We are looking for an experienced IT audit specialist to support a passwordless authentication audit for a long-term contract engagement based in Cincinnati, Ohio. This role is well suited for a manager or senior consultant who brings strong knowledge of authentication controls, infrastructure environments, and audit execution within complex enterprise settings. The assignment is expected to begin in late June and will contribute to key Q3 audit efforts, with a focus on assessing control design, technical implementation, and risk exposure related to passwordless authentication.
Responsibilities:
• Lead and support audit activities focused on passwordless authentication controls, including planning, walkthroughs, testing, and documentation.
• Evaluate authentication processes across infrastructure and directory services to identify control gaps, risks, and areas requiring remediation.
• Review Microsoft Active Directory configurations and related access controls to assess alignment with security and audit expectations.
• Analyze IT application controls and broader IT general controls that support identity, access, and authentication processes.
• Partner with stakeholders to gather evidence, clarify technical configurations, and validate how passwordless authentication is implemented in the environment.
• Develop clear audit observations, risk summaries, and supporting workpapers that can be used for reporting and follow-up activities.
• Apply audit frameworks and control standards, such as COBIT and ITGC principles, when assessing the effectiveness of the control environment.
• Contribute subject matter expertise during Q3 audit execution and provide practical recommendations to strengthen authentication governance and control maturity.