Mindlance
- Description:
The Identity & Access Management (IAM) Engineer's primary responsibilities are to implement security principles to the IAM IGA(Identity Governance & Administration) platform, performs daily functions required to maintain the rules and controls, maintain security and least privileged safeguards and support align GBT IAM policies to protect data and reduce risk. This role will help drive IAM-related security and compliance requirements across all areas of IAM IGA, especially in Saviynt but also could include Okta, CyberArk and AWS. This role will be responsible for contributing to IAM component designs, IAM development, service integration, implementation, and operations. This role will report directly to the Manager of Identity Access Management (IGA).
Essential Duties and Responsibilities:- Design, implement, and manage Saviynt IAM solutions to ensure effective access controls, identity lifecycle management, and compliance. Manage user provisioning, de-provisioning, and account modifications.
- Work closely with stakeholders to understand business requirements and translate them into IAM solutions.
- Configure and deploy Saviynt modules and connectors for various applications, platforms, and systems.
- Integrate Saviynt with other identity management and security systems to create a seamless IAM ecosystem.
- Identify and assess potential security risks related to identity and access management. Implement risk mitigation strategies and ensure compliance with industry regulations.
- Establish monitoring mechanisms for IAM activities and generate regular reports for audit and compliance purposes.
- Investigate and respond to security incidents related to identity and access management.
- Collaborate with other IAM team members seeking guidance on IAM related matters and contributing to system support.
- Execute reports and gather data for metrics. Assist with tracking and producing IAM metrics including key performance indicators (KPIs).
- Document changes, enhancements, and lifecycle events according to the set standards and procedures.
- Assist launching Access Certifications to ensure user accounts and access aligns with their roles and responsibilities. Work with system and application owners to generate the required reports.
- Promote and socialize IAM best practices, standards, and governance.
- Evaluate current IAM solutions and identify areas for improvement. Implement automated processes to streamline existing tedious processes.
- Performs troubleshooting of issues impacting IGA. Provides after-hours support for critical IGA related P1 issues if engaged.
- Assisting in ensuring project teams comply with company IAM standards, policies, industry regulations, and Cybersecurity best practices.
- Other daily and ad-hoc IAM tasks as assigned.
- General task and project-level reporting.
- Requirements:
Required Knowledge and Skills:- Minimum 5 years of professional/hands on experience and knowledge in IAM
- Minimum 3 years of professional/hands on experience with Saviynt including understanding of security system, endpoint, entitlements, workflows, email template, analytics, certificates and connections etc.
- Total 6 years of experience in leading the design, implementation, and maintenance of any IGA Product (i.e. Identity Now, IdentityIQ, OIM, etc..) solutions if Saviynt skillset is not found.
- Hands on experience in connected and disconnected application onboarding including request form, dynamic attributes, mapping and data types etc.
- Hands on experience in REST & SOAP connector including - JSON building, mapping, reconciliation and provisioning use cases etc.
- Hands on experience in SOD, technical/update rules
- Experience creating static and actionable analytical reports based on complex SQL queries.
- Expert knowledge of identity management principles, access controls, and security best practices.
- Proficiency with Postman, Java Scripting and Power Shell scripting.
- General understanding of Single Sign-On, Multi-Factory Authentications (MFA), and Authentication, Privileged Access Management (PAM) & Cloud technologies.
- Experience or deep understanding CyberArk( or any other Privileged Access Management solution), Azure, AWS, Active Directory, Okta and various multi-factor authentication services is preferred.
- Familiarity with industry regulations and standards (e.g. SOC2, ISO, SOX, PCI).
- Excellent analytical and problem-solving skills.
- Ability to comprehend and write technical documentation.
- Ability to work well with people of varying levels of technical abilities.
- Ability to gather, analyze, report, and present information
- EEO:
"Mindlance is an Equal Opportunity Employer and does not discriminate in employment on the basis of - Minority/Gender/Disability/Religion/LGBTQI/Age/Veterans."