IAM Solutions Architect (Remote)
Detalles del trabajo
- Recomendación de trabajo:
- 167638
- Ubicación:
- Providence, RI 02908
- Flexibilidad de ubicación:
- Remoto
- Categoría:
- IT
- Tipo de Empleo:
- Tiempo completo
- Estado Laboral:
- Exempt
- Fecha prevista de cierre:
- 10 de enero de 2025
- Base salarial
- Yearly
- Rango salarial
- $114300.00 - $220500.00 Annually ($54.95 - $106.01 Hourly)
- Marca
- UNFI
Job Overview:
The function of the IAM Solution Architect is to partner with the Product Management team and Enterprise/Security/IT Architects to create the overall technical vision of a full IT solution to support the business goal. This role is responsible for, in partnership with IT peers, design, planning, implementing the solution. This role will also partner with operations teams to provide support and evaluate the solution to ensure continuous improvement of the solution. The IAM Solution Architect stays up to date on the latest technologies, security best practices and deployment strategies both in the cloud and on premise. Core functions include assessing existing deployments for remediation efforts regarding availability, recoverability, security and. This position is responsible for architecting, designing, engineering, coordinating and cost forecasting solutions for the Identity & Access Management (IAM) area, including directory services, authentication/authorization, privileged access management, identity lifecycle management and cloud identity services. This position is highly collaborative, interacts frequently with IT and business leadership and possesses excellent communication skills.
Job Responsibilities:
Solution Architecture
• Formulate the technical strategy and roadmaps as required to develop, build, and support the company’s IAM strategy including on-premises, IaaS, PaaS, and SaaS products.
• Responsible for ensuring that IAM solutions are focused on standards development, stability, security, efficiency, upgrades, migrations, Disaster Recovery, and system integration/inter-operability.
• Establish governance and enforce quality IAM standards for cloud software and infrastructure architectures (IaaS, PaaS and SaaS).
• Collaborate with stakeholder teams to define use cases, goals, objectives, and architecture to support the business needs.
• Initiates solution ideation and execution to drive the creation and ongoing improvement of solutions with product managers, as well as 3rd-party technology providers.
• Collaborate with IT architects to ensure solutions meet the enterprise standards for architecture, engineering, quality, and security.
• Engage and align recommendations to senior IT leadership team.
• Understand the current state of the organization-wide architecture
• Identify key business drivers and technology capabilities required to achieve optimal state.
• Work closely with IT peers and act as a liaison between key business, and IT experts
• Ensure alignment between business strategies, information technology roadmap, and technical and tactical deployment plans.
• Drive POC’s, vendor evaluations and comparisons for the right solution
• Maintains records to document architecture and technology portfolio as well as revisions to enterprise artifacts.
• Provide architectural guidance to the product team
People Leadership
• Provide IAM consultation services to enterprise and IT teams
• Explain technical issues and IT solution strategies to stakeholders and other IT professionals
• Serve as IAM SME for the extended Infrastructure team and help develop internal knowledge
• Mentor and coach engineers, administrators, and developers to ensure that architecture and requirements best practices are followed.
Job Requirements:
Education/Certification:
• Bachelor’s degree in computer science or a related discipline desired, or relevant IAM Engineering work experience.
• Masters in IT Management strongly preferred.
• Industry Cybersecurity or IAM certifications such as CISSP, ISC2+, GSEC, GISF, GCIA and GISP or equivalent
• Relevant product certifications such as CyberArk, SailPoint, Microsoft, AWS Certified Cloud Practitioner
Experience:
• 6-10+ years’ professional experience working as an architect in large scale identity environments (10,000 users minimum).
• 6+ years’ experience in as an IAM Engineer/Architect in a large complex on-premises/cloud hybrid identity environment
• 6+ years’ experience with directory services, authentication/authorization, privileged access management, identity lifecycle management and/or cloud identity services: Active Directory, Azure AD/SSO/MFA, Azure Identity Framework, AWS cloud native, CyberArk, SailPoint IIQ, Oracle OUD, LDAP, etc.
