Job ID: U#1234 - Senior IAM Analyst
PLEASE NOTE: This is a 12 month contract to hire and needs to meet Client full-time conversion policies. Those dependent on a work permit sponsor now or anytime in the future (ie H1B, OPT, CPT, etc) do not meet Client requirements for this opening.
The Global Cybersecurity IAM Analyst will be responsible for implementing robust identity and access management strategies and solutions to ensure the security and integrity of our organization’s digital assets. They will work closely with the business and application teams to ensure that the right people have access to the right resources. This position will report to the Global Cybersecurity IAM Director.
Responsibilities:
· Serve as a subject matter expert for identity and access management solutions, including identity governance and administration (IGA), Active Directory, privileged access management (PAM), identity synchronization and provisioning, public key infrastructure (PKI), and related IAM platforms, frameworks, and tools.
· Support the development, enforcement, and remediation of IAM policies, standards, procedures, and controls.
· Participate in audits and access management process walkthroughs, address control deficiencies, and provide accurate, timely audit evidence.
· Ensure IAM activities comply with corporate policies, ethical standards, security requirements, and applicable regulations.
· Understand and be able to articulate the company’s IAM strategy.
· Develop IAM metrics, KPIs and concise reports to upper management to track progress and measure success.
· Understand the various IAM tools and technologies available and be able to recommend solutions that will meet the company’s needs.
· Lead IAM projects from planning through implementation, including requirements gathering, resource coordination, timeline management, testing, deployment, and operational transition.
· Apply security principles, including least privilege, access governance, segregation of duties, and risk-based access controls, across IAM processes and solutions.
· Manage day-to-day IAM operations, resolve escalations, and support the timely resolution of identity, access, and provisioning issues.
· Support and oversee automated identity lifecycle, access provisioning, access request, and governance processes across the organization’s identity management ecosystem.
· Collaborate with cybersecurity, infrastructure, application, audit, and business teams to integrate IAM solutions effectively into the enterprise environment.
· Configure and maintain Saviynt connectors and onboard applications such as Microsoft Entra ID, Oracle EBS, and Salesforce. Responsibilities include requirements gathering, configuration, testing, troubleshooting, deployment, and ongoing support.
· Troubleshoot IGA workflows, provisioning failures, connector and integration issues, access requests, and identity lifecycle processing across integrated applications.
· Design, launch, and manage user access review and certification campaigns in Saviynt, including campaign configuration, completion tracking, escalation, and remediation.
· Build and maintain segregation of duties (SoD) rulesets and mitigating controls, and support SoD violation review and remediation.
· Configure Saviynt access request workflows, rules, and approval processes. Use Saviynt analytics and reporting capabilities to monitor performance and support audit evidence.
· Follow the Underwriters Laboratories Code of Conduct and follow all physical and digital security practices.
· Perform other duties as assigned.
Qualifications:
· Bachelor's degree in computer science, information security, or a related field
· 6+ years of experience in Identity and Access Management
· In-depth knowledge of IAM concepts, technologies, and frameworks.
· Experience with Access Management (AM) tools such as Microsoft Azure, Okta, Oracle, or Ping Identity.
· Hands-on experience with an Identity Governance and Administration (IGA) platform required, including experience supporting or implementing IGA capabilities. Saviynt Identity Cloud experience strongly preferred; experience with SailPoint, Oracle, or a similar enterprise IGA platform will also be considered
· Knowledge or experience with Privileged Access Management solutions such as Delinea (Thycotic/Centrify), Beyond Trust, CyberArk.
· Multi-Factor Authentication technology knowledge or experience such as Azure AD MFA, Duo, Okta.
· Strong understanding of security principles, access controls, and authentication protocols.
· Proficiency in MS Office Suite (Excel, Word, PowerPoint)
· Knowledge and understanding of legal and regulatory requirements, such as: Sarbanes-Oxley Act (SOX), Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry/Data Security Standard, GDPR, and PIPL.
· Knowledge of information security risk management frameworks and compliance practices, including ISO 27001, SOC2 Type 2, and NIST 800-30
· Industry certifications such as CISSP, CISM, or IAM certifications are a plus
· Experience deploying passwordless authentication is a nice to have.
· Knowledge of Customer IAM is beneficial.
· Oracle EBS and Oracle Cloud experience preferred, including integrating Oracle applications with an IGA platform and supporting SoD controls.
Knowledge and Skills:
· Advanced knowledge of identity and access management methodologies, principles, and best practices.
· Demonstrated ability to implement and manage IAM solutions that protect digital assets and support business and security requirements.
· Ability to identify IAM risks, implement appropriate mitigations, and lead the response and resolution of IAM related security incidents.
· Experience establishing IAM governance processes, policies, standards, and controls aligned with regulatory requirements and industry practices.
· Ability to define IAM metrics and key performance indicators, evaluate program effectiveness, and present clear insights about the organization’s IAM posture to senior leaders.
· Knowledge of authentication technologies and protocols, including multi-factor authentication (MFA) and passwordless authentication as methods to enhance the security of user logins and transactions.
· Expertise in identity lifecycle management, including provisioning, deprovisioning, access requests, entitlement management, and access reviews.
· Strong understanding of access control models, including role-based access control (RBAC), least privilege, and privileged access management.
· Ability to translate technical and security concepts into clear business language for executives and other stakeholders.
· Ability to manage competing priorities and deliver quality results in a demanding, deadline-driven environment.
· Strong analytical and troubleshooting skills, with the ability to resolve complex IAM, integration, authentication, and access related issues.
· Strategic mindset with the ability to incorporate business requirements, security priorities, and risk considerations into technical roadmaps.
Professional Attributes:
· Confident, self-motivated professional with strong interpersonal skills, initiative, and a sense of urgency.
· Excellent written and verbal communication, project administration, and stakeholder management skills.
· Strong analytical, problem-solving, organizational, and attention-to-detail capabilities.
· Ability to work independently and collaborate effectively across technical, business, cybersecurity, and application teams.
· High standards of integrity, accountability, and ethical conduct.
· Commitment to continuous improvement and operational excellence.