Position: IAM Security Engineer
Location: Onsite 4 days a week in Lutz FL
Duration: 6-month contract to hire
The goal is not to hire administrators or analysts performing day-to-day operational work. IBM already provides Tier 1/Tier 2 support and routine administration.
The organization needs senior-level IAM and Data Security professionals who drive maturity, innovation, and strategic execution.
MUST HAVES:
- CyberArk / Idira – Need an SME, not an administrator. Someone who can provide strategic direction, mature the organization's use of the platform, and guide future CyberArk/PAM capabilities. Performing day-to-day operational work.
- Privileged Access Management (PAM)
- The organization needs senior-level IAM and Data Security professionals who drive maturity, innovation, and strategic execution.
- Roughly 5+ years preferred
- Automate manual processes where possible
- Develop roadmaps and execution plans
- Partner with IBM rather than perform outsourced operational tasks
- Have engineering/problem-solving mindsets rather than ticket-processing backgrounds
POSITION CONCEPT
The IAM Security Engineer is responsible for operating the company’s information security systems, ensuring that all procedures are followed on a daily, weekly, and monthly basis. Provides expert level support, within a team environment, for all systems used to secure the enterprise information technology assets, the scope includes all network infrastructure, operating systems, and web server platforms throughout TECO Energy and its subsidiaries. Direct assistance with the development and enhancing of IAM systems including SSO, authentication, and access controls ensuring confidentiality, integrity, and availability of IAM systems and data. Provides IAM Security support for the TECO environment primarily focusing on SAP and Non-SAP Corps applications, NERC Applications. Responsible for adhering to established policies, following best practices, developing, and possessing an in-depth understanding of exploits and vulnerabilities, resolving issues by taking the appropriate corrective action, or following the appropriate escalation procedures. Supports the enforcement of corporate, regulatory, and risk management policies and assists in developing, maintaining, and publishing corporate IAM security standards, procedures, and guidelines for enterprise computing platforms. Position will be responsible for collaborating with multiple business units across Tampa Electric (TEC), Peoples Gas (PGS), New Mexico Gas (NMG), and Emera.
PRIMARY DUTIES AND RESPONSIBILITIES
- Lead, develop and maintain a strategic roadmap for Identity and Access Management (IAM) aligned with both business and technological objectives. Collaborate closely with teams including Cyber Security, Human Resources, RPA, and Lines of Business (LoBs) to create efficient and user-friendly IAM solutions. (20%)
- Lead, design, and implement access control policies and authorization mechanisms to govern user access to systems, applications, and data. Enforce the principle of least privilege to minimize security risks. (20%)
- Design, Implement and maintain IGA processes, including role-based access control (RBAC), certification, and compliance monitoring. Conduct regular access reviews and audits to ensure compliance with policies and regulations. (20%)
- Enforce security policies related to authentication, password management, and session management. Monitor, respond to security incidents related to unauthorized access attempts and troubleshoot the incidents. (10%)
- Serve as Subject Matter Expert (SME) for audit, compliance, and regulatory efforts pertaining to IAM, SOX, and PII through investigating, documenting, and reporting to management. (10%)
- Deploy and manage SSO solutions to enhance user convenience while maintaining security. Integrate applications to enable seamless and secure authentication across multiple systems. (10%)
- Effectively collaborate with both Technical and Non-technical business owners, highlighting strong interpersonal skills. Actively seek opportunities to optimize the use of IAM toolsets and processes in support of business goals and provide innovative ideas. (10%)
Knowledge/Skills/Abilities (KSA)
- Proficient understanding of RBAC roles, including their assignment, coupled with a practical grasp of authorization object concepts.
- Advanced/Expert knowledge of the identity lifecycle management by designing workflows for user onboarding, offboarding and changes.
- Advanced/Expert understanding of Developing scripts, connectors, or custom code to enhance IAM functionality and address specific requirements.
- Advanced Knowledge of position based security and how roles are assigned to positions on the org structure. This includes advanced troubleshooting of access issues related to position-based security
- Advanced knowledge of how structural authorization is used via the org structure to restrict access to HR data. Authorizations are based on a user’s position within the org structure. Should also have advanced knowledge of the other configuration, organizational structure, and structural profile considerations, which govern what users, can do & on what HR data they can operate
- Advanced/Expert knowledge of the use of reporting tools and privileges concepts
- Advance knowledge of Customizing IAM solutions to align with specific business needs and processes and Integrate IAM systems with other applications, directories, and platforms.
- Advanced knowledge of Reporting tool security as it relates to securing access to various reports, applications, connections, WEBI's, performing certain functions within certain related objects along with creating users.
- Advanced knowledge of the SAP portal architecture and user administration and how it handled through portal frontend along with troubleshooting knowledge of said architecture. Perform SAP security and authorizations duties, including Portal Roles, Single-Sign-On, Directory services, and securing Internet Transaction Server / web services
- Advanced knowledge of established system security control policies as it relates to GRC. Ability to analyze application authorization/privileges assignments and segregation of duties (SOD) conflicts, works with internal audit and compliance teams to resolved identified violations. Functional knowledge and implementation experience of GRC Access Control
- Working knowledge of the processes that ensure compliance with NERC, CIP, SOX, NIST and PCI;
Preferred:
- General knowledge of Active Directory (AD) or other LDAP Directory Services, especially querying/updating through scripts/programs
- Multi-Factor Authentication (MFA) technology – skills deploying and supporting MFA technology for internal and internet-facing application requirements.
- Single Sign-On (SSO) technology – skills deploying and supporting Single Sign-on (SSO) applications within an organization. Must include support skills such as tracing, logging, and real-time troubleshooting. Federated SSO - Security Assertion Markup Language (SAML) and/or OpenID Connect (OIDC) skills required to support both internal and vendor authentication.
- Knowledge of Privilege Management and Muti factor Authentication (MFA) tools. Knowledge and support of Azure AD groups
Key Direction from Manager
The goal is not to hire administrators or analysts performing day-to-day operational work. IBM already provides Tier 1/Tier 2 support and routine administration.
The organization needs senior-level IAM and Data Security professionals who drive maturity, innovation, and strategic execution.
Core Hiring Philosophy
Target candidates who:
- Challenge the status quo
- Identify gaps and opportunities proactively
- Drive program maturity and modernization
IAM Role Expectations
- These individuals should spend approximately:
- 90%+
- Program maturity
- Engineering
- Roadmap execution
- Integration planning
- Process improvement
- Partner governance
- Automation
- Audit readiness improvements
Less than 10%
- Manual certifications
- Administrative tasks
Examples:
- Expanding integrated applications from 7 to 14
- Building IAM roadmap execution plans
- Identifying non-human identity gaps
- Developing PKI/certificate management strategies
- Improving audit evidence collection through automation
Desired IAM Candidate Profile
Experience
- Strong candidates with less experience may be considered if they demonstrate significant accomplishments
Preferred Background
Experience with:
- CyberArk / Palo Alto PAM
- IGA platforms
- Microsoft Identity
- SSO
- Access Management
- Authentication systems
Nice-to-have certifications:
- CyberArk certifications
- IGA certifications
- Microsoft identity certifications
Ideal Traits
- Engineering mindset
- Problem solver
- Process improvement focus
- Ability to build programs from the ground up
- Strong analytical skills
- Self-directed