Sr Identity Access Management - CyberArk Administration - Remote US
$100,000–$125,000 year
RemoteUnited States
Job Summary
Define and maintain the IAM strategy, roadmap, and reference architecture covering workforce, privileged, and application identities. Champion Zero Trust principles by enforcing strong authentication, continuous evaluation, least privilege, and just-in-time access. Establish governance for identity lifecycle, access policies, and compliance with internal standards and external regulations including SOX, HIPAA, PCI DSS, GDPR, and ISO 27001. Own joiner–mover–leaver processes to ensure accurate provisioning and deprovisioning integrated with HRIS and directories. Implement RBAC/ABAC models, role mining, segregation of duties, and toxic combination controls. Govern federation standards, app onboarding, token lifecycles, and session management across cloud providers and SaaS platforms. Lead day-to-day operations of IAM platforms ensuring availability, scalability, and incident response while coordinating with Security, HR, Legal, and IT Operations. Prepare for audits, produce evidentiary artifacts, and manage remediation plans. Conduct periodic access reviews, entitlement clean-up campaigns, and report residual risk to leadership.
Required Qualifications
- Bachelor's degree in related field or equivalent combination of education and experience
- Minimum of 6+ years of industry and/or relevant experience, typically with 1+ years in a Senior Associate level role or external equivalent
- Hands-on experience with IAM platforms such as Microsoft Entra ID (Azure AD), SailPoint, CyberArk, Okta, or similar
- Proven track record in implementing SSO, MFA, RBAC/ABAC, and Privileged Access Management (PAM) solutions
- Experience managing identity lifecycle processes (JML) and integrating with HR systems and directories
- Strong background in cloud identity management (Azure, AWS, GCP) and federation protocols (SAML, OAuth 2.0, OpenID Connect)
- Proficiency in PowerShell or other scripting languages for IAM automation
- Knowledge of Windows Server, Active Directory, and modern authentication technologies
- Familiarity with Zero Trust principles, identity threat detection, and risk-based access controls
- Understanding of regulatory frameworks such as SOX, HIPAA, PCI DSS, GDPR, ISO 27001
- Experience preparing for audits and maintaining evidentiary artifacts for IAM controls
- Proficiency in IAM technologies and protocols, including SAML, OAuth 2.0, OpenID Connect, and MFA solutions
- Strong knowledge of Microsoft Active Directory, Azure AD/Entra ID, and Windows operating systems (including Windows 11)
- Experience with IAM automation using scripting languages such as PowerShell or Python
- Familiarity with regulatory and audit requirements (SOX, HIPAA, PCI DSS, GDPR, ISO 27001) and ability to maintain evidentiary artifacts
- Understanding of Zero Trust principles and identity-centric security frameworks
- Ability to analyze complex identity challenges, exercise sound judgment, and develop strategic solutions
- Skilled in troubleshooting identity-related issues and resolving conflicts with diplomacy and professionalism
- Exceptional oral, written, and technical communication skills for engaging stakeholders at all levels
- Strong interpersonal skills to influence and collaborate across IT, Security, and business teams
- Requires attending any department provided training
- Requires the ability to work shifts outside of normal working hours
- Requires the ability for extended travel in the event of a catastrophic event
- Requires the ability to be on call and support a 24x7x365 operations
- Requires the ability to support both planned and unplanned events
Desired Qualifications
- CISSP
- CISM
- Microsoft Certified: Identity and Access Administrator
- SailPoint
- CyberArk
- Okta certifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.