FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

IT Audit and Controls Analyst
FCamara Consulting & Training. Conduct analyses and assessments of controls related to identity and access management (IAM), particularly technical and privileged access .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Identity and Access Management (IAM) and Privileged Access Management (PAM), with a strong focus on risk assessment methodologies, internal controls, and compliance within the financial sector. Proficient in technical reporting and stakeholder relationship management, ensuring effective communication and collaboration across teams.
Highest-signal resume keywords
Identity And Access Management (IAM)Privileged Access Management (PAM)Risk Assessment MethodologiesIT Audit And Internal ControlsTechnical Reporting
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Access Control AssessmentControl Effectiveness TestingTechnical Evidence AnalysisAudit Process KnowledgeIT General Controls (ITGCs)
Soft Skills
Communication SkillsStakeholder Relationship Management
Tools & Technologies
CyberArkSailPointBeyondTrustMicrosoft Entra IDAWS Access Controls
Certifications & Qualifications
CISACRISCCISMISO 27001
Industry Keywords
Financial SectorDigital BanksFintechsCentral Bank RegulationsCybersecurity Guidelines
Tech Stack
Tools & technologiesAWS
About the role
Key responsibilities & impact- Conduct analyses and assessments of controls related to identity and access management (IAM), particularly technical and privileged access
- Validate scenarios for granting, modifying, revoking, and recertifying access to systems, applications, databases, and infrastructure environments
- Assess the adequacy of access profiles in accordance with the principles of least privilege, need-to-know, and segregation of duties
- Identify technology risks associated with inappropriate access, excessive permissions, privileged accounts, service accounts, and technical credentials
- Perform IT internal control testing, including evidence analysis, sampling, identification of deviations, and documentation of results
- Assess the effectiveness of preventive, detective, and corrective controls related to access security
- Support internal and external audits by organizing evidence, identifying nonconformities, and monitoring action plans
- Prepare technical reports detailing identified risks, potential impacts, and improvement recommendations
- Collaborate with Information Security, Infrastructure, IAM, IT Governance, Risk, and Compliance teams
- Work with a banking-sector client, supporting the assessment, validation, and continuous improvement of technical access management controls for corporate environments and systems
Requirements
What you’ll need- Professional experience in IT audit, technology internal controls, technology risk management, or information security
- Knowledge of identity and access management (IAM) processes, including privileged access management (PAM)
- Experience assessing logical access controls, authorization profiles, and segregation of duties
- Knowledge of risk assessment methodologies and control effectiveness testing
- Familiarity with COBIT, ISO/IEC 27001, ISO/IEC 27002, and NIST
- Ability to analyze technical evidence, logs, permission reports, and access matrices
- Knowledge of audit processes, including test planning, documenting findings, and monitoring remediation activities
- Strong technical reporting, communication, and stakeholder relationship-management skills
- Experience in IT audit and risk consulting, particularly with a Big Four firm or similar consultancy, is a desirable differentiator
- Previous experience in IT Internal Audit, Internal Controls, IT Risk, IT Compliance, or Information Security is a desirable differentiator
- Experience in the financial sector, digital banks, fintechs, or environments regulated by Brazil’s Central Bank is a desirable differentiator
- Knowledge of IT general controls (ITGCs) is a desirable differentiator
- Experience with IAM/PAM tools such as CyberArk, SailPoint, BeyondTrust, or Microsoft Entra ID is a desirable differentiator
- Knowledge of access controls in AWS environments, operating systems, databases, and enterprise applications is a desirable differentiator
- Familiarity with regulatory requirements applicable to financial institutions, including Central Bank regulations and cybersecurity guidelines, is a desirable differentiator
- CISA, CRISC, CISM, ISO 27001, or equivalent certifications are a desirable differentiator
Benefits
Comp & perks- The company operates in Brazil, Europe, and the United Kingdom, with offices in Portugal, London, Dubai, and the Netherlands
- Social initiatives and programs focused on development
- Orange Juice tech community
- Training Program
- Leadership School
- Partnerships with NGOs and edtech companies
- An inclusive environment where diversity, respect, and ethics are core values