Overview:We are seeking an experienced Information Security Analyst and Administrator to support our client's security-related technologies, processes, and implementations. This position will serve as the primary IT Security subject matter expert especially with the deployment of a new Identity Access Management solution and case management system.
Will need knowledge and experience with both on-premises and cloud environments especially within OKTA, Azure platform, and Active Directory. Strong communication and organization skills, and a deep understanding of Identity and Access Management solutions.
Duties & Responsibilities:- Server as primary IT Security Subject Matter Expert (SME) for the Department of Child Support Services.
- Manage user authentication, authorization, and access control policies to prevent unauthorized access
- Support the design and build of role-based access control security frameworks for the department,
- Perform vulnerability scans, penetration tests, and risk assessments to identify and mitigate threats
- Monitor security alerts, investigate breaches, and respond to incidents promptly
- Develop, enforce, and update security policies; ensure compliance with legal and regulatory requirements
- Educating staff on security best practices and protocols
- Support the creation and maintenance of business continuity and disaster recovery plans
- Administer identity and access management (IAM) systems including OKTA, Active Directory, Azure AD, and privileged access workstations
- Monitor SIEM platforms (Splunk, Microsoft Sentinel, QRadar) for security events, tune alert rules, and escalate confirmed incidents
- Implement and enforce multi-factor authentication, certificate management, and single sign-on configurations across enterprise applications
- Develop and maintain security policies, standards, and procedures aligned with NIST CSF, ISO 27001, or CIS Controls frameworks
- Support security audits and compliance assessments for SOC 2, HIPAA, PCI-DSS, or FedRAMP by gathering evidence and remediating findings
- Perform security reviews on new systems, applications, and vendors as part of the change management and third-party risk process
- Investigate phishing incidents, malware infections, and unauthorized access events; document findings and implement corrective controls
- Identify and mitigate security replated project risks, issues, and dependencies, and develop contingency plans to ensure project success.
Required Skill Sets:- Deep technical expertise in Microsoft Active Directory and Microsoft Entra ID.
- Experience designing and implementing IAM integrations, provisioning workflows, and access controls.
- Proven experience implementation & maintaining role-based access control frameworks.
- Proven ability to lead and mentor technical engineering teams.
- Strong understanding of identity security principles and enterprise authentication models.
- Previous experience with NIST CSF, ISO 27001, or CIS Controls frameworks
- Bachelor's degree, preferably in Computer Science, Information Technology, Computer Engineering, or related IT discipline; or equivalent experience
Preferred Qualifications:- Strong understanding of identity security principles and enterprise authentication models. (SAML, OIDC, SCIM) and access control models like Fine-Grained Authorization (FGA)
- Public sector child support/HHS; modernization programs.
- Firewalls and network security: Palo Alto Networks, Fortinet FortiGate, Cisco ASA/FTD - rule writing, NAT, VPN configuration
- SIEM: Splunk (SPL queries), Microsoft Sentinel (KQL), IBM QRadar - correlation rule tuning, dashboard creation
- Endpoint security: CrowdStrike Falcon, Microsoft Defender for Endpoint, Carbon Black - alert triage, isolation, policy management
- IAM: Active Directory, Azure Active Directory, Okta, CyberArk for PAM
- Scripting: PowerShell and Python for automation of repetitive security tasks (log parsing, alert enrichment, AD queries)
- Experience with ServiceNow and integration with prevalent identity access management platforms.
Tools & Platforms:- ServiceNow, Active Directory, Okta, Ping Identity, Azure AD, Cisco ASA, Fortinet FortiGate, Palo Alto PA-OS, Check Point, FortiGate, Splunk, IBM QRadar, Microsoft Sentinel, eSet, Proofpoint Nessus, Qualys, NDiscovery, OpenVAS, ISO 27001 compliance checklists, CJIS compliance tools, SSAE 16 audit frameworks, NIST & Fed Ramp frameworks.
Certifications- CompTIA Security+, CISSP (Certified Information Systems Security Professional), Microsoft Azure Security Engineer Associate (AZ-500), Microsoft Applied Skills: Administer Active Directory Domain Services
Skills:Identity and Access Management (IAM),Active Directory,Microsoft Entra ID,IAM Integrations,JIRA,Azure DevOps