FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

IT Audit and Controls Analyst
FCamara Consulting & Training. Analyze scenarios involving the granting, modification, review, revocation, and recertification of access .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Identity and Access Management (IAM) processes, including Privileged Access Management (PAM), and evaluates access controls to ensure compliance with security standards. Proficient in IT audit practices, risk management, and technical writing to support internal and external audits.
Highest-signal resume keywords
Identity And Access Management (IAM)Privileged Access Management (PAM)IT Audit ExperienceRisk Assessment MethodologiesCISA Certification
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Access Control EvaluationTechnical Evidence AnalysisControl Effectiveness TestingAudit Process KnowledgeSegregation Of Duties
Soft Skills
Technical WritingCommunication Skills
Tools & Technologies
CyberArkSailPointBeyondTrustMicrosoft Entra ID
Certifications & Qualifications
CISACRISCCISMISO 27001
Industry Keywords
IT Internal ControlsTechnology Risk ManagementFinancial SectorCentral Bank Regulatory RequirementsCOBITISO/IEC 27001NIST
Tech Stack
Tools & technologiesAWS
About the role
Key responsibilities & impact- Analyze scenarios involving the granting, modification, review, revocation, and recertification of access
- Evaluate identity and access management (IAM) controls, particularly technical and privileged access
- Validate access to systems, applications, databases, and infrastructure environments
- Evaluate access profiles according to the principles of least privilege, need-to-know, and segregation of duties
- Identify risks related to inappropriate access, excessive permissions, privileged accounts, service accounts, and technical credentials
- Execute IT internal control testing, including evidence analysis, sampling, deviation identification, and results documentation
- Assess the effectiveness of preventive, detective, and corrective access security controls
- Support internal and external audits by organizing evidence, identifying nonconformities, and monitoring action plans
- Prepare technical reports detailing risks, potential impacts, and improvement recommendations
- Collaborate with Information Security, Infrastructure, IAM, IT Governance, Risk, and Compliance teams
Requirements
What you’ll need- Professional experience in IT audit, technology internal controls, technology risk management, or information security
- Knowledge of identity and access management (IAM) processes, including privileged access management (PAM)
- Experience evaluating logical access controls, authorization profiles, and segregation of duties
- Knowledge of risk assessment methodologies and control effectiveness testing
- Familiarity with COBIT, ISO/IEC 27001, ISO/IEC 27002, and NIST
- Ability to analyze technical evidence, logs, permission reports, and access matrices
- Knowledge of audit processes, including test planning, findings documentation, and remediation tracking
- Strong technical writing and communication skills
- Experience in IT audit and risk consulting, particularly with the Big Four or similar firms, is preferred
- Experience in IT Internal Audit, Internal Controls, IT Risk, IT Compliance, or Information Security is preferred
- Experience in the financial sector, digital banks, fintechs, or environments regulated by the Central Bank is preferred
- Knowledge of IT general controls (ITGC) is preferred
- Experience with CyberArk, SailPoint, BeyondTrust, or Microsoft Entra ID is preferred
- Knowledge of access controls in AWS environments, operating systems, databases, and enterprise applications is preferred
- Familiarity with Central Bank regulatory requirements and cybersecurity guidelines is preferred
- CISA, CRISC, CISM, ISO 27001, or equivalent certifications are desirable
Benefits
Comp & perks- Position also open to people with disabilities
- Professional development opportunities through initiatives such as the Orange Juice tech community, the Training Program, and the Leadership School
- Partnerships with NGOs and EdTech companies
- Inclusive environment where diversity, respect, and ethics are core values
- Hybrid work