New
IAM Audit Analyst
Spectraforce Technologies | |
United States, Illinois, Chicago | |
Sep 04, 2026 | |
|
Role: IAM Audit Analyst Location: Chicago, IL - Hybrid Duration :2+ Months The IAM Audit Analyst leads audit engagements (internal/external) focused on Identity and Access Management (IAM), IT controls, and cybersecurity. This role involves overseeing audit request execution, evaluating evidence, and working closely with 1LOD/2LOD to define scope and develop effective evidence testing documentation. You will bring technical expertise in risk, controls, and IAM technologies, ensuring strong governance and compliance across access management processes. Key Responsibilities * Lead projects related to: o Identity and Access Management (IAM) controls o IT General Controls (ITGC) o Information security / cybersecurity o Application and system implementation reviews o IT governance and operational processes * Provide oversight and guidance to stakeholders on IAM Audit requests and Evidence Requests * Partner with Implementation owners to: o Define audit scope and objectives o Develop appropriate testing strategies based on risk assessment * Assist in developing evidence testing timelines based on scope and risk * Finalize and review audit planning and scoping documentation * Conduct and review walkthroughs and testing of: o Application controls o Interface controls o IAM processes (provisioning, de-provisioning, access reviews, PAM) * Ensure work meets departmental standards and quality requirements * Analyze and review implementation plans, and follow up on milestones for issues identified by 1LOD, 2LOD, and Audit teams * Work with various stakeholders across business, technology, risk, and control functions to drive issue resolution, remediation tracking, and governance alignment * Communicate audit status and findings to business stakeholders and leadership * Draft audit findings, reports, and recommendations for: o Status updates o Memos o Final Closure Packages * Identify and evaluate risks, control gaps, and remediation actions * Coordinate with other teams (regional, business unit, specialist teams) to ensure comprehensive coverage of risk areas Required Skills & Qualifications * 5-10 years of experience in: o IT Audit / Risk / Controls o IAM-focused audits or security controls * Strong knowledge of: o Audit standards, methodologies, and procedures o IT systems, applications, and cybersecurity risks o Identity and Access Management (IAM) principles, including: * User lifecycle management * Role-based access control (RBAC) * Privileged Access Management (PAM) * Experience with IAM technologies such as: o SailPoint, Saviynt, Okta, Azure AD, CyberArk (or similar) * Understanding of IT General Controls (ITGC) and compliance frameworks (SOX, ISO, etc.) * Ability to lead and execute: o Walkthroughs o Design and operational effectiveness testing * Strong analytical, documentation, and reporting skills * Excellent communication and stakeholder management skills Preferred Qualifications * Certifications such as: o CISA, CISSP, CRISC (ISACA, ISC2, or equivalent) * Experience in: o IAM governance and access certification programs o Cloud IAM environments (Azure, AWS, GCP) * Ability to manage: o Multiple projects simultaneously o Tight deadlines with strong prioritization | |
Sep 04, 2026