Senior IT Compliance & Audit Analyst
Listed on 2026-08-07
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst, IT Consultant
Job Summary:
Our client, a leading travel and hospitality provider, is seeking a Senior IT Compliance & Audit Analyst to join their team! This position is responsible for supporting enterprise access governance, IT SOX compliance, audit readiness, and supporting IT SOX relevant risk management activities across critical systems and infrastructure. This role partners with technology, security, business, audit, and compliance stakeholders to ensure effective SOX IT General controls, regulatory compliance, and remediation of identified gaps from IT SOX audit.
The ideal candidate will have experience in IT General Controls (ITGCs), user access reviews, SOX compliance, audit support, identity governance, and IT SOX risk assessments, with a strong understanding of access and change management controls across applications, databases, operating systems, cloud platforms, and infrastructure environments.
- Conduct periodic user access reviews across applications, databases, cloud platforms, operating systems, and infrastructure environments
- Facilitate access certification campaigns using established standard operating procedures and automated Identity Governance and Administration (IGA) solutions
- Partner with management and system owners to design, review, and enhance role-based access controls (RBAC) and user provisioning processes to ensure compliance with policies
- Assess user access appropriateness, identify excessive privileges, and support remediation of access-related risks
- Support Segregation of Duties (SoD) reviews and identify potential conflicts across critical business systems
- Develop familiarity and expertise with Identity Governance solutions such as:
Saviynt and Sonrai Security - Other access governance and cloud entitlement management platforms
- Perform testing and evaluation of IT General Controls (ITGCs), IT Application Controls (ITACs), and System Development Life Cycle (SDLC) controls
- Execute control testing related to:
User access management, privileged access management, change management, data validity controls, interface controls, platform and infrastructure controls, and segregation of Duties (SoD) - Support all phases of SOX compliance activities, including planning, walkthroughs, test plan development, testing execution, documentation, and reporting
- Conduct Test of Design (TOD) and Test of Operating Effectiveness (TOE) assessments for IT SOX controls supporting key business processes
- Prepare clear, complete, and accurate audit work papers in accordance with internal audit and compliance standards
- Review IT SOX controls across enterprise technologies including SAP, Workday, Windows, Unix/Linux, databases, cloud services, and other critical applications
- Collaborate with internal auditors, external auditors, and regulatory examiners as needed during audit and assessment activities
- Coordinate stakeholder support for audit requests, evidence collection, walkthroughs, and testing activities
- Document IT SOX audit findings, control deficiencies, observations, recommendations, and management responses
- Track remediation activities and drive resolution of IT SOX audit findings and control gaps through completion
- Facilitate status meetings and provide reporting on remediation progress to management and leadership
- Perform validation testing of remediation activities to confirm effectiveness and closure
- Collaborate with process owners, control owners, risk management teams, and technology leadership to strengthen enterprise control environments
- Participate in governance meetings to address access management risks, IT SOX audit findings, and compliance requirements
- Educate stakeholders on IT risk, SOX compliance responsibilities, access governance requirements, and control best practices
- Review and evaluate policies
- Identity Lifecycle Management:
Manage the lifecycle of user identities, including provisioning, de-provisioning, and role-based access control - User Provisioning and De-provisioning:
Assist in the processes for user account creation, modification, and termination, ensuring timely and secure access for employees and contractors - Compliance and Reporting:
…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).