Identity & Access Management Analyst

Posted 1hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

IAM Analyst operating access controls across U.S. FinTech’s cloud mortgage-securitization platform. Managing lifecycle operations, certifications, automation, audits, and incident response.

Responsibilities:

  • Support the Identity and Access Management program across cloud and remote locations
  • Execute IAM controls and lead efforts to improve their effectiveness
  • Monitor, facilitate, and operate identity and access lifecycle management controls
  • Implement and operate NIST 800-53 Rev. 5 controls for AWS, AWS-hosted applications, SaaS, and other services
  • Manage, report, and facilitate access certification for in-scope SaaS, AWS, Azure, and company-managed resources
  • Operate directory-based provisioning using MS Active Directory Domain Services, Azure Active Directory, and AWS IAM Services
  • Manage end-user accounts, access groups, entitlements, and ownerships
  • Manage account, group, entitlement, and ownership changes based on requests
  • Ensure privileged identity lifecycle management tools and processes are properly used
  • Continuously monitor IAM controls for effective operation
  • Provision access to SaaS cloud-based services based on business needs
  • Respond to internal audit and third-party assessment requests, including control walkthroughs and evidence presentation
  • Investigate and resolve control issues, focusing on automation and operational efficiency
  • Participate in cybersecurity incident response, incident investigations, and audit reporting
  • Support a 24/7 coverage schedule as needed, including weekends
  • Lead IAM readiness for Disaster Recovery Management Plans and support disaster recovery exercises
  • Develop, maintain, and enhance IAM strategies, policies, standards, and guidelines
  • Communicate consistently with stakeholders using a customer-centric approach

Requirements:

  • Bachelor's degree or equivalent experience in an IT related field
  • Minimum 2 years' experience with Identity and Access Lifecycle Management Operations and Controls
  • Minimum 2 years' experience supporting and operating Cloud IAM Services, AWS preferred
  • Minimum 2 years' experience supporting MS Active Directory Domain Services, Azure Active Directory (MS Entra ID), Azure Web Federation and Active Directory Connect
  • Minimum 1 year's experience supporting Privileged Identity Management Tools
  • Minimum 1 year's experience with scripting (PowerShell, JSON, and Python etc.)
  • Experience with IAM controls aligned with ISO 27001/2, FISMA or NIST guidelines
  • Experience working across teams and delivering IAM services across business lines
  • Working knowledge and practical use of Sailpoint IdentityNow, Okta, common OS and domain structures, LDAP, servers, services, and directory services
  • Hands-on experience with MS Directory Services Products, including Active Directory, Azure, Entra ID, Office 365, Exchange, SharePoint, and MS Teams
  • Hands-on experience with ServiceNow Ticketing System for integration with Sailpoint and other connected systems
  • Working experience managing Access Certification campaigns in Sailpoint
  • Experience enabling automation for identity lifecycle management and scripting technologies
  • Experience with Windows, Linux, Red Hat, and related hosts, operating systems and applications
  • Excellent interpersonal, presentation, verbal, and written communication skills
  • Ability to document and explain processes and procedures to business and technical stakeholders
  • Ability to influence peers and management and work cross-functionally
  • Solid understanding of information security policies, standards, and industry leading practices
  • Organizational and time-management skills
  • Ability to manage multiple priorities, projects, deliverables, and stakeholders
  • Willingness to learn new technology and tools and create new processes
  • Must be authorized to work in the US without requiring employer sponsorship currently or in the future
  • Candidate will be part of an after-hours and weekend on-call rotation
  • CISSP, CISA, Microsoft, AWS certifications or equivalent designation desired
  • Experience with DR/BCP planning for IAM services desired
  • Experience using IGA/IAM and PIM tools, including Thycotic Secret Server, is a plus
  • Experience with SIEM tools such as Splunk and Rapid7 is a plus
  • Familiarity with Jira for project and time tracking is a plus

Benefits:

  • Performance bonus
  • 401k match
  • Healthcare coverage
  • PTO
  • Broad range of other benefits