Job#: 3044484 Job Description: Job DescriptionOverviewUnder the general direction and supervision of the Chief Information Security Officer, the Identity and Access Management Architect (IAM) has responsibility for the lifecycle planning, design, installation and support of the corporate security strategy, architecture, and practices. Lead the definition and execution of the organization?s IAM strategy, aligning with the overall enterprise security and technology roadmap and serve as the top-tier authority on all IAM topics, with an emphasis on integrating cloud and on-premises enterprise architectures. Develops implementation plans, coordinates implementation of security related systems verifying the installation of hardware, software, and security management tools. Works at a technical level and maintains effective communication with management teams and across user departments, and other support organizations. The IAM security architect will be required to effectively translate business objectives and risk management strategies into specific processes enabled by security technologies and services. This position is responsible for and has oversite of the execution of all cybersecurity and compliance requirements associated operational tasks required to implement a highly scalable and secure multi-vendor health-care application landscape. Documents and communicates all security changes that take place across the YNHHS applications, network, and platforms according to the established organizational procedures and standards of the clients Digital & Technology Solutions (DTS).
Responsibilities- Responsible for the evaluation, architecture and delivery of advanced technology solutions while demonstrating a high degree financial awareness and consideration of final objectives.
- Determine requirements, develop, and recommend security solutions, capabilities, and controls that are aligned with business objectives, technology, and threat drivers.
- Evaluate, assess, and recommend improvements to statements of work and proposals from vendors to ensure that adequate security protections are in place for security-related deficiencies and required "user controls," and report any findings to the CISO and vendor management teams.
- Develop and maintain security architecture, design, and roadmap documents. Develop and present detailed strategies, designs, and implementation plans to management.
- Deliver complex customized designs and solutions aligned to defense in depth strategies by self and by collaborating with peers, vendors, and stakeholders.
- Test, evaluate, and review security technologies, tools, and services aligned to business goals and make recommendations to the broader security team for their use based on security, financial and operational metrics.
- Track developments and changes in the digital business and threat environments to ensure that the YNHHS healthcare applications' landscape is adequately protected by existing security controls.
- Responsible for setting technical direction, scope, quality metrics, planning, execution and closing of technical projects.
- Determine baseline security configuration standards for operating systems, applications, network segmentation, and identity and access management.
- Provide high level of technical skill to enable resolution of complex security and identity and access related technology problems throughout the project lifecycle.
- Work collaboratively across technical, customer, and management constituencies to ensure a quality and timely service delivery.
- Perform other job duties and responsibilities as assigned.
QualificationsEDUCATIONBachelor's degree in Computer Science or related discipline and/or extensive technical training and related experience.
EXPERIENCE- At least ten (10) years of experience in a technical services function in a complex distributed enterprise network and application environment.
- Hands-on experience in managing and designing IAM technologies and services (e.g. SailPoint IdentityIQ, Active Directory / EntraID IAM solutions in a large environment is required.
- Ability to automate complex access management and authentication policies for on-prem and cloud hosted applications at an expert level required.
- Skilled at collaborating with peers and socializing IAM governance and strategy with senior leadership and executives.
- Working knowledge of Microsoft Purview, Azure IaaS security and data protection controls (e.g. data loss, encryption, conditional access, data classification).
- Experienced in the following areas: security architecture, design, implementation, and integration management for full stack IT infrastructure (applications, scripting, databases, operating systems, hardware, IP network, and test planning in a dynamic continuous improvement environment.
LICENSURE- Certified Information Systems Security Professional (CISSP) certification or within 12-24 months in role, Microsoft Azure security certifications technologies and SailPoint Identity management experience required .
- Sailpoint IdentityIQ certification is desirable.
SPECIAL SKILLS- In depth knowledge delivering IAM and cloud security capabilities in a hybrid hosting model.
- Optimize RBAC controls and map workflows for individuals / groups and perform certification based on segregation of duties / role.
- Extensive knowledge of IAM technologies and protocols (SSO, MFA, Federation, PAM, OIDC, OAuth, SAML, and SCIM) and the ability to automate / streamline identity workflow scenarios.
- Knowledge of NIST CSF, Health Insurance Portability and Accountability Act (HIPAA)/Health Information Technology for Economic and Clinical Health (HITECH) security concepts where capable of reviewing / performing security assessments for project solutions.
- Ability to work effectively under pressure and function in a fast-paced collaborative team setting.
- Demonstrated capacity to acquire new skills efficiently and ability to blend technical expertise and business perspective.
- Able to make logical decisions regarding the best method to accomplish goals or solve a problem and is guided by precedent and general policy in making decisions.
- Able to coordinate and obtain cooperation of others and to handle controversial issues tactfully.
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.
Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at
Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide.
Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.
If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at or . Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.
UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.