> Markdown version of [/jobs/ext/2468214-it-identity-governance-analyst](https://www.wearedevelopers.com/jobs/ext/2468214-it-identity-governance-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Identity Governance Analyst - **Company:** Banc of California - **Location:** Escondido, CA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Identity and Access Management, Role-Based Access Control, IT General Controls (ITGC), Information Technology, SailPoint - **Published:** August 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3bd5363308c360ad ## About the Role * Bachelor's degree in Information Technology, Information Systems, or a related field (or equivalent experience). * 3+ years of experience in identity governance, access management, IT controls, or a related operational role. * Hands-on experience supporting or executing access reviews, certifications, or compliance processes. * Strong organizational and tracking skills with the ability to manage multiple campaigns concurrently. * Excellent written and verbal communication skills, particularly with non-technical users., * Experience using Identity Governance & Administration (IGA) platforms such as Saviynt or SailPoint. * Familiarity with access control concepts including RBAC, least privilege, and segregation of duties (SOD). * Experience supporting audit or compliance activities (e.g., SOX, internal audit). * Comfort working with reporting, evidence collection, and control documentation. * High School diploma or equivalent required ## Description The IT Identity Governance Analyst is responsible for the execution and operational management of identity governance controls, with a primary focus on user access review (UAR) campaigns, reviewer support, and post-certification validation activities. This role partners with IT, application owners, information security, and audit teams to enforce access controls, execute user access reviews, and support compliance with regulatory and internal control requirements. The Analyst partners closely with the AVP, IT Identity Governance Engineer, who is responsible for onboarding applications and enabling technical configurations within the Identity Governance & Administration (IGA) platform (Saviynt). While the Engineer ensures that applications are technically ready for governance, the Analyst runs the governance process itself, coordinating campaigns, supporting reviewers, monitoring progress, and validating remediation outcomes. This role is highly execution-oriented and requires strong organizational skills, attention to detail, and the ability to support business users through access certification activities at scale. Performs all duties in accordance with the Company's policies and procedures, all U.S. state and federal laws and regulations, wherein the Company operates. HOW YOU'LL MAKE A DIFFERENCE Access Review & Certification Execution * Create, launch, and manage user access review campaigns within the IGA platform (Saviynt). * Coordinate campaign schedules, milestones, and deadlines in alignment with governance requirements. * Monitor campaign progress, track completion status, and manage escalations for overdue reviews. * Validate campaign scope to ensure appropriate users, roles, and entitlements are included prior to launch. * Ensure campaigns are closed in accordance with governance standards and documentation requirements. Reviewer & End-User Support * Provide direct support to reviewers and certifiers performing access reviews. * Respond to questions related to review expectations, certification decisions, and platform navigation. * Develop and maintain user guidance materials, job aids, and FAQs for access review participants. * Partner with business stakeholders to resolve issues that could delay or impact campaign completion. Revocation Validation & Lookback process * Perform post-certification lookback process to confirm that revoked access was successfully removed. * Coordinate with technical teams when remediation actions fail or require follow-up. * Track and document revocation exceptions, delays, and corrective actions. * Ensure evidence of revocation and remediation is complete, traceable, and audit-ready. Campaign Reporting & Evidence Management * Produce status reporting on active and completed access review campaigns. * Maintain documentation and evidence supporting campaign execution and outcomes. * Support audit and compliance requests by providing access review artifacts and explanations. * Identify recurring issues or patterns that impact review quality or timeliness and escalate appropriately. Collaboration with Identity Governance Engineering * Partner with the AVP, IT Identity Governance Engineer to: + Validate that newly onboarded applications are ready for access review execution. + Provide feedback on campaign behavior, reviewer experience, and remediation outcomes. * Participate in testing and validation of new campaign configurations prior to production use. Continuous Improvement * Identify opportunities to streamline campaign execution and reduce manual effort. * Provide input on improvements to review workflows, reviewer experience, and reporting. * Contribute to the evolution of standardized access review operating procedures. * Follow all established policies and procedures. * Perform other duties and projects as assigned. ## Related Videos - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Un-complicate authorization maintenance](https://www.wearedevelopers.com/videos/889-un-complicate-authorization-maintenance) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [How to Write a CV and Interview if You Don't Fully Qualify For The Job](https://www.wearedevelopers.com/magazine/183-how-to-write-a-cv-and-interview-if-you-don-t-fully-qualify-for-the-job)