Identity & Access Governance Engineer :: Initial Remote (Denver, Colorado) :: 10+ Years Only :: Only USC or GC or EAD at Denver, Colorado, USA |
Email: [email protected] |
From: Mohd Niyaz, Sibitalent Corp [email protected] Reply to: [email protected] Identity & Access Governance Engineer The IAG Engineer will support functional and technical aspects of the Identity Access Governance function. The engineer will support functions that support authentication, authorization, profile management, and federation. The engineer is responsible for supporting the IAG program maturity, implementing and increasing adoption by onboarding technology platforms, maturing processes, and providing actionable guidance on security standards & best practices. The IAG Engineer will support access provisioning (joiners/movers/leavers), governance, and administrative needs across the organization. The candidate will work on the adoption and expansion of the corporate Identity Governance & Administration (IGA) platform. The IAG Engineer will expand the centralized access management architecture, to mature the automation of provisioning and governance for enterprise applications. The Engineer will collaborate with cross-functional teams to implement and support secure identity and access management solutions for the organization. The candidate will work to ensure that employees, business partners, and contractors have the right access to the right systems at the right times for the right reasons. Essential Functions Support the design, configuration, and implementation of an Identity Governance & Administration (IGA) solution that provides capabilities to manage identity lifecycles (of joiners, movers, leavers) and entitlement reviews (e.g., user access reviews, privileged access reviews). Work with internal stakeholders/business partners to gather and document IGA requirements for new and existing applications and systems. Work closely with stakeholders to understand their requirements, translate them into technical specifications, and design/implement IGA solutions that meet those requirements. Support technical functions that automate provisioning and de-provisioning of user access, managing entitlements, managing roles, and enforcing policies for compliance purposes. Develop and maintain workflows, rules, and policies within IGA platforms for managing access requests, approvals, and access certification. Configure/manage access certification campaigns, developing access rules, and managing access workflows. Monitor, manage, and troubleshoot the IGA platform environment to ensure its high availability, stability, reliability, and security. Perform regular IGA solution maintenance/upgrades, troubleshoot, resolve issues, and ensure the systems performance and availability. Analyze system requirements, including identifying interactions and appropriate interfaces between affected components and sub systems. Work collaboratively with vendors, consultants, and other third-party service providers to implement and maintain IGA solutions. Develop and/or review system specifications, including output requirements, flow charts and technical diagrams. Supports software system testing & validation procedures, programming, and documentation. Collaborate with cross-functional teams to develop IAG strategies, roadmaps, and standards that align with business goals and objectives. Provide technical expertise in the areas of access control, identity governance, and authentication & authorization to ensure compliance with industry regulations and standards such as SOX, PCI-DSS, and TSA. Work collaboratively with other teams to develop and implement security policies, procedures, and best practices that support the organization's overall IAG posture. Develop and maintain documentation on the IGA solutions and processes to ensure compliance with internal policies and regulatory requirements. Develop and maintain detailed documentation on IGA solutions, processes, and procedures to ensure compliance with internal policies and regulatory requirements. Work collaboratively with internal and external auditors to provide evidence of compliance with IAG policies/procedures and develop remediation plans for any identified gaps. Provide training and support to end-users on IAG-related topics to ensure that they are able to access the resources they need, support joiner/mover/leaver provisioning processes, while adhering to security policies and procedures. Provide training and support to end-users on IAG -related topics, including self-service password reset, access requests, and entitlement reviews. Stay up-to-date with emerging IGA technologies and best practices, and provide recommendations for improving the IGA solutions and processes to meet the evolving needs of the organization. Qualifications Bachelor's degree in Computer Science, Information Systems, or a related field; or equivalent work experience (required). 5+ years of experience configuring, implementing, and maintaining a packaged or custom IGA solution, such as: Saviynt, SailPoint, ForgeRock, or equivalent tool (required). 4+ years of experience in configuring, implementing, and maintaining SailPoint IdentityNow and/or SailPoint IdentityIQ (required). Experience with Microsoft Azure Active Directory (required). Experience using Power for reporting and automation (required). Experience using database connections and SQL queries (required) Working knowledge in infrastructure technologies such as Linux, Windows, and LDAP (required). Experience on SailPoint IdentityNow with developing custom workflows, connectors, rules, and policies (required). Certifications such as SailPoint Certified IdentityNow Engineer (desired). Certifications such as CISSP, CISM, or CISA (desired). Knowledge, Skills, and Abilities Proficient in developing and maintaining policies, standards, and guidance artifacts. Expert knowledge in core identity domains: Identity Governance & Administration (IGA), Privileged Access Management, Authentication, Authorization, and Identity Lifecycle Management. In-depth knowledge of Identity and Access Management concepts, technologies, and best practices, including user provisioning, access certification, role management, and entitlements management. Hands-on experience designing, implementing, and deploying IGA solutions in an enterprise environment, such as Azure AD, Okta, SailPoint, Saviynt, ForgeRock. Subject matter expert for IAG including: role-based access control (RBAC), access request, and certification. Demonstrates extensive understanding of IAG concepts such as directory services, SSO, federation, MFA, provisioning, access certification, roles, and segregation of duties (SOD). In-depth knowledge of legacy and modern authentication protocol differences (such as RADIUS, SAML, OpenID, Oauth, and LDAP). Deep understanding of SailPoint IdentityNow architecture and components, and be able to perform regular maintenance and upgrades, troubleshoot and resolve issues, and ensure system performance & availability. Security best practices for Windows-based and Linux-based systems including authentication principles and components. Experience in implementing and supporting IGA solutions in large and complex environments. Solid understanding of security and compliance regulations such as GDPR, SOX, PCI DSS, and HIPAA. Strong problem-solving and troubleshooting skills with the ability to analyze complex issues, identify root causes, and implement effective solutions. Excellent communication and interpersonal skills, with the ability to collaborate effectively with cross-functional teams and business partners. Strong project management skills, with the ability to manage multiple projects simultaneously and deliver on time and within budget. Exceptional consultative and interpersonal skills that have resulted in business relationships of impeccable trust, confidence, and results. Exhibit leadership skills required to manage resources as well as projects deliverables. Knowledge of industry trends and current and emerging risks. Self-directed professional with strong work ethics and excellent organizational skills. Strong leadership and negotiation skills with business and technical group. Thanks and Regards, Mohd Niyaz Email : [email protected] Linkedin ID:- linkedin.com/in/mohd-niyaz-362667220 Web: www.sibitalent.com 101 E. Park Blvd., Suite 600 Plano, TX - 75074 Keywords: active directory Delaware Idaho Texas Identity & Access Governance Engineer :: Initial Remote (Denver, Colorado) :: 10+ Years Only :: Only USC or GC or EAD [email protected] |
[email protected] View All |
01:11 AM 20-Dec-24 |