Job Description:
General Function / Summary:
The Senior Identity & Access Management Engineer is responsible for Identity and Access Management (IAM) solutions including lifecycle of accounts, federation, single sign-on and multi-factor authentication, network access control, privileged account management, provisioning and deprovisioning of active directory account, user access reviews, certificate and key management & encryption standards.
Essential Duties:
-
Plan and implement security measures to protect the company’s computer systems, networks, and data.
-
Manage and onboard MFA and SSO solutions to prevent loss of sensitive data through identity theft.
-
Manage privileged account management and role-based access control solutions for various platforms including Windows, Linux, and serverless solutions in multiple environments including in-house, hybrid cloud, and X-as-a-Service resources.
-
Perform audits of accounts to ensure they meet compliance standards of least privileged access.
-
Integrate application authentication through SSO.
-
Partner and assist with Managed Detection and Response (MDR) team members for incident response to protect corporate IT assets, including intellectual property, regulated data, and the company’s reputation.
-
Configure, troubleshoot, and maintain PAM and RBAC solutions.
-
Monitor systems for irregular behavior and set up preventive measures.
-
Remediate access risks if detected from penetration tests.
-
Recommend and coordinate the implementation of technical controls to support and enforce defined security policies.
-
Create user group/user access metrics.
-
Analyze information security hardware and software to ensure maximum performance and provide technical expertise for the administration of security tools.
-
Develop and maintain security processes and procedures.
-
Perform monthly, quarterly, yearly user access reviews.
-
Manage the AIM governance process and provide improvements.
Minimum Education and Experience Required:
-
Bachelor’s degree or equivalent experience
-
4+ years of experience administering cyber security solutions
-
Understanding of FFIEC and NIST frameworks methodologies
-
Experience managing Active Directory
-
Experience performing Identity Access Management duties
-
Experience configuring, operating, and maintaining security systems
-
Experience using Venafi Trust Protection Platform
-
Strong knowledge of authentication solutions for SSO and MFA
-
Familiar with networking technologies, network security, and network monitoring solutions
-
Experience using scripting languages like PowerShell, Python, Ruby or JavaScript and the ability to demonstrate knowledge
-
Strong knowledge managing Azure Entra ID
-
Strong knowledge managing Microsoft NPS for policies and Radius configurations
-
Strong knowledge of managing internal PKI and external TLS certificates
-
Strong knowledge and experience with PAM and RBAC systems
-
Knowledge of security protocols and principles
-
Ability to handle multiple projects and tasks simultaneously and collaborate with all areas of the organization
-
Excellent written and verbal communication skills
-
Proficient in Microsoft Office programs
-
Ability and willingness to consistently live and embrace our core values of accountable, inclusive, transparent, and focused
Top Skills
What We Do
CNG Holdings Inc. (CNG) is headquartered in Cincinnati, Ohio, and is a respected leader in the financial services industry. Through professional partnerships, CNG provides a wide range of convenient and accessible financial products and services designed to improve customers’ financial situations, thereby filling a need and delivering value to our customers.
Our mission is to help and educate our customers while building and nurturing long-term relationships. We strive to make a difference in our customers’ lives and the communities we serve.
Our vision is to deliver innovative financial solutions that better fulfill our customers’ unique financial needs so that they can build a better future for themselves and their families.
CNG Holdings Inc. core values ultimately define how we treat our customers and each other. We are:
• Inclusive: We are committed to creating environments that make all people feel welcomed, supported and valued; giving people the respect that is due them; being human and recognizing the humanity in others.
• Accountable: We do what we say we’re going to do. We take ownership for the quality of our individual work but also take pride in what we deliver as a team. We operate with honesty and integrity.
• Transparent: Share information. Share mistakes. Share victories. Trust is built through transparency.
• Focused: Work with a sense of urgency on the critical few. Everyone is responsible to own their focus area, so we deliver on the collective results through flowless execution. We’re empowered to make decisions which benefit the health of the company.
We demonstrate our commitment to being customer-centric by placing our customer at the center of all our communications, not ourselves.