Senior IT Security Analyst
Job Description
Lead enterprise IAM and identity security modernization across global cloud and SaaS environments from the Corporate Headquarters in Denver, CO.
Responsibilities
- Design, implement, and maintain enterprise Identity and Access Management (IAM) solutions for workforce, privileged, and application identities
- Integrate, administer, and optimize enterprise IAM platforms
- Define IAM architecture standards, design patterns, and technical roadmaps aligned to business and security objectives
- Build scalable identity solutions supporting cloud-first and hybrid environments
- Assess emerging IAM technologies and industry best practices to strengthen security posture
- Lead programs across Identity Governance and Administration (IGA), Access Management, Privileged Access Management (PAM), Identity Threat Detection and Response (ITDR), and Zero Trust
- Design and implement identity lifecycle management including provisioning, deprovisioning, role management, and access certification activities
- Develop and maintain authorization models using RBAC, ABAC, and PBAC
- Support segregation of duties (SoD), least privilege, just-in-time access, and privileged account governance programs
- Administer and enhance authentication services such as SSO, MFA, passwordless authentication, federation, and conditional access
- Manage on-premise, cloud, and hybrid identity environments
- Configure Identity Protection policies and Conditional Access controls, including risk-based authentication and adaptive access capabilities
- Design and maintain integrations between identity platforms, cloud services, and business applications using APIs, provisioning connectors, and automation frameworks
- Implement secure identity integrations for Microsoft Azure, AWS, and Google Cloud Platform and associated enterprise apps and SaaS
- Partner with application owners and development teams to ensure consistent authentication and authorization controls
- Support application onboarding, federation, provisioning, and access governance activities
- Develop automation solutions using PowerShell, Python, SQL, Power Automate, or similar tools to reduce manual effort and improve efficiency
- Create and maintain technical documentation, architecture diagrams, operational procedures, and support runbooks
- Recommend and implement process improvements that enhance security, user experience, and operational effectiveness
- Act as a senior IAM subject matter expert and trusted advisor to Information Security, IT, Audit, Compliance, and business stakeholders
- Lead technical projects from planning and design through deployment and operational transition
- Mentor junior employees and provide technical guidance across IAM initiatives
- Support audit, compliance, and regulatory activities by implementing controls and providing required evidence
- Participate in identity-related incident response and root cause investigations
- Stay current on IAM threats, technologies, and industry trends
- Perform other duties as assigned
Requirements
- Advanced knowledge of IAM, including IGA, PAM, authentication, authorization, and identity lifecycle management
- Strong understanding of modern identity security, including Zero Trust, least privilege, adaptive authentication, risk-based access controls, continuous access evaluation, and ITDR
- Advanced knowledge of on-premise, cloud, and hybrid identity environments
- Strong understanding of authentication, federation, and directory protocols: SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), LDAP, Kerberos, RADIUS, SCIM
- Knowledge of access control frameworks: RBAC, ABAC, PBAC
- Strong analytical and problem-solving skills to diagnose and resolve complex technical issues
- Excellent verbal and written communication skills for technical and non-technical audiences
- Strong organizational and project leadership skills; ability to manage multiple priorities
- Demonstrated ability to influence stakeholders and collaborate across cross-functional teams
- Ability to develop and maintain technical documentation, standards, procedures, and operational runbooks
Technologies
- Identity and Access Management (IAM), Identity Governance and Administration (IGA), Privileged Access Management (PAM), Identity Threat Detection and Response (ITDR)
- Zero Trust, RBAC, ABAC, PBAC
- SSO, MFA, passwordless authentication, Conditional Access, Identity Protection policies
- APIs, provisioning connectors
- PowerShell, Python, SQL, Power Automate
- Microsoft Azure, AWS, Google Cloud Platform
- SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), LDAP, Kerberos, RADIUS, SCIM
Benefits
- Medical with multiple plan options
- Short and long-term disability and life insurance
- Health savings and flexible spending accounts
- Generous time off: 3 weeks paid vacation, 7 days paid sick time, 12 paid holidays
- 8 hours of paid volunteer time off
- 8 weeks of paid parental leave for both parents
- Company matched 401(k)
- Tuition reimbursement
- Expanded mental health coverage and employee assistance programs
- Voluntary benefits: critical illness, accident and hospital indemnity, pet insurance, identity theft, and legal assistance
Work Environment
- On-site in Denver, Colorado at Corporate Headquarters
- Standard office environment
Preferred Qualifications
- Knowledge of regulatory and compliance frameworks: SOX, NIST, ISO 27001, and CIS Controls
- Familiarity with IT and Security platforms or applications within Customer Relationship Management (CRM), Zero Trust, and other enterprise product families
- Understanding of cloud security architectures across Azure, AWS, and Google Cloud Platform
Experience
- Seven (7) or more years in Identity and Access Management, Cybersecurity Engineering, Information Security, or a related technical discipline
- Five (5) or more years administering and supporting enterprise IAM platforms and access management processes
- Three (3) or more years supporting on-premise, cloud, and/or hybrid identity directory services in a medium to large enterprise environment
- Experience implementing and supporting IGA and PAM solutions
- Experience administering enterprise authentication solutions including SSO, MFA, federation services, and conditional access policies
- Experience integrating identity platforms with cloud providers, enterprise applications, and SaaS solutions
- Experience designing and implementing user provisioning, deprovisioning, access reviews, role management, and access certification processes
- Experience developing automation solutions using PowerShell, Python, SQL, Power Automate, or similar technologies
- Experience leading technical projects from planning and design through implementation and operational support
- Experience collaborating with Information Security, Infrastructure, Application Development, Audit, and business stakeholders to deliver IAM solutions
Preferred Experience
- Experience with IAM platforms and technologies
- Experience supporting global or manufacturing organizations
- Experience supporting regulatory audits, compliance initiatives, and remediation activities
- Experience implementing Zero Trust, PAM, or enterprise IAM modernization programs
Preferred Certifications
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Certified Information Systems Security Professional (CISSP)
- Certified Identity and Access Manager (CIAM)
- Certified Identity Management Professional (CIMP)
- Additional cloud, cybersecurity, or identity management certifications relevant to the role
Education
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Engineering, or a related field; or an equivalent combination of education and experience
Similar Jobs
$115k - $132k/yr
Full time
Cybersecurity Tools
Iam Identity Governance
Identity and Access Management