Summary
Crowell & Moring LLP is an international law firm that represents clients in various legal matters. The Security Analyst specializes in Identity and Access Management technologies and is responsible for managing the IAM platform, ensuring appropriate access to data, and staying updated on current identity technologies.
Responsibilities
- Under general supervision the Security Analyst manages the IAM system including Enterprise Applications, federations, certificates, Identity Provider (IdP)
- Maintains and validates the Firm’s Multifactor Authentication (MFA) systems
- Integrates external applications with the Firm’s identity system using OAUTH, SAML, OpenID or other appropriate technology
- Coordinates with Human Resources, Finance, and others to automate as much as possible the Join/Move/Leave process for employee, Partner, and third-party identities
- Maintains and manages the Firm’s sources of Identity, including Active Directory, Microsoft Entra ID, and Active Directory Federation Systems (AD FS)
- Manages federation and replication technologies such as Entra ID Connect
- Maintains the Firm’s Public Key Infrastructure (PKI) systems including certificate templates, issuance policies, automation, security, and revocation
- Completes special projects and other duties as assigned
Skills
- Bachelor's Degree, preferably in Computer Science/MIS or equivalent certification from an accredited technical training school
- Four years of progressive experience may substitute for education
- Minimum of four (4) years of increasingly responsible, directly related experience during which knowledge, skills and abilities applicable to the position were demonstrated
- Knowledge of Identity technologies and systems including Security Assertion Markup Language (SAML), Single Sign On (SSO), and related technologies such as OAUTH, OpenID
- Understanding of directory and authentication technologies such as Active Directory (AD), lightweight directory access protocol (LDAP), Kerberos, RADIUS, and Public Key Infrastructure (PKI)
- Understanding of Microsoft identity products such as Entra ID, Conditional Access, Defender for Identity, and Enterprise Applications
- Understanding of multifactor technologies and platforms, including NIST 800-63 R4 approved methods
- Ability to work overtime as needed
- Microsoft SC-300 or related Identity and Access, Azure, or Entra certifications
- CISSP or GIAC certifications are a plus
Qualifications
Must Haves
- Bachelor's Degree, preferably in Computer Science/MIS or equivalent certification from an accredited technical training school
- Four years of progressive experience may substitute for education
- Minimum of four (4) years of increasingly responsible, directly related experience during which knowledge, skills and abilities applicable to the position were demonstrated
- Knowledge of Identity technologies and systems including Security Assertion Markup Language (SAML), Single Sign On (SSO), and related technologies such as OAUTH, OpenID
- Understanding of directory and authentication technologies such as Active Directory (AD), lightweight directory access protocol (LDAP), Kerberos, RADIUS, and Public Key Infrastructure (PKI)
- Understanding of Microsoft identity products such as Entra ID, Conditional Access, Defender for Identity, and Enterprise Applications
- Understanding of multifactor technologies and platforms, including NIST 800-63 R4 approved methods
- Ability to work overtime as needed
- Microsoft SC-300 or related Identity and Access, Azure, or Entra certifications
Nice to Haves
- CISSP or GIAC certifications are a plus
Benefits
- Healthcare
- Vision
- Dental
- Retirement
- All-purpose leave
- Progressive options such as back up childcare
- Wellness programs
- Cultural events and social activities
- Additional compensation may include a discretionary bonus