Info Security Advisor / Sr Advisor Job family - Identity & Access Management (IAM) - PS36452

Security, Access, Management, IT, Application, Disaster Recovery, Cryptography, Risk Management, Environmental, Architecture, Telecommunications, Network, API, JavaScript, Python, Programming, Java, CISSP, Systems, Engineering, Lifecycle, Oracle
Full Time

Job Description

Description
SHIFT: Day Job

SCHEDULE: Full-time

Location: Atlanta, GA/ Indianapolis, IN/ Richmond, VA/ Norfolk, VA/ Mason, OH office

Your innovation. Our impact. At Anthem, Inc., it's a powerful combination, and the foundation upon which we're creating greater access to care for our members, greater health for our communities, and greater experiences for our customers. Innovation is a top priority. Here, you'll have an opportunity to work in a collaborative environment that brings together industry leaders and technology experts, so together we can drive the future of health care.

As an Info Security Advisor/ Sr Advisor (Identity & Access Management (IAM) engineer), you will be responsible for contributing to IAM component designs, IAM service development, service integration, implementation and operations. This position collaborates closely with IAM management, architects, and service providers to implement the IAM Program modernization efforts for the Enterprise.

This position develops, recommends, and implements enterprise information security policies, technical standards, guidelines, procedures, and other elements of an infrastructure necessary to support information security in compliance with established company policies, regulatory requirements, and generally accepted information security controls.

Responsible for the selection and delivery of strategic network security, access control and secure transaction/messaging solutions.

Primary duties may include, but are not limited to:
  • Leads system and network architecture support for information and network security technologies; leads development and execution of risk assessment methodologies to fit business, regulatory, and technical environment considerations; leads the development of requirements, system architecture, and software design of security products and services; leads the development of strategies for discovery, evaluation and response to new networking attacks; develops security incident response plans and strategies.
  • Provides trouble resolution and serves as point of technical escalation on complex problems and be part of the 24/7 On call support team.
  • Creates presentations and seeks IT management approval and acceptance of significant replacements or reconfigurations of major security systems serving the Enterprise.
  • Sets vendor strategy and direction. May be assigned to project teams for technical consultation to business partners and developers.
  • Designs & engineers comprehensive access management and network security technical solutions based on business requirements and defined technology standards; works with architecture to update technology direction & strategy. Develops reports supporting strategy and direction for management.
  • Capable of serving as technical merger & acquisition lead. Acts as a subject matter expert among peers, with manager and senior management.
  • Must be capable of providing top-tier support for 5 or more of the information security technology common body of knowledge skill sets:

1) Access Control, 2) Application Security, 3) Business Continuity and Disaster Recovery Planning, 4) Cryptography, 5) Information Security and Risk Management 6) Legal, Regulations, 7) Compliance and Investigations, 8) Operations Security, 9) Physical (Environmental) Security, 10) Security Architecture and Design, 11) Telecommunications and Network Security.

You should be knowledgeable and be able to demonstrate experience with the following:

- Modern approaches to IT service-oriented architectures and applications. Specifically, good experience with implementing services using Microservices architectures, DevOps, and continuous delivery of IAM services and applications in a hybrid computing environment.

- Services (i.e. REST)/UI/SDK based Integration of role-based access control, Active Directory, LDAP, Single Sign-On, End-User provisioning and identity data synchronization services with existing applications and systems.

- API Gateways, Enterprise Directories, SSO and Access Management systems, identity federation protocols (SAML/OAuth/Open ID Connect), and LDAP.

- Scripting languages such as JavaScript, Python, PowerShell and etc.

- Programming languages such as Java, Dot Net and etc.

Qualifications

Requires BS/BA in related field; 5 to 8 years of experience for the Advisor level and 8+ years experience for the Sr Advisor level in systems administration and security aspects of information systems, computer networking, telecommunications, systems development and management; significant experience with multiple technical and business disciplines required.; or any combination of education and experience, which would provide an equivalent background.

Advanced knowledge and understanding of industry-accepted data processing controls and concepts as applied to access management and network security technologies, hardware, software, data, network communications, and people.

Security Certifications: CISSP and other advanced technical security certifications (e.g. Information Systems Security Architecture Professional, Information Security Engineering Professional, Certification and Accreditation Professional, or equivalent certifications) preferred.

An ideal candidate will have:

- Experience in understanding and implementing against technical IAM architecture designs across six major capability areas:
  • Identity Federation
  • Identity & Access Lifecycle Management
  • Identity Data Models
  • Credential Management

History of contributing to deployments in an engineering role. Deployment experience must include two or multiple of the following IAM solutions:

- Single Sign On (SSO) integration and session management such as SiteMinder, Ping SSO, Okta and etc. for web applications.

- Identity Federation (SAML) configuration and integration across multiple trusted third parties, applications, and systems.

- Directory (LDAP) service implementation and integration such as Microsoft AD, Ping/Oracle LDAP and etc. for identity data consumption by applications and systems.

- Multi Factor Authentication (MFA) such as Okta/Ping/Duo/Secure Auth security integration into the authentication, authorization, and single sing

on process for applications and systems.

- Good knowledge in identity and access data correlation, normalization and building of cohesive identity and access data models for large enterprises.
- Experience with complex Identity and Access Management integration and service delivery use cases and requirements.
- Exposure and good understanding of Microservice architectures and implementation approaches.
- Exposure and good understanding of Docker and DevOps CI/CD tooling.
- Knowledge of IT, service-oriented architectures, software development life cycles, or information security platforms and applications.

Anthem, Inc. is ranked as one of America's Most Admired Companies among health insurers by Fortune magazine, and is a 2018 DiversityInc magazine Top 50 Company for Diversity. To learn more about our company please visit us at antheminc.com/careers.

AnEqualOpportunityEmployer/Disability/Veteran
Dice Id : 10121414
Position Id : PS36452-Indianapolis-Indianapolis
Originally Posted : 2 months ago
Have a Job? Post it