Summary
Vibrant Emotional Health provides technology-enabled services, community wellness programs, advocacy, and education focused on emotional wellness. The Identity and Access Management Analyst I supports day-to-day IAM security operations, protects company data and systems, investigates security incidents, and assists with IAM solution implementation, policy development, vulnerability assessments, and access management.
Responsibilities
- Participate in the planning and design of enterprise security architecture with a primary focus on Identity Access and Management of IAM
- Participate in the creation of enterprise security documents in IAM (policies, standards, baselines, guidelines, and procedures)
- Participate in the planning and design of an enterprise business continuity plan and disaster recovery plan
- Participate in the design and implementation of access controls, authorization rules, and role-based access policies
- Participate in the designing and implementation of role-based access policies leveraging systems such as Okta, AWS, Azure, GCP, Microsoft AD etc
- Maintain up-to-date, in-depth knowledge of the Cybersecurity industry, with a particular emphasis on Identity and Access Management (IAM) security. This includes awareness of new or enhanced security solutions, improvements in IAM security processes, and the evolving landscape of attacks and threat vectors
- Assist with recommending additional Identity and Access Management (IAM) security solutions or enhancements to existing security solutions, aiming to improve overall enterprise security
- Assist in the deployment, integration, and initial configuration of all new security solutions and of any enhancements to existing security solutions in accordance with standard best operating procedures generically and the enterprise’s security documents specifically
- Collaborate with application owners and leadership to address any technical issues involved in deploying, governing, and extending identity services where suited
- Maintain up-to-date baselines using industry standard frameworks such as CIS and CSA for the secure configuration and operations of all in-place devices, whether they be under direct control (i.e. security tools) or not (e.g. workstations, servers, network devices)
- Maintain operational configurations of all in-place security solutions as per the established baselines and industry best practices
- Monitor all in-place security solutions for efficient and appropriate operations
- Review logs and reports of all in-place devices, whether they be under direct control (i.e. security tools) or not (e.g. workstations, servers, network devices). Interpret the implications of that activity and devise plans for appropriate resolution
- Respond to tickets for addressing security concerns, vulnerabilities, and end-user reported issues
- Participate in investigations into problematic activity
- Participate in the design and execution of vulnerability assessments, penetration tests, and security audits
- Provide on-call support for end users, including support for all in-place Identity and Access Management (IAM) security solutions
- Partner with AppDev to identify and remediate vulnerabilities in Applications
- Assist in reviewing and processing access requests submitted by employees or departments, ensuring they comply with IAM and Security policies
- Assist in the configuration, maintenance, and optimization of IAM systems and related tools to ensure efficient user access and security controls
- Enforcing access control policies and ensuring that users have the appropriate level of access to systems and data
- Manage the user lifecycle, including onboarding, role changes, and offboarding processes. Ensure timely provisioning and de-provisioning of user accounts
- Reviewing and auditing IAM logs and record any security compliance, tracking, and reporting incidents
- Additional duties as assigned
Skills
- * General knowledge of security frameworks and controls such as: NIST (CSF, SP 800-53, SP 800-171), CIS, CSA, ISO27000
- * Some experience with security systems and tools that may include: Firewalls, WAF, SIEM, SOAR, MDR, IAM, PAM/PIM, Network Packet sniffers, Nmap, IDS/IPS, SAST/DAST Burp Suite
- * Some experience with Encryption, Antivirus/Malware, Penetration Testing, Source Code Scanning
- * Some experience with IAM concepts such as user provisioning, authentication, authorization, access control, and identity lifecycle management
- * Some technical knowledge of Cloud and SaaS security solutions and tools
- * Basic understanding of IP, TCP/IP, and other network administration protocols
- * Basic understanding of IAM lifecycle management, security controls and system configurations for technologies such as: AWS, Azure, GCP, Microsoft AD
- * Some experience working with IAM solutions, such as Okta, Active Directory, LDAP, or IAM software
- * Knowledge of various authentication methods, including multi-factor authentication (MFA), biometrics, and single sign-on (SSO)
- * Proven analytical and problem-solving abilities
- * Ability to effectively prioritize and execute tasks in a high-pressure environment
- * Excellent written, oral, and interpersonal communication skills
