Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
T
TEKsystems
IAM Audit & Compliance Analyst
Career Insights for Compliance Auditor
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on national data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Compliance Auditor examines records and procedures to determine adherence to regulatory guidelines of an organization. Inspects accounting, IT or security, prepares reports on the compliance with required regulations and risk management procedures.
$99,199 / year median in the U.S.
+1% projected growth
Job Description
Search IAM Audit & Compliance Analyst Employer TEKsystems Location Conshohocken, Pennsylvania, United States Salary
USD 65.00
- 70.
TESYUSJP006264009ENUS
View more categories View fewer categories Job role Audit , Compliance/risk Sector Accounting- Public practice Apply (This will open in a new window from which you will be automatically redirected to an external site after 5 seconds) Save job Click to add the job to your shortlist You need to sign in or create an account to save a job.
Job Details Job Title:
IAM Audit & Compliance Analyst Location:
100% Remote- At this time, the client is considering candidates who are authorized to work in the U.
- not a project. There is no existing program, documentation, or team to inherit. This person is building the foundation from a blank page. The person in this role will serve as the single lane highway
- the sole point of contact
- between organization's large IAM organization and every internal and external audit and assessment team. Everything audit-related flows in and out through this person's desk. They own it end to end. The overarching goal is audit readiness. Not passing audits by the skin of your teeth
- but having the right processes, controls, documentation, and evidence in place so that when auditors arrive, can show and prove everything without chasing their tail.
- Brad's strongest candidate to date was eliminated in round two for exactly this reason.
Key Responsibilities:
Serve as the single IAM liaison for all audit and assessment activity- own the entire process from walkthrough coordination and evidence gathering through action plan development and response delivery back to assessment teams Ensure audit readiness across the IAM organization
- review and train internal IAM team members on updated control standards, what's required, what's not, and how to document and retain evidence properly in an auditable, accessible repository Map IAM control standards to applicable regulatory frameworks including SOX, NIST, HITRUST, PCI-DSS, HIPAA, and GDPR
- identify gaps, assess whether standards are inclusive enough, and drive remediation before auditors find the problems Develop and manage a Segregation of Duties matrix and ensure no SOD conflicts exist in the environment Drive automation of evidence collection
- serve as the SME who identifies which controls should be automated, partners with IAM dev teams to get tasks prioritized on their backlog, validates that automation is working as intended, and maintains output as ongoing audit proof so evidence is always ready and never has to be scrambled for Serve as control owner or delegate for IAM preventive and detective controls
- define, maintain, and periodically assess control effectiveness and maturity Govern IAM policy exceptions, remediation plans, compensating controls, and periodic recertification workflows Validate effectiveness of User Access Review processes and ensure certification controls meet audit and regulatory expectations Monitor and track IAM-related findings, risks, and issues through ServiceNow GRC
- ensure timely remediation and maintain defensible, auditable documentation throughout Lead cross-functional remediation efforts involving IAM, Application Owners, Infrastructure, IT Controls & Compliance, and HR teams Provide IAM governance subject matter expertise during new projects and system implementations Capture and report IAM compliance metrics and contribute to leadership dashboards Additional Skills & Qualifications 5+ years of hands-on, individual contributor experience in IAM Governance, IT Audit, Compliance, or Risk Management•must have physically performed this work, not managed a team that did Strong working knowledge of SailPoint IdentityIQ•governance, administration, and operational support experience required Demonstrated experience supporting SOX, SOC1, SOC2, HITRUST, GDPR, and PCI-DSS compliance requirements specifically within an IAM context Experience with Joiner/Mover/Leaver processes, Privileged Access Governance concepts, and Access Certification programs Proficiency with ServiceNow GRC for issue management and tracking Working knowledge of Active Directory and Azure AD Advanced Microsoft Excel skills•pivot tables, power query, data validation between source systems and SailPoint Experience partnering with engineering and development teams to drive control automation initiatives•does not need to be a technical builder but must be the SME who drives it Strong root cause analysis and incident support capabilities Certifications highly valued: CISA, CISM, CISSP, CRISC, or CIAM Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent experience Critical Screening Notes for Recruiters Must screen for hands-on, solo ownership: Ask candidates to walk you through a specific IAM audit readiness program they built and owned independently.
- redirect and ask how they design controls proactively.
- 5+ years of experience in Information Security, IAM Governance, IT Audit, Compliance, or Risk Management, with hands on experience managing audit findings, issue remediation, control testing, evidence collection and more
- Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or equivalent experience.
- Demonstrated experience supporting SOX, Internal Audit, external audit, and regulatory engagements for Identity Access Management controls.
Analytical Skills:
High attention to detail, strong analytical thinking, and problem-solving abilities.Communication:
Strong interpersonal and communication skills in order to support the " non-technical" stakeholders and manage relationships with variety of teams and assessment activities.Certifications:
While not always required, professional certifications like Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Risk and Information Systems Control (CRISC) and/or Certified Identity and Access Manager (CIAM) are highly valuedCompliance Knowledge:
Working knowledge of IAM frameworks as well as SOX requirements and NIST framework guidance.SKILLS & KNOWLEDGE
Behavioral Skills:
- Critical Thinking and Problem Solving
- Detail Orientation and Accountability
- Interpersonal Communication
- Learning Agility and Adaptability
- Multitasking and Time Management
Collaboration and Teamwork Technical Skills:
- Working knowledge of
SOX, SOC1, SOC2, HITRUST, GDPR
- IT Risk and Compliance Awareness
- Identity Governance and Administration (IGA)
- Joiner, Mover, Leaver (JML) processes
- Segregation of Duties (SOD)
- Privileged Access Governance concepts
- Access Certification Programs
- Root Cause Analysis and Incident Support
Reporting and Documentation Tools Knowledge:
- Sailpoint
- Directory Services (Active Directory, Azure AD) Job Type & Location This is a Contract position based out of Conshohocken, PA. Pay and Benefits The pay range for this position is $65.00
- $70.
- Medical, dental & vision
- Critical Illness, Accident, and Hospital
- 401(k) Retirement Plan
- Pre-tax and Roth post-tax contributions available
- Life Insurance (Voluntary Life & AD&D for the employee and dependents)
- Short and long-term disability
- Health Spending Account (HSA)
- Transportation benefits
- Employee Assistance Program
- Time Off/Leave (PTO, Vacation or Sick Leave) Workplace Type This is a fully remote position.