• 6+ years of experience with Amazon Web Services (AWS), and Google Cloud Platform (GCP) with enterprise-level web/SaaS applications and IaaS/PaaS architecture within AWS, and GCP.
• Highly engaged technologist with broad experience across a variety of operations and services, including infrastructure as code, CI/CD pipelines, real-time OLTP systems, heterogeneous environments (Linux & windows), serverless & containerized
deployments, and zero trust security. Familiarity with cloud tools including Terraform, CHEF, Ansible, etc. preferred.
• 6+ years of hands-on engineering experience with the following IAM domains:
Cloud
• Experience designing Azure Conditional Access policies, Azure SSO, Azure MFA and Identity federation using AD Connect and/or ADFS
• Experience supporting AWS identity federation and AWS governance
• Experience securing applications with cloud access security broker (CASB)
• Experience managing an Azure B2C tenant for external users, including design and creation of Azure B2C policies, Azure forms and workflows using the Azure Identity Framework
Directory Services
• Experience designing Active Directory Group Policies, fine-grain password policies, AD Sites, Time Service
(NTP), DNS and AD replication topology, with Active Directory 2016 functional forest level
• Experience with AD delegated administration tools such as Quest ARS, RMAD, GPO Admin, Enterprise Reporter
• Experience applying security standards using automated processes to prevent misuse of stale accounts, compromise of passwords or escalation of permissions, such as identifying and disabling stale accounts
Identity Lifecycle Management
• Experience with SailPoint Identity IQ
• Experience integration SailPoint IIQ with enterprise applications and IAM solutions
• Understanding and experience in Java application development, Beanshell, Linux/Unix, Windows, scripting (Bash, PowerShell, Perl), SQL, LDAP, and web services
• Experience developing custom workflows for joiners, leavers and movers
• Experience connecting applications to SailPoint for automated provisioning/deprovisioning and access reviews
• Experience with designing and implementing Role Based Access Control using technical and business roles
Privileged Access Management
• Extensive experience architecting, designing and implementing CyberArk products for a complex enterprise environment with multiple domains and platforms
• Experience integrating CyberArk with various applications using out of the box and custom connectors
• Experience rolling out privileged access to administrative users to maximize security and operational efficiency
• Experience using CyberArk to secure remote access for vendors
• Experience with architecting and designing for Security Constraints, Resiliency, High-Availability, Fault Tolerance, and Scalability
Knowledge / Skills and Abilities:
• Proficient with industry security frameworks such as NIST, ISO 17799, CIS, etc.
• Proficient with one or more regulatory requirements and laws such as, but not limited to, PCI, Federal Financial Institutions Examination Council (FFIEC), Sarbanes-Oxley (SOX), HIPAA, GDPR and GLBA.
• Proficient with implementation of zero trust principles
• Knowledge of ITIL and able to follow established processes for ITSM
• Knowledge of relational databases (Oracle, MSSQL, MySQL, etc)
• Knowledge of enterprise systems (SAP, PeopleSoft, Cherwell)
• Ability to create and articulate target and reference architectures and product, capability roadmaps.
• Working knowledge of design patterns and appreciation of the purpose and the practices of Agile
• Excellent verbal and written communications skills to collaborate with leadership and stake holders
• Knowledge of web services standards and related technologies
• Instill best practices and standards across technical and business teams
• Proven ability to contribute to the development of strategic technology direction and architecture vision for a large organization
• Ability to think across IT solutions in a multi-platform environment and define potential impact.
• Strong analytical, problems-solving and conceptual skills.
• Strong project management skills; experience organizing, planning and executing large-scale projects from vision through implementation, involving internal and external resources.
• Strong teamwork and interpersonal skills; ability to communicate and influence at all management levels and with both technical and non-technical individuals and successfully manage in a cross-functional environment and remote locations.
