Haystack
← Back to Jobs
Other
XG

IAM Audit Analyst

Xcelo Group IncChicago, IL🇺🇸United StatesPosted 4 Sept 2026

Why This Role Stands Out

This hybrid IAM Audit Analyst role offers a fantastic opportunity to deepen your expertise in critical cybersecurity controls and make a significant impact within a reputable company. You'll thrive in this position if you have 5-10 years of experience in IT audit or cybersecurity and possess a strong understanding of IAM principles, with preferred certifications like CISA or CISSP. Apply today to leverage your skills in a dynamic and collaborative environment!

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Chicago, IL, United States
Posted
5 days ago
AWSAuditingAzureComplianceExternal AuditGoogle CloudInternal AuditRisk AssessmentStakeholder Management

Job Description

Job Title: IAM Audit Analyst

Work Location: Chicago, IL

Work Mode: Hybrid

Work Auth: All Work Authorizations accepted (No h1 and No Fake profile)



Experience Required

5 10 years of relevant experience in IT Audit, Risk & Controls, IAM Audit, or Cybersecurity Controls.

Education

  • High School Diploma or equivalent required

  • Bachelor's degree preferred


Preferred Certifications

  • CISA

  • CISSP

  • CRISC

  • ISACA / ISC2 or equivalent certifications


Job Summary

We are seeking an experienced IAM Audit Analyst to lead and support audit engagements focused on Identity and Access Management (IAM), IT General Controls (ITGC), cybersecurity, risk, and compliance.

The ideal candidate will have strong experience evaluating IAM controls, reviewing audit evidence, performing walkthroughs and control testing, identifying control gaps, and partnering with business, technology, risk, and compliance teams to drive remediation and governance initiatives.

Required Skills

  • 5 10 years of experience in IT Audit, IT Risk, Controls, IAM Audits, or Security Controls

  • Strong understanding of audit standards, methodologies, procedures, and risk-based auditing

  • Strong knowledge of IAM principles, including:

    • User lifecycle management

    • User provisioning and de-provisioning

    • Role-Based Access Control (RBAC)

    • Privileged Access Management (PAM)

    • Access reviews and certifications

  • Hands-on knowledge of IAM technologies such as SailPoint, Saviynt, Okta, Azure AD / Microsoft Entra ID, CyberArk, or similar platforms

  • Strong understanding of IT General Controls (ITGC)

  • Experience with compliance and control frameworks such as SOX and ISO

  • Experience conducting audit walkthroughs, control design assessments, and operational effectiveness testing

  • Ability to independently lead audit engagements from planning and scoping through testing, findings, remediation, and closure

  • Strong risk assessment, analytical, documentation, and reporting skills

  • Strong stakeholder management and communication skills

  • Ability to identify control deficiencies, risks, remediation requirements, and governance gaps

  • Ability to manage multiple priorities and work effectively under tight deadlines


Preferred Skills

  • Experience with IAM governance and access certification programs

  • Experience with Cloud IAM environments across Azure, AWS, or Google Cloud Platform

  • Strong project management and prioritization skills

  • Experience working with 1st Line of Defense (1LOD), 2nd Line of Defense (2LOD), Internal Audit, and External Audit teams


Key Responsibilities

  • Lead and coordinate IAM audit and evidence requests

  • Provide guidance to business and technology stakeholders on audit requirements

  • Develop audit evidence testing timelines based on scope, risk, and audit objectives

  • Prepare and review audit planning and scoping documentation

  • Evaluate submitted evidence for completeness and control effectiveness

  • Conduct and review walkthroughs for IAM, application, interface, and IT controls

  • Perform design effectiveness and operational effectiveness testing

  • Review IAM processes including provisioning, de-provisioning, access reviews, RBAC, and PAM

  • Identify and assess risks, control gaps, audit findings, and remediation actions

  • Track remediation plans, milestones, and closure activities for issues identified by 1LOD, 2LOD, and Audit teams

  • Partner with implementation owners to define audit scope, objectives, and risk-based testing strategies

  • Coordinate across business units, regional teams, technology teams, risk functions, and specialist groups

  • Communicate audit progress, risks, issues, and findings to stakeholders and leadership

  • Draft and review audit findings, recommendations, status reports, memos, and final closure packages

  • Support audits and reviews involving IAM Controls, IT Cybersecurity, Application Controls, System Implementations, IT Governance, and Operational Processes


Key Technologies / Keywords

IAM, IT Audit, IT Cybersecurity, Risk & Controls, SailPoint, Saviynt, Okta, Azure AD, Microsoft Entra ID, CyberArk, RBAC, PAM, Access Certification, User Lifecycle Management, SOX, ISO, Cloud IAM, AWS, Azure, Google Cloud Platform, Audit Walkthroughs, Control Testing, Risk Assessment

Similar jobs