Point your AI agent at freehire and let it find you a job.

Get the CLI →

TEKsystems

NewBe an early applicant

IAM Audit & Compliance Analyst

Discussion

Summary

Contract IAM Audit & Compliance Analyst (via TEKsystems) building a net-new IAM audit readiness function for a Fortune 10 pharmaceutical company. Fully remote; owns the entire audit liaison process, maps controls to SOX/NIST/HIPAA/PCI-DSS, manages SOD and evidence automation using SailPoint, ServiceNow GRC, and Active Directory/Azure AD.

Job Title: IAM Audit & Compliance Analyst

Location: 100% Remote

*** At this time, the client is considering candidates who are authorized to work in the U.S. on W2

Description

Fortune 10 global pharmaceutical services and distribution company, is building a net-new IAM Audit and Compliance function within their Identity and Access Management organization. This is an experienced, fully autonomous role responsible for establishing and owning IAM audit readiness as a true BAU capability — not a project. There is no existing program, documentation, or team to inherit. This person is building the foundation from a blank page.

The person in this role will serve as the single lane highway — the sole point of contact — between organization's large IAM organization and every internal and external audit and assessment team. Everything audit-related flows in and out through this person's desk. They own it end to end.

The overarching goal is audit readiness. Not passing audits by the skin of your teeth — but having the right processes, controls, documentation, and evidence in place so that when auditors arrive, can show and prove everything without chasing their tail. Do it the right way the first time, every time.

This role requires someone who runs toward ambiguity, owns their domain without daily direction, and has the experience and confidence to build something that didn't exist before. If a candidate signals they would need handholding or significant oversight, they are not the right fit — Brad's strongest candidate to date was eliminated in round two for exactly this reason.

Key Responsibilities:

Serve as the single IAM liaison for all audit and assessment activity — own the entire process from walkthrough coordination and evidence gathering through action plan development and response delivery back to assessment teams

Ensure audit readiness across the IAM organization — review and train internal IAM team members on updated control standards, what's required, what's not, and how to document and retain evidence properly in an auditable, accessible repository

Map IAM control standards to applicable regulatory frameworks including SOX, NIST, HITRUST, PCI-DSS, HIPAA, and GDPR — identify gaps, assess whether standards are inclusive enough, and drive remediation before auditors find the problems

Develop and manage a Segregation of Duties matrix and ensure no SOD conflicts exist in the environment

Drive automation of evidence collection — serve as the SME who identifies which controls should be automated, partners with IAM dev teams to get tasks prioritized on their backlog, validates that automation is working as intended, and maintains output as ongoing audit proof so evidence is always ready and never has to be scrambled for

Serve as control owner or delegate for IAM preventive and detective controls — define, maintain, and periodically assess control effectiveness and maturity

Govern IAM policy exceptions, remediation plans, compensating controls, and periodic recertification workflows

Validate effectiveness of User Access Review processes and ensure certification controls meet audit and regulatory expectations

Monitor and track IAM-related findings, risks, and issues through ServiceNow GRC — ensure timely remediation and maintain defensible, auditable documentation throughout

Lead cross-functional remediation efforts involving IAM, Application Owners, Infrastructure, IT Controls & Compliance, and HR teams

Provide IAM governance subject matter expertise during new projects and system implementations

Capture and report IAM compliance metrics and contribute to leadership dashboards

Additional Skills & Qualifications

5+ years of hands-on, individual contributor experience in IAM Governance, IT Audit, Compliance, or Risk Management — must have physically performed this work, not managed a team that did

Strong working knowledge of SailPoint IdentityIQ — governance, administration, and operational support experience required

Demonstrated experience supporting SOX, SOC1, SOC2, HITRUST, GDPR, and PCI-DSS compliance requirements specifically within an IAM context

Experience with Joiner/Mover/Leaver processes, Privileged Access Governance concepts, and Access Certification programs

Proficiency with ServiceNow GRC for issue management and tracking

Working knowledge of Active Directory and Azure AD

Advanced Microsoft Excel skills — pivot tables, power query, data validation between source systems and SailPoint

Experience partnering with engineering and development teams to drive control automation initiatives — does not need to be a technical builder but must be the SME who drives it

Strong root cause analysis and incident support capabilities

Certifications highly valued: CISA, CISM, CISSP, CRISC, or CIAM

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent experience

Critical Screening Notes for Recruiters

Must screen for hands-on, solo ownership: Ask candidates to walk you through a specific IAM audit readiness program they built and owned independently. If they keep referencing "the team" or "my manager," they are not the right fit

Screen out the audit testing mindset: If a candidate defaults to talking about sampling, testing, and finding problems — redirect and ask how they design controls proactively. If they can't answer that question confidently, pass

Screen for the communication bridge: Ask them to explain a complex IAM control concept as if they were talking to a non-technical business stakeholder. If they can't simplify it, they won't survive in this role

Handholding is a dealbreaker: Any signal that this person needs daily direction, significant oversight, or a team around them to function is an automatic no

Additional Skills & Qualifications

Essential Skills and Qualifications

• 5+ years of experience in Information Security, IAM Governance, IT Audit, Compliance, or Risk Management, with hands on experience managing audit findings, issue remediation, control testing, evidence collection and more

• Bachelor’s Degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or equivalent experience.

• Demonstrated experience supporting SOX, Internal Audit, external audit, and regulatory engagements for Identity Access Management controls.

• Analytical Skills: High attention to detail, strong analytical thinking, and problem-solving abilities.

• Communication: Strong interpersonal and communication skills in order to support the " non-technical” stakeholders and manage relationships with variety of teams and assessment activities.

• Certifications: While not always required, professional certifications like Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Risk and Information Systems Control (CRISC) and/or Certified Identity and Access Manager (CIAM) are highly valued

• Compliance Knowledge: Working knowledge of IAM frameworks as well as SOX requirements and NIST framework guidance.

SKILLS & KNOWLEDGE:

Behavioral Skills:

• Critical Thinking and Problem Solving

• Detail Orientation and Accountability

• Interpersonal Communication

• Learning Agility and Adaptability

• Multitasking and Time Management

• Collaboration and Teamwork

Technical Skills:

• Working knowledge of SOX, SOC1, SOC2, HITRUST, GDPR

• IT Risk and Compliance Awareness

• Identity Governance and Administration (IGA)

• Joiner, Mover, Leaver (JML) processes

• Segregation of Duties (SOD)

• Privileged Access Governance concepts

• Access Certification Programs

• Root Cause Analysis and Incident Support

• Reporting and Documentation

Tools Knowledge:

• Sailpoint

• Directory Services (Active Directory, Azure AD)

Job Type & Location

This is a Contract position based out of Conshohocken, PA.

Pay and Benefits

The pay range for this position is $65.00 - $70.00/hr.

Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors.

Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: • Medical, dental & vision • Critical Illness, Accident, and Hospital • 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available • Life Insurance (Voluntary Life & AD&D for the employee and dependents) • Short and long-term disability • Health Spending Account (HSA) • Transportation benefits • Employee Assistance Program • Time Off/Leave (PTO, Vacation or Sick Leave)

Workplace Type

This is a fully remote position.

Application Deadline

This position is anticipated to close on Sep 4, 2026.

About TEKsystems

We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company.

The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.

About TEKsystems and TEKsystems Global Services

We’re a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We’re a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. We’re strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. We’re building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com.

The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.

San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.

Massachusetts Lie Detector: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available