Plan and execute control testing cycles (design effectiveness and operating effectiveness) across IT general controls (ITGCs), application controls, and regulatory controls for frameworks including SOX, SOC 1/2, ISO 27001, NIST CSF, CMMC, GDPR, CCPA, HIPAA, and others. Review and test IAM controls including role-based access control (RBAC), privileged access management (PAM), MFA enforcement, access certification cycles, and joiner/mover/leaver processes against regulatory and audit requirements.