Audit Analyst leads audit engagements (internal/external) focused on Identity and Access Management (IAM), IT controls, and cybersecurity. This role involves overseeing audit request execution, evaluating evidence, and working closely with 1LOD/2LOD to define scope and develop effective evidence testing documentation. You will bring technical expertise in risk, controls, and IAM technologies, ensuring strong governance and compliance across access management processes.
Responsibilities:
- Provide oversight and guidance to stakeholders on IAM Audit requests and Evidence Requests
- Assist in developing evidence testing timelines based on scope and risk
- Finalize and review audit planning and scoping documentation
- Ensure work meets departmental standards and quality requirements
- Analyze and review implementation plans, and follow up on milestones for issues identified by 1LOD, 2LOD, and Audit teams
- Work with various stakeholders across business, technology, risk, and control functions to drive issue resolution, remediation tracking, and governance alignment
- Communicate audit status and findings to business stakeholders and leadership
- Identify and evaluate risks, control gaps, and remediation actions
- Coordinate with other teams (regional, business unit, specialist teams) to ensure comprehensive coverage of risk areas
Lead projects related to:
- Identity and Access Management (IAM) controls
- IT General Controls (ITGC)
- Information security / cybersecurity
- Application and system implementation reviews
- IT governance and operational processes
Partner with Implementation owners to:
- Define audit scope and objectives
- Develop appropriate testing strategies based on risk assessment
Conduct and review walkthroughs and testing of:
- Application controls
- Interface controls
- IAM processes (provisioning, de-provisioning, access reviews, PAM)
Draft audit findings, reports, and recommendations for:
- Status updates
- Memos
- Final Closure Packages