We’re looking for an IAM Compliance Specialist to join Procore’s Governance, Risk & Compliance team. In this role, you’ll manage the execution and documentation of all user access reviews across our financial system landscape. Your primary goal is to mitigate the risk of unauthorized access and ensure strict Segregation of Duties (SoD).
As an IAM Compliance Specialist, you’ll partner with System Admins and Business Process Owners to facilitate the quarterly and annual access certification cycles. Use your analytical skills, knowledge of IAM tools, and audit rigor to ensure the right people have the right access at the right time. Help us secure our most critical data—Join us!
This position reports into the Manager, GRC - SOX and will be based in our Austin, TX office. We’re looking for someone to join us immediately.
What you’ll do:
Coordinate and execute periodic User Access Reviews (UARs) for all SOX-scope applications and infrastructure.
Design and maintain a Segregation of Duties (SoD) matrix for key financial systems, ensuring conflicting responsibilities are identified and mitigated.
Validate that user de-provisioning as identified as part of the user access review process is performed timely and accurately.
Maintain evidence of review approvals and ensure all revocations are completed within the required SLAs.
Partner with IT to automate manual access review processes using GRC or IAM tools.
Support the broader GRC team during external audits by providing specific evidence for Logical Access controls.
Track and report on the status of access reviews to senior leadership to ensure 100% completion.
What we’re looking for:
Bachelor’s degree in Information Technology, Business, or a related discipline.
2-4 years of experience specifically within Identity & Access Management or IT Audit.
Demonstrated experience working with access and change management domains in IT compliance frameworks.
Experience with Role-Based Access Control (RBAC) design and implementation in complex SaaS ecosystems.
Proficiency with IAM and GRC tools such as Okta, Veza, or SailPoint.
Ability to manage high-volume data sets and identify anomalies in user permissions through various means of data analysis.
Strong communication skills to influence busy stakeholders to complete required certifications.
Base Pay Range:
89,120.00 - 122,540.00 USD AnnualProcore will consider for employment all qualified applicants, including those with arrest or conviction records, in accordance with the requirements of applicable federal, state, and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act.
A criminal history may have a direct, adverse, and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment: 1. appropriately managing, accessing, and handling confidential information including proprietary and trade secret information, as well as accessing Procore's information technology systems and platforms; 2. interacting with and occasionally having unsupervised contact with internal/external customers, stakeholders, and/or colleagues; and 3. exercising sound judgment.
| Director, Partner Operations | Austin, Texas, United States |
| GRC Analyst - IAM | Austin, Texas, United States |
| Security Engineer II | Austin, Texas, United States |
| Commercial Sales Development Representative | Carpinteria, California, United States. Austin, Texas, United States |
| Revenue Operations Business Partner, Strategic | Carpinteria, California, United States. Austin, Texas, United States |
Learn about our applicant and candidate privacy policy and about creating a profile on My Settings.
This website uses cookies to improve your browsing.
We use cookies to personalize content such as job recommendations, and to analyse our traffic. You consent to our cookies if you click "I Accept". If you click on "Manage Cookies", then you can decline the use of performance cookies but you may have a deteriorated user experience. You can change your settings by clicking on the Settings link on the top right of the device.
Procore does not sell Personal Data in the traditional sense, please see our Do Not Sell Policy.
A one-time (for page view) session cookie is necessary to provide protection against a security attack called "Cross-site scripting (XSS)".
This cookie is mandatory, short lived (one page interaction) and contains no personally identifiable information.
This website uses 2 performance cookies.
The first is a long term cookie (13 months) used to remember you as a candidate and maintain your preferences.
The second is a temporary session cookie (lasts for 15 minutes or when your session ends) used to tie activity such as form submissions and page views with location data (city, country) and present a more localized and relevant job recommendations and other career related content.