• Strong leadership and communication skills with a focus on the ability to leverage technology as a business enabler.
• Good judgment is required for this position as there may be times when direct supervision may not be immediately available
All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity or expression, national origin, disability, or protected veteran status. UNFI is an Equal Opportunity employer committed to creating an inclusive and respectful environment for all. - M/F/Veteran/Disability. VEVRAA Federal Contractor.
Additional Information
- Schedule: Full-time
- Empresa:
- United Natural Foods Inc.
Indemnización laboral:
UNFI prevé pagar el salario mencionado (o dentro del rango salarial mencionado) para este puesto. El salario real, según corresponda, dependerá de ciertos factores; incluidos, entre otros, educación, experiencia laboral, formación y cualesquier requisitos previstos en los convenios laborales colectivos aplicables. UNFI está comprometida con la transparencia salarial, en virtud de la legislación estatal y local aplicable.
Beneficios:
En el caso de los puestos en Washington (o los puestos en los que se trabaje remotamente desde Washington), haga clic AQUÍ para conocer los detalles sobre el pago de licencias laborales específicas para Washington.
Los candidatos contratados para este puesto también serán elegibles para participar en los siguientes programas de beneficios: licencias pagadas; licencias por enfermedad; pago de vacaciones y licencia por maternidad/paternidad; Programa 401K; póliza con cobertura médica, odontológica, oftalmológica y seguro de vida, accidentes, muerte y pérdida de miembros; programa de seguro a corto y largo plazo por discapacidad; cuenta con gastos flexibles, cuenta de ahorro sanitario o ambas; sujeto al cumplimiento de los requisitos de elegibilidad y los términos y condiciones de dichos programas, y sujeto a cualquier requisito previsto en los convenios laborales colectivos aplicables.
Solamente puestos de Ventas: en el caso de los puestos de ventas con base en comisiones, el rango mencionado representa un estimado de la compensación potencial por comisiones durante el primer año de un asociado; pero UNFI ofrece un mínimo de $680 a la semana para el periodo inicial. Después del periodo inicial, por tratarse de un puesto basado totalmente en comisiones, no hay un salario fijo. Los planes de comisiones de UNFI no tienen tope y las ganancias promedio dependen del territorio y de las ventas logradas, entre otros factores.
Las políticas de UNFI referentes a la compensación, los beneficios y las licencias pagadas están sujetas a cambios por decisión exclusiva de la compañía y acorde a la legislación aplicable. El aviso de empleo disponible no debe interpretarse como una oferta de empleo con ciertos términos, así como tampoco debe interpretarse como un mínimo garantizado.
Las solicitudes calificadas con antecedentes de arresto o condena se considerarán para empleo de acuerdo con la Ordenanza de Oportunidades Justas del Condado de Los Ángeles y la Ley de California Fair Chance Act.
Conoce más sobre nuestras marcas:
Featured Jobs
Part Time Baker
Rochester, MNRochester West Cub on Scott Road is looking for a dedicated individual to fill a part time bak er position ! Bakers at Cub prepare, bake and fry a variety of products and fini sh them with frosting, glaze or icing according to item standards to ensure quality and consistency …
Fleet Refrigeration Tech
Schnecksville, PAJoin our team and immediately become part of the largest distributor of conventional, natural, organic and specialty products in the United States and Canada. We serve over 43,000 customer locations with 200,000 different products. Our warehouse associates supply thousands of consumers with "better for you" food that nourishes families nationwide. …
Retail Merchandiser
Ithaca, NYUNFI is looking for a Part-Time Retail Merchandiser near Ithaca, NY. This position will service a route of local UNFI customers (Tops Market) and offers: Part-Time hours Monday, Wednesday, and Friday. Mileage reimbursement plan ($0.67/mile) accrued home to home. Weekly Pay. Purpose: Partner with assigned customers to ensure they …