- * Ability to conduct research into IT security issues and products as required
- * Ability to present ideas in business-friendly and user-friendly language
- * Ability to effectively organize your tasks and manage priorities
- * Highly self-motivated and directed
- * Self-started but have the ability to work with a team(s)
- * Keen attention to detail
- * Team-oriented and skilled in working within a collaborative environment
- * College diploma or university degree in Cybersecurity or other computer technology degree and/or two years equivalent work experience
- * One or more of the following certifications or the ability to obtain one or more of the following certifications within specified time frame after employment: CompTIA Security+, GIAC Information Security Fundamentals, Okta Certified Professional, AWS Certified Security - Specialty, Microsoft Certified Systems Administrator: Security, Associate of (ISC)2 or CISSP, ISACA CISA or CISM
- * 2+ years working in an Identity Access Management role
- * 1+ years of experience in network, server and data storage security technologies recommended
- * 1+ years of prior experience with Cloud-based security technologies required
- * 1+ year of prior experience with protocols such as 0Auth 2.0, OpenID Connect, and SAML
- * Must be able to remain in a stationary position 50% of the time
- * Will constantly operate a computer and other office productivity machinery, such as a calculator, copy machine, and computer printer
- * Will frequently communicate over video calls with internal and external stakeholders
- * Preferred experience implementing and assessing Industry Security Standards including HIPAA HITECH, GDPR HITRUST, FISMA, IS027K, PCI, NIST, etc
- * Some experience with Penetration Testing and Malware Reverse Engineering as a nice to have but not required
Qualifications
Must Haves
- * General knowledge of security frameworks and controls such as: NIST (CSF, SP 800-53, SP 800-171), CIS, CSA, ISO27000
- * Some experience with security systems and tools that may include: Firewalls, WAF, SIEM, SOAR, MDR, IAM, PAM/PIM, Network Packet sniffers, Nmap, IDS/IPS, SAST/DAST Burp Suite
- * Some experience with Encryption, Antivirus/Malware, Penetration Testing, Source Code Scanning
- * Some experience with IAM concepts such as user provisioning, authentication, authorization, access control, and identity lifecycle management
- * Some technical knowledge of Cloud and SaaS security solutions and tools
- * Basic understanding of IP, TCP/IP, and other network administration protocols
- * Basic understanding of IAM lifecycle management, security controls and system configurations for technologies such as: AWS, Azure, GCP, Microsoft AD
- * Some experience working with IAM solutions, such as Okta, Active Directory, LDAP, or IAM software
- * Knowledge of various authentication methods, including multi-factor authentication (MFA), biometrics, and single sign-on (SSO)
- * Proven analytical and problem-solving abilities
- * Ability to effectively prioritize and execute tasks in a high-pressure environment
- * Excellent written, oral, and interpersonal communication skills
- * Ability to conduct research into IT security issues and products as required
- * Ability to present ideas in business-friendly and user-friendly language
- * Ability to effectively organize your tasks and manage priorities
- * Highly self-motivated and directed
- * Self-started but have the ability to work with a team(s)
- * Keen attention to detail
- * Team-oriented and skilled in working within a collaborative environment
- * College diploma or university degree in Cybersecurity or other computer technology degree and/or two years equivalent work experience
- * One or more of the following certifications or the ability to obtain one or more of the following certifications within specified time frame after employment: CompTIA Security+, GIAC Information Security Fundamentals, Okta Certified Professional, AWS Certified Security - Specialty, Microsoft Certified Systems Administrator: Security, Associate of (ISC)2 or CISSP, ISACA CISA or CISM
- * 2+ years working in an Identity Access Management role
- * 1+ years of experience in network, server and data storage security technologies recommended
- * 1+ years of prior experience with Cloud-based security technologies required
- * 1+ year of prior experience with protocols such as 0Auth 2.0, OpenID Connect, and SAML
- * Must be able to remain in a stationary position 50% of the time
- * Will constantly operate a computer and other office productivity machinery, such as a calculator, copy machine, and computer printer
- * Will frequently communicate over video calls with internal and external stakeholders
Nice to Haves
- * Preferred experience implementing and assessing Industry Security Standards including HIPAA HITECH, GDPR HITRUST, FISMA, IS027K, PCI, NIST, etc
- * Some experience with Penetration Testing and Malware Reverse Engineering as a nice to have but not required
Benefits
- Medical benefits
- Dental benefits
- Vision benefits
- Supplemental income insurance
- Employer-paid disability insurance
- Employer-paid life insurance
- Pre-tax FSA for medical and dependent care
- 401K available