Business Analyst, IAM Risk & Audit
Listed on 2026-07-29
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst
About Northern Trust
As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions.
About Northern TrustAs a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions.
Since 1889, we have aligned our efforts with our three guiding Principles That Endure:
Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.
With more than 135 years of financial experience and over 24,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.
Position SummaryThe Business Analyst, Identity & Access Management (IAM) Risk & Audit, plays a key role in supporting the organization's IAM governance, risk, and compliance programs. This position partners with IAM engineering teams, risk management, internal audit, compliance functions, and business stakeholders to strengthen the IAM control environment and support regulatory, audit, and risk management activities.
The successful candidate will support control monitoring, audit readiness, reporting, issue remediation, and process improvement initiatives across key IAM capabilities, including Identity Governance & Administration (IGA), Privileged Access Management (PAM), Access Controls, Authentication, Authorization, and Directory Services.
Key Responsibilities Audit & Compliance Support- Support internal and external audit activities related to IAM processes and controls.
- Gather, validate, and deliver audit evidence in accordance with established timelines.
- Assist with regulatory examinations, risk assessments, and compliance reviews.
- Partner with control owners to address audit requests and inquiries.
- Maintain documentation supporting IAM policies, standards, procedures, and controls.
- Support execution and monitoring of IAM controls.
- Assist in identifying control gaps, process weaknesses, and areas for improvement.
- Track audit findings, risk issues, and remediation activities through completion.
- Help ensure IAM processes align with regulatory and security requirements.
- Participate in control testing and validation activities.
- Develop and maintain IAM risk, audit, and compliance reporting.
- Analyze IAM data to identify trends, control exceptions, and operational risks.
- Create dashboards, scorecards, and metrics to support management reporting.
- Assist with KPI, KCI, and control effectiveness reporting.
- Support recurring reporting requirements for leadership and governance forums.
- Identify opportunities to improve audit readiness and control effectiveness.
- Assist in automating manual reporting and evidence collection processes.
- Contribute to the development of standardized documentation and repeatable procedures.
- Support continuous improvement initiatives that improve efficiency and reduce risk.
- Work closely with IAM engineers, risk teams, auditors, and business stakeholders.
- Communicate audit requirements, findings, and remediation progress effectively.
- Participate in risk reviews, control discussions, and project meetings.
- Support knowledge sharing and best practice adoption across the IAM organization.
- Bachelor's degree in Cyber Security, Information Technology, Business, Computer Science, or a related field.
- 3-7 years of experience in Cyber Security, IAM, Risk Management, Audit, Compliance, or related disciplines.
- Understanding of Identity & Access Management concepts and practices.
- Experience working with control frameworks, audit activities, or compliance processes.
- Strong analytical and problem-solving skills.
- Ability to analyze data and produce meaningful reporting.
- Strong organizational…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).