We are looking for a GRC Analyst to support the Compliance team by executing tactical compliance activities with a strong focus on User Access Reviews (UAR), SOX IT General Controls (ITGC) testing, and audit evidence collection for PCI DSS compliance.
Key Responsibilities
User Access Reviews & Identity Governance
- Execute end-to-end periodic User Access Review (UAR) cycles across enterprise applications, databases, and operating systems.
- Analyze user access to identify Segregation of Duties (SoD) violations and excessive privileges.
- Track pending approvals, coordinate with business owners, and prepare remediation reports.
SOX & ITGC Testing
- Perform operating effectiveness testing for IT General Controls (ITGC) covering:
- Change Management
- Logical Access
- IT Operations
- Prepare audit-ready workpapers with appropriate screenshots and supporting evidence.
- Support compliance activities related to SOX and PCI DSS audits.
Required Skills
- 3–5 years of hands-on experience in ITGC testing and User Access Reviews.
- Solid knowledge of GRC Risk and SOX Section 404 compliance.
- Experience with Identity Governance and access management processes.
- Advanced Microsoft Excel skills (VLOOKUP, Pivot Tables).
- Excellent verbal and written communication skills.
Preferred Skills
- Experience working with US-based clients.
- Knowledge of security frameworks such as NIST 800-53 or ISO 27001.
- Ability to work independently and manage multiple priorities within strict timelines.