Overview
Skills
Job Details
Overview
We are seeking a skilled and proactive IGA Analyst to strengthen our identity security posture across corporate, frontline, and operational technology (OT) environments. This role will focus on onboarding applications into our enterprise IGA platform, modernizing authentication through FIDO2 and passwordless technologies, and reducing technical debt through robust governance and lifecycle management controls.
Key Responsibilities
<>Application Onboarding & Integration</>Collaborate with application owners to onboard and certify applications into IGA platforms (e.g., Sail Point, Saviynt, Oracle IDCS).
Define and enforce access models, entitlements, and approval workflows.
Implement least-privilege and segregation-of-duties (SoD) controls.
Identify and remediate identity risks such as orphaned accounts and privileged access sprawl.
Support cleanup initiatives for Active Directory (AD), Entra ID, and connected systems.
Contribute to risk-based access policies and automated lifecycle management.
Drive adoption of phishing-resistant authentication (FIDO2, password less).
Migrate legacy authentication flows to modern protocols (Web Authn, OIDC, SAML).
Evaluate security impact and user experience across diverse populations.
Configure and manage federated SSO integrations via Entra ID and other IdPs.
Apply conditional access and adaptive authentication policies.
Align privileged session management with federated access controls.
Partner with IAM engineering, security architecture, and compliance teams.
Document and report metrics on access certifications and identity lifecycle performance.
Provide operational support for IGA platform upgrades and integrations.
Qualifications
Bachelor s degree in Information Security, Computer Science, or related field (or equivalent experience).
3 5 years of hands-on experience in Identity Governance & Administration (IGA).
Strong knowledge of Active Directory, Entra ID, and federated authentication protocols (SAML, OIDC, OAuth2).
Familiarity with platforms such as:
IGA: SailPoint, Saviynt, Oracle IDCS
PAM: BeyondTrust, CyberArk, ManageEngine PAM360
MFA/SSO: Microsoft Entra ID, Duo, Okta, Ping Identity
Working knowledge of Zero Trust, FIDO2, passwordless authentication, and phishing-resistant MFA.
Experience applying IGA controls across corporate, frontline, and OT environments.
Strong analytical, documentation, and communication skills.
Additional Skills
Experience with identity lifecycle automation and RBAC modeling.
Understanding of privilege escalation risks and compliance frameworks (NIST 800-63B, CIS, TSA).
Scripting proficiency in PowerShell, Python, or SQL.
Familiarity with cloud identity models (Azure, AWS, Google Cloud Platform).