Job Title: IAM Audit & Compliance Analyst
Location: Remote (EST and CST resource required)
Key Skills:
Sailpoint (Key IAM Tool experience)
Microsoft Azure AD/Entra ID
Privileged Access Management (PAM)
SOX user access control testing
Role-Based Access Control (RBAC)
IT Audit and Audit Management
Enterprise Risk Management
Joiner-Mover-Leaver processes
Provisioning/deprovisioning controls
Job Summary
We are seeking an experienced IAM Audit & Compliance Analyst to support audit, compliance, risk, and governance activities within the Identity & Access Management organization.
This role will serve as a key point of contact for IAM-related audits, assessments, regulatory reviews, evidence collection, issue remediation, control testing, and compliance reporting. The ideal candidate will possess a strong understanding of IAM governance, audit controls, regulatory frameworks, and risk management while effectively engaging with auditors, compliance teams, and business stakeholders.
This is primarily a governance, compliance, and audit-focused role rather than an IAM engineering or development position.
Key Responsibilities
Audit & Assessment Management
Serve as primary point of contact for IAM-related audits and assessments.
Coordinate walkthroughs, evidence gathering, audit responses, and remediation efforts.
Support internal, external, and regulatory audit engagements.
Maintain audit-ready documentation and evidence repositories.
Compliance & Controls
Ensure IAM controls are operating effectively and comply with policy requirements.
Act as control owner or delegate for IAM preventive and detective controls.
Define, maintain, and assess IAM control effectiveness and maturity.
Support control testing and validation activities.
Findings & Risk Management
Track audit findings, remediation plans, risks, and exceptions.
Coordinate with stakeholders to ensure timely issue resolution.
Monitor remediation progress and provide management reporting.
Segregation of Duties (SoD)
Develop and maintain SoD matrices.
Review and identify SoD conflicts and ensure remediation.
Support preventive and detective control processes.
IAM Governance
Validate User Access Review (UAR) effectiveness.
Ensure certification programs meet regulatory and audit expectations.
Review policy exceptions and risk acceptance documentation.
Support IAM governance initiatives and control improvements.
Documentation & Reporting
Maintain IAM policies, control standards, workflows, and procedures.
Produce audit reports, metrics, dashboards, and compliance documentation.
Support regulatory reporting requirements.
Data Analysis
Analyze IAM data for completeness and accuracy.
Reconcile source system access data with SailPoint and governance records.
Utilize advanced Excel functions for validation, reporting, and analysis.
Cross-Functional Collaboration
Work closely with IAM, Compliance, Audit, Infrastructure, HR, Application Owners, and Security teams.
Provide IAM governance guidance during projects and implementations.
Required Qualifications
5+ years of experience in IAM Governance, Information Security, Audit, Compliance, Risk Management, or Controls.
Experience managing audit findings, evidence collection, remediation tracking, and control testing.
Strong understanding of IAM controls and governance processes.
Experience supporting SOX, Internal Audit, External Audit, and Regulatory Reviews.
Strong analytical and problem-solving skills.
Excellent verbal and written communication skills.
Preferred Certifications
Required Knowledge Areas
SOX
SOC1
SOC2
HITRUST
GDPR
PCI-DSS
NIST
IAM Governance
Access Certifications
User Access Reviews (UAR)
Joiner-Mover-Leaver (JML)
Segregation of Duties (SoD)
Privileged Access Governance
Compliance & Risk Management
Root Cause Analysis