Title: Identity Access Management SME
Operational Support: May require participation in on-call or surge support activities depending on operational needs.
Location: Telework
Travel: As required per contract direction.
Clearance: Ability to obtain and maintain SEC Public Trust (or higher if required).
The Identity Access Management SME serves as the senior technical authority for enterprise IAM capabilities supporting the SEC ISS contract. This role leads the design, implementation, and governance of Microsoft Entra- and Microsoft ICAM-based frameworks and identity services to ensure secure authentication, authorization, compliance, and least-privilege access across cloud and on-premises environments. The position drives implementation of conditional access, MFA, PIM/PAM, RBAC, and identity governance workflows aligned to SEC zero-trust objectives and OMB M-22-09 direction. The SME partners with infrastructure, security, and operations teams to sustain audit readiness, support FISMA evidence requirements, and resolve complex identity and access challenges at enterprise scale.
PRIMARY RESPONSIBILITIES:
- IAM Strategy, Architecture, and Engineering.
- Serve as the enterprise subject matter expert for IAM architecture and provide technical leadership for identity and access services across the SEC ISS environment.
- Design and implement secure authentication and authorization models using Microsoft Entra ID, Microsoft ICAM, and role-based access controls.
- Lead integration of Entra identity services with Microsoft 365 and enterprise applications to support consistent identity lifecycle and policy enforcement.
- Define IAM standards, patterns, and operating procedures that align with zero-trust principles and federal security requirements.
- Identity Governance and Access Control:
- Compliance, Risk, and Audit Support:
- Operations, Automation, and Stakeholder Engagement:
REQUIRED:
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Engineering, or a related field.
- Minimum 8 years of deep expertise and experience in identity governance, identity and access management and/or cybersecurity roles supporting enterprise environments.
- Mandatory hands-on experience implementing and operating Microsoft Entra ID (Azure AD) and Microsoft ICAM capabilities.
- Advanced experience with MFA, conditional access, privileged access management, Entra Identity Governance, and integration with Microsoft 365 and enterprise applications.
- Strong understanding of compliance frameworks (NIST, ISO 27001, CISA SCuBA) and zero-trust principles.
Technical Skills (Matrix-Derived Required):
- Microsoft Entra ID (Azure AD) and Microsoft ICAM.
- Multifactor authentication (MFA), conditional access, RBAC, and privileged access/identity management (PIM/PAM).
- Entra Identity Governance and identity lifecycle management.
- Microsoft 365 and enterprise application identity integration patterns.
- Compliance and control frameworks: NIST, ISO 27001, CISA SCuBA.
- Zero-trust architecture implementation and policy enforcement.