
Senior Identity Access Management – CyberArk Administration
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in United States.
• Develop and uphold the IAM strategy, roadmap, and reference architecture for workforce, privileged, non-human, and application identities.
• Advocate for Zero Trust principles, robust authentication, ongoing evaluation, least privilege, and just-in-time access.
• Align IAM initiatives with enterprise security architecture, cloud adoption strategies, data protection measures, and digital transformation efforts.
• Establish governance for identity lifecycle management, access policies, and adherence to regulatory compliance.
• Oversee joiner–mover–leaver processes and manage provisioning/deprovisioning integrations.
• Implement RBAC/ABAC models, role mining initiatives, segregation of duties, and toxic combination controls.
• Govern federation standards, application onboarding processes, token lifecycles, and session management.
• Enforce credential vaulting, session recording, and just-in-time elevation for administrators and high-risk roles.
• Manage identities, roles, and policies across Azure, AWS, GCP, and various SaaS platforms.
• Maintain IAM controls, prepare for audits, create evidentiary artifacts, and oversee remediation plans.
• Conduct access reviews, entitlement cleanup initiatives, and residual-risk reporting.
• Lead daily IAM platform operations, ensuring availability, scalability, incident response, SLAs/OLAs, runbooks, and change management.
• Monitor identity data quality, directory hygiene, and the effectiveness of the deprovisioning process.
• Collaborate with Security, HR, Legal, Compliance, IT Operations, application owners, and Data Governance teams.
• Communicate identity-related risks and trade-offs to executive stakeholders.
• Manage user accounts and permissions for both corporate and client systems.
• Resolve access-related issues within established SLAs and document solutions.
• Benchmark IAM capabilities against industry best practices and drive improvements in maturity.
• Conduct post-incident reviews and prioritize the backlog for continuous improvement.
• Perform additional duties as assigned by the manager.
• Bachelor’s degree in a relevant field or an equivalent combination of education and experience.
• At least 6+ years of industry or relevant experience.
• Typically, a minimum of 1+ years in a Senior Associate level role or its external equivalent.
• Practical experience with IAM platforms such as Microsoft Entra ID, SailPoint, CyberArk, Okta, or similar systems.
• Experience in implementing SSO, MFA, RBAC/ABAC, and PAM solutions.
• Proven track record managing JML identity lifecycle processes and integrating with HR systems and directories.
• Strong background in cloud identity management across platforms like Azure, AWS, and GCP.
• Familiarity with SAML, OAuth 2.0, and OpenID Connect federation protocols.
• Proficient in PowerShell or other scripting languages for IAM automation.
• Understanding of Windows Server, Active Directory, and modern authentication technologies.
• Knowledgeable about Zero Trust principles, identity threat detection, and risk-based access controls.
• Awareness of compliance standards such as SOX, HIPAA, PCI DSS, GDPR, and ISO 27001.
• Experience in preparing for audits and maintaining evidentiary artifacts for IAM controls.
• Strong expertise in Microsoft Active Directory, Azure AD/Entra ID, and Windows operating systems, including Windows 11.
• Experience with IAM automation using PowerShell or Python.
• Capability to analyze complex identity challenges and formulate strategic solutions.
• Skilled in troubleshooting identity-related issues and resolving conflicts in a professional manner.
• Excellent oral, written, and technical communication skills.
• Strong interpersonal skills to influence and collaborate effectively across IT, Security, and business teams.
• Willingness to attend training provided by the department.
• Flexibility to work shifts beyond standard working hours.
• Availability for extensive travel in the event of a catastrophic incident.
• Readiness to be on call and support 24x7x365 operations.
• Ability to assist with both planned and unplanned events.
• Discretionary bonus eligibility for specific positions.
• Paid time off (PTO).
• Paid holidays.
• Medical insurance.
• Dental insurance.
• Vision insurance.
• Life insurance.
• Disability insurance.
• Participation in a 401K plan.
• Training provided by the department.
Moysies & Partner IT- und Managementberatung
The Cigna Group
WhiteWater Express Car Wash
Maximus
Get handpicked remote jobs straight to your inbox weekly.