Job DescriptionThe Identity and Access Management (IAM) Identity Engineer will assist in the development, implementation, and maintenance of IAM solutions that adhere to the University's security policies and requirements. Key responsibilities include supporting the evaluation of hosting platforms and configuration technologies to ensure consistency across production and non-production environments. This role requires collaboration with IAM Managers, Senior Engineers, Administrators, Analysts, various University departments, and external vendors to ensure secure, compliant, and efficient access and identity data management. As a member of the Identity and Lifecycle Management team, the IAM Identity Engineer will help design, implement, and maintain the technical infrastructure that supports the lifecycle of user identities within UCSF. This involves working with various IAM tools and technologies to securely manage identities from creation to deactivation, ensuring compliance with UCSF policies and regulatory requirements.
The IAM Identity Engineer should have experience in administering and supporting identity and governance (IGA) solutions. Additionally, they must possess knowledge and experience with advanced identity infrastructures. Strong troubleshooting skills are essential. Hands-on experience with technologies such as SailPoint, Bravura ID, or similar platforms is also required.
Department Overview:
University of California, San Francisco (UCSF) is distinguished as a leading academic healthcare organization, home to groundbreaking discoveries, world-class education, and exceptional healthcare services. Infrastructure Services (IS) is the backbone of the technological infrastructure, assuring the technical services that enable the academic, medical, and research missions of the organization. Beyond a focus on maintaining systems and resolving issues, we are committed to nurturing the potential of our team members and empowering them to excel. UCSF Infrastructure Services provides 24x7 support to the University community, always upholding the highest level of responsiveness and reliability for our customers. IS values innovation and excellence in ensuring secure and efficient Information Technology (IT) services, regardless of the hour or complexity of the issue.
The Identity and Access Management Services team within Infrastructure Services protects UCSF's resources through access management, including accounts, authentication, access, and role-based provisioning at the enterprise level. This team implements rigorous regulation of UCSF data through granular access control and the auditing of all UCSF assets on the premises and in the cloud. By ensuring information security at UCSF, the IAM Services team enables the academic, medical, and research mission of UCSF.
Responsibilities% of TimeEssential Function (Yes/No)Key Responsibilities25%
Yes
Identity and Lifecycle Management- Participates in the design, implementation, and integration of Identity and Access Management (IAM) solutions to support identity lifecycle management, including provisioning, maintenance, and de-provisioning of user identities.
- Develops and configures workflows and automation scripts to streamline identity management processes, including identity provisioning, de-provisioning, reconciliation, and remediation of discrepancies.
- Collaborates with IAM analysts and stakeholders to gather requirements, design, and implement IAM processes and technologies that align with the University's security policies and goals.
- Implements and maintains role-based access control (RBAC) models, defining and managing roles and entitlements to ensure they meet business requirements and security policies.
- Supports monitoring and analysis of IAM system performance, security, and compliance, recommending improvements and enhancements as necessary.
- Troubleshoots and resolves IAM system issues, working with appropriate teams to identify root causes and implement corrective actions.
- Develops and maintains technical documentation, including solution design documents, configuration guides, and process workflows.
- Assists in the development and implementation of security policies, procedures, and guidelines related to IAM.
20%
Yes
Problem Solving- Maintains network security systems by applying system patches and other periodic tasks, as needed. Reviews and monitors security appliances and enacts changes based on operational requirements. Builds network security infrastructures and responds to network-related incidents in a timely fashion.
- Assists in incident responses for breaches and intrusions, including responses that occur outside of normal business hours, as required. Tests systems for software and hardware weaknesses.
20%
Yes
Customer Service- Actively engages with stakeholders to resolve IAM-related issues. Acts as a consultant to campus departments to determine the root cause of access issues. Aligns activities to approved security policies.
10%
Yes
Continuous Improvement- Stays current with IAM technologies, trends, and regulatory requirements, and recommend changes to the University's IAM program, as needed.
- Facilitates innovation and continuous improvement by leveraging the latest industry knowledge and maintains currency with new technologies.
10%
Yes
Project Planning and Management- Plans and executes system upgrades, bug fixes, and other changes using service management software and methodologies.
10%
Yes
Communications and Training- Provides timely communications to stakeholders, technical staff, and management as required. Communicates and reports network security incidents and issues to University and Information Technology (IT) leaders.
5%
Yes
Other- Actively promotes the University's core values and consistently integrates innovation, employee fulfillment, teamwork, respect, excellence, integrity, service, and accountability into each aspect of their work.
- Maintains current knowledge of university policies and procedures; effectively, consistently, and fairly applies university policy and/or campus/division procedures for assigned area and team members supervised; complies with university, campus, and division policies and procedures regarding privacy of information, authorized use of university resources and the security of university systems and data.
- Participates in an on-call rotation for high and critical 24x7 incident response, as needed.
- Performs other related responsibilities as requested and when necessary. The University reserves the right to add or change duties at any time.
Total: 100%
QualificationsREQUIRED QUALIFICATIONS- Bachelor's Degree or equivalent combination of experience/training in one or more of the following fields: cybersecurity, information technology, computer science, public administration, business administration, communications
- 3 to 5+ years of experience working in one or more of the following fields: cybersecurity, computer science, computer information systems, etc.
- Experience with implementation and integration, experience with Identity and Access Management (IAM) systems and tools.
- Hands-on experience with directory services (e.g., Active Directory, Lightweight Directory Access Protocol (LDAP)), Single Sign-On (SSO) technologies, and multi-factor authentication (MFA) solutions.
- Proficient knowledge and experience in both relation and non-relational databases management, scripting, ETL process on-prem and on cloud.
- Proficient in scripting and programming languages (e.g., PowerShell, Python, Java) for automation and integration purposes.
- Experience in incident response and digital forensics, including reporting.
- Demonstrated skills applying security controls to computer software and hardware.
- Knowledge of data encryption technologies and experience selecting and applying appropriate data encryption technologies.
- Knowledge of Identity Governance and Administration (IGA) solutions, including SailPoint, Saviynt, Bravura Identity, and similar platforms.
- Strong written and verbal communication skills and ability to communicate technical information and ideas to a diverse community of colleagues and stakeholders.
- Ability to establish and advance positive working relationships and a strong rapport with team members, stakeholders, and customers.
- Strong organizational skills and ability to balance competing priorities and support concurrent projects. Experience working in a project-based environment using leading project management practices including schedule management, status reporting, and communication of project risks and issues.
- Strong demonstrated problem-solving skills; scopes solutions based on knowledge of available resources and timelines. Ability to ask questions, gather information, evaluate options, and make decisions with integrity.
- Thinks creatively and proposes innovative ideas, including the incorporation of new technologies or processes. Ability to work with agility in a fast-paced environment.
PREFERRED QUALIFICATIONS- Experience in complex higher education environments, serving academic, medical, and research, medical, and research and administrative functions of a large public university.
- One or more of the following certifications: CCNP Security, Cisco Certified Internetwork Expert (CCIE) Security, Offensive Security Certified Professional (OSCP), Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or equivalent
- Cisco Certified Internetwork Expert (CCIE) Security
Salary InformationThe final salary and offer components are subject to additional approvals based on UC policy.
Your placement within the salary range is dependent on a number of factors including your work experience and internal equity within this position classification at UCSF. For positions that are represented by a labor union, placement within the salary range will be guided by the rules in the collective bargaining agreement.
To learn more about the benefits of working at UCSF, including total compensation, please visit: https://ucnet.universityofcalifornia.edu/compensation-and-benefits/index.html