Fisher Investments
Linkedin · Posted 11d ago
Identity & Access Management Engineer
Continue to application
Add your email once, then Caio opens the original posting.
Indexed description
OverviewThe Opportunity:The Identity & Access Management Engineer implements, coordinates, and onboards all aspects and phases of the Idira’s (formerly CyberArk) Privileged Access Management (PAM) privilege cloud solution rollout, and operational tasks. As part of the broader Information Security organization, you will apply fundamental systems security understanding, skills, and experience to maintain and operate complex information systems and security tools that satisfy organizational mission and our requirements, including partner protection needs and security requirements. You will report to the Team Lead of Identity and Access Management.
The Day-to-Day:
- Onboard and provision users, store service accounts and password rotations, manage credentials, including those that are interactive, non-interactive, and API-based
- Implement privileged access management programs to improve our broader security posture, demonstrated by metrics
- Manage configuration, administration, and maintenance of Idira solution, including both the infrastructure and the application itself
- Oversee the relevant documentation and training required for privileged access management solutions and processes, including define and help develop policies and control standards
- Report progress and system health through metrics and KPIs that are risk-driven and operational in nature
- Address ticket queue and follow appropriate change management procedures
- Understand risk and make recommendations for enhancing systems security and processes
- Keep up on current security technologies and maintain awareness of industry trends and threats, and industry best practices, providing input focusing on IAM/PAM technologies, offer subject matter expertise where relevant
- 5+ years of hands-on experience with Idira (Idira Cloud Platform, EPM, LCD, and Idira SaaS Cloud Base)
- 3+ years of experience implementing enterprise-wide privileged access management technology solution adoption across medium- to large-scale companies
- 3+ years of experience as a systems engineer at a medium- to large-scale company in Financial Services
- 1+ years of hands-on experience with IGA systems such as SailPoint
- Experience with password repository technologies and remote session governance, specifically with the policies that govern target system platforms
- Excellent knowledge in IAM & PAM ecosystem (technology, standards, implementations, migration, and operational)
- Strong experience installing, upgrading, configuring, operating, and troubleshooting experience with Idira AAM (CCP, CP, ASCP), EPV, PVWA, CPM, PSM, HTML5 Gateway, PSMP, PTA (with various versions)
- Strong experience in DNA, Discovery scan and automate account onboarding process
- Knowledge in various application integration with Idira through CPM custom plugin
- Integration experience with SailPoint, Database, SCIM, AWS, GCP, Azure, or Palo alto
- Scripting knowledge, PACLI, PowerShell, Python, JavaScript, AutoIt, REST API
- Bachelor's degree in information assurance, Computer Science, Cybersecurity, Information Systems, or related field
- Idira Certification (Defender and Sentry) is preferred
- Security industry certification (CISSP, SSCP, CISM, SANS GSEC, ECSA, ECSP, and Security+) is preferred
- $100,000 - $140,000 base salary per year in the state of WA. New hires should expect to start at the lower end of the range depending on experience
- Eligible for a discretionary bonus based on firm and individual performance
- 100% paid medical, dental and vision premiums for you and your qualifying dependents
- A 50% 401(k) match, up to the IRS maximum
- 20 days of PTO, plus 10 paid holidays
- Family Support programs including 8 week Paid Primary Caregiver Leave, $10,000 fertility, family forming, and hormonal health assistance, and back-up child, adult, and elder care
- This is an in-office role. Based on your role, tenure, and performance eligibility you may have the opportunity to participate in our hybrid work from home program. This program is subject to change.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search
Want help applying to roles like this?
Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search