Security Administrator, Identity & Access Management
Summary
Manages SailPoint and Entra ID roles, workflows, and certifications for a financial-services client, translating RBAC/ABAC policies into governed access and integrating audit events with Splunk.
Security Admin Identity & Access Mgt Ex
Location: Jersey City, NJ, USA, Delaware, USA
Work Location: onsite
- Co-author RBAC/ABAC policy definitions with the Data Governance Architects and Business Analyst, ensuring technical feasibility within SailPoint and AD/Entra ID.
- Design and configure the role-to-group mapping schema between the entitlement taxonomy and Active Directory security groups.
- Configure SailPoint roles, access request/approval workflows, and recertification campaigns aligned to SmartApproval and Firmwide Certification.
- Configure Entra ID roles, access request/approval workflows, and recertification campaigns aligned to SmartApproval and Firmwide Certification.
- Design SailPoint and Entra ID certification campaigns (scope, reviewers, frequency, and escalation rules) aligned to the tri-annual Firmwide Certification cycle.
- Administer elevated-permission and break-glass access (HR-for-HR, Operating Committee, senior/peer) with documented approval chains.
- Integrate SailPoint and Entra ID audit and certification events with Splunk for monitoring, alerting, and evidence capture.
- Support UAT, negative testing, and production cutover for all IAM-layer components.
- Co-author the IAM sections of the operational runbook and lead related knowledge-transfer sessions.
- Hands-on SailPoint (IdentityIQ or IdentityNow) role, workflow, and certification configuration.
- Hands-on Entra ID role, workflow, and certification configuration.
- Active Directory / Entra ID security-group administration at enterprise scale (multi-thousand group environments).
- RBAC and ABAC policy design; entitlement/role-catalog modeling.
- ServiceNow access-request/workflow integration.
- Working knowledge of data-layer entitlement enforcement tools (e.g., Immuta, Databricks Unity Catalog) to align IAM groups with downstream policy consumption.
- Scripting/API experience for SailPoint connectors and automation (e.g., PowerShell, Python, REST APIs).
- Log/audit integration experience with SIEM platforms (Splunk preferred).
- Experience operating within regulated, multi-country financial-services environments.
- SailPoint Certified IdentityIQ Engineer / IdentityNow Engineer.
- CISSP or CISM.
- Microsoft Identity and Access Administrator (SC-300).
- ITIL Foundation.