Senior IT Compliance & Audit Analyst
KellyMitchell Group · Fort Worth, TX
قدّم وتابع مع أبلاي إيدجJob Summary: Our client, a leading travel and hospitality provider, is seeking a Senior IT Compliance & Audit Analyst to join their team! This position is responsible for supporting enterprise access governance, IT SOX compliance, audit readiness, and supporting IT SOX relevant risk management activities across critical systems and infrastructure. This role partners with technology, security, business, audit, and compliance stakeholders to ensure effective SOX IT General controls, regulatory compliance, and remediation of identified gaps from IT SOX audit. The ideal candidate will have experience in IT General Controls (ITGCs), user access reviews, SOX compliance, audit support, identity governance, and IT SOX risk assessments, with a strong understanding of access and change management controls across applications, databases, operating systems, cloud platforms, and infrastructure environments.Core ResponsibilitiesConduct periodic user access reviews across applications, databases, cloud platforms, operating systems, and infrastructure environmentsFacilitate access certification campaigns using established standard operating procedures and automated Identity Governance and Administration (IGA) solutionsPartner with management and system owners to design, review, and enhance role-based access controls (RBAC) and user provisioning processes to ensure compliance with policiesAssess user access appropriateness, identify excessive privileges, and support remediation of access-related risksSupport Segregation of Duties (SoD) reviews and identify potential conflicts across critical business systemsDevelop familiarity and expertise with Identity Governance solutions such as: Saviynt and Sonrai SecurityOther access governance and cloud entitlement management platformsPerform testing and evaluation of IT General Controls (ITGCs), IT Application Controls (ITACs), and System Development Life Cycle (SDLC) controlsExecute control testing related to: User access management, privileged access management, change management, data validity controls, interface controls, platform and infrastructure controls, and segregation of Duties (SoD)Support all phases of SOX compliance activities, including planning, walkthroughs, test plan development, testing execution, documentation, and reportingConduct Test of Design (TOD) and Test of Operating Effectiveness (TOE) assessments for IT SOX controls supporting key business processesPrepare clear, complete, and accurate audit workpapers in accordance with internal audit and compliance standardsReview IT SOX controls across enterprise technologies including SAP, Workday, Windows, Unix/Linux, databases, cloud services, and other critical applicationsCollaborate with internal auditors, external auditors, and regulatory examiners as needed during audit and assessment activitiesCoordinate stakeholder support for audit requests, evidence collection, walkthroughs, and testing activitiesDocument IT SOX audit findings, control deficiencies, observations, recommendations, and management responsesTrack remediation activities and drive resolution of IT SOX audit findings and control gaps through completionFacilitate status meetings and provide reporting on remediation progress to management and leadershipPerform validation testing of remediation activities to confirm effectiveness and closureCollaborate with process owners, control owners, risk management teams, and technology leadership to strengthen enterprise control environmentsParticipate in governance meetings to address access management risks, IT SOX audit findings, and compliance requirementsEducate stakeholders on IT risk, SOX compliance responsibilities, access governance requirements, and control best practicesReview and evaluate policiesRequired Skills/Experience (Must-Haves)Identity Lifecycle Management: Manage the lifecycle of user identities, including provisioning, de-provisioning, and role-based access controlUser Provisioning and De-provisioning: Assist in the processes for user account creation, modification, and termination, ensuring timely and secure access for employees and contractorsCompliance and Reporting: Ensure adherence to identity management standards and provide regular reports on identity management practices and compliance to stakeholdersAnalytical Thinking: Dissect complex data to identify and mitigate security threatsProblem-Solving: Quickly address and resolve security incidents and vulnerabilitiesAttention to Detail: Ensure accurate monitoring, analysis, and documentation of security eventsCommunication: Clearly convey technical information to stakeholders and document incidentsTeamwork and Collaboration: Work well in a team and coordinate efforts during security activitiesAudit and Compliance: Support the execution of regular audits of access controls and directory services to ensure compliance with internal policies and external regulations. Assist in addressing any identified issues or gapsIncident Response and Troubleshooting: Assist in the response to and resolution of access-related security incidents and service requests. Support the troubleshooting and resolution of issues related to user access and directory servicesCollaboration: Work closely with end users to troubleshoot issues, and provide clear guidance, while ensuring a postitive and efficient support experience End User Training: Develop training for end users, focusing on Identity Lifecycle Management and Application Access best practicesPreferred Skills/Experience (Nice-to-Haves)Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field; advanced degree preferredUnderstanding of IAM technologies and protocols (such as SAML, OAuth, LDAP, IGA, MFA and PAM) Experience with technologies and concepts such as SSO, RBAC, directory services, certificates and secrets managementFamiliarity with cloud platforms (e.g., AWS, Azure, Google Cloud) and their security featuresKnowledge of regulatory compliance and industry standards (e.g., GDPR, PCI-DSS, ISO 27001)Work EnvironmentLocation: Fort Woth, TexasCompensation & BenefitsPay Range: The approximate pay range for this position is between $50 and $60/hr. Please note that the pay range provided is a good faith estimate. Final compensation may vary based on factors including but not limited to background, knowledge, skills, and location. We comply with local wage minimums.Medical, Dental, & Vision Insurance PlansEmployee-Owned Profit Sharing (ESOP)401K offeredAbout KellyMitchell At KellyMitchell, our culture is world class. We’re movers and shakers! We don’t mind a bit of friendly competition, and we reward hard work with unlimited potential for growth. This is an exciting opportunity to join a company known for innovative solutions and unsurpassed customer service. We're passionate about helping companies solve their biggest IT staffing & project solutions challenges. As an employee-owned, women-led organization serving Fortune 500 companies nationwide, we deliver expert service at a moment's notice.Marketing Disclosure By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from KellyMitchell and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at https://www.careers.kellymitchell.com/privacy-policy