Volkswagen Group

IAM Engineer & Technical Lead

Volkswagen Group  •  Auburn Hills, MI (Hybrid)  •  11 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Worldwide, the Volkswagen Group has a long tradition of dramatic innovations. The Volkswagen Group with its headquarters in Wolfsburg, Germany is one of the world’s leading automobile manufacturers and the largest carmaker in Europe. The Group comprises twelve brands from seven European countries: Volkswagen Passenger Cars, Audi, SEAT, ŠKODA, Bentley, Bugatti, Lamborghini, Porsche, Ducati, Volkswagen Commercial Vehicles, Scania and MAN.

Brief Role Description

This position is Career Level 20L+, located in Auburn Hills, MI, with a Role Classification of Hybrid

Under the general supervision of the Sr Mgr., Workplace Technologies IAM Svcs the Identity & Access Management Engineer and Technical Lead is a part of both the Information Security and Technology & Operations team. This role is responsible for the day-to-day operations and support of the Information Security Identity and Access Management program. This is a hands-on position that works closely with Information Security team members on continuous design, assessment and hardening of company’s information security IAM posture, maturity level and risk assessments.

The IAM Engineer Team Lead will be responsible for supporting the planning, design, development and deployment of centralized identity & access management (IAM) and identity governance & administration (IGA) solutions. This role supports the planning, design, and delivery of the enterprise-level IAM program including but not limited to the areas of identity access management, privileged access management, SSO federation and SaaS / PaaS cloud technologies. This role will work with teams such as Development, Architecture, Security, Engineering and Operations to come up with optimized IAM solutions. This position focuses on both the technical and administrative aspects of IAM.

This role will be responsible for the Smart Card (PKI) infrastructure and processes, including server maintenance, card programming, incident troubleshooting, and alignment with the IT Security team in Germany.

Work Flexibility:

  • Must be willing to travel (mostly domestic) and work outside normal business hours.
  • Rotation on-call for support escalations.

Role Responsibilities

Operations – 70%

  • Oversight of identity and access management functions company-wide.
  • Responsible for the day to day oversight of Information Security Administration policies, procedures and systems in order to maintain confidentiality, integrity and availability.
  • Provide knowledge and act as a subject matter expert on key principles of (IAM) with an in-depth knowledge in the areas of authentication and authorization systems, identity lifecycle management, and identity governance
  • Lead, maintain and support Smart Card (PKI) infrastructure and processes
  • Responsible for IAM tools administration and configuration according to industry best practices; own identity access and governance related changes
  • Generate solutions and policies in support of the Identity Lifecycle Management and Identity Governance for the company.
  • Develop, maintain and administer RBAC policies, roles and permissions; employ and maintain segregation of duties and least privilege principles across all services.
  • Work closely with Information Security Operations & Engineering teams to ensure proper monitoring on internal and external (third party) access and design.
  • Ensure proper implementation and configuration of appropriate preventive, detective, and corrective controls for mitigation of IAM risks.
  • Develop and maintain IAM control requirements for cloud-based applications and services.
  • Develop technical documentation in support of identity and access management services.
  • Act as subject-matter expert (SME) and provide identity and access management consulting services.
  • Responsible for planning, managing, facilitating, instructing and monitoring IAM project activities for all assigned tasks.
  • Work with application owners to integrate application security and application roles with centralized IAM directories.
  • Work closely with business units across the company on a regular basis to assist in defining applications access security, application requirements and identify opportunities to improve company-wide IAM posture.
  • Responsible for ensuring team adherence to IAM processes and policies.
  • Execute on a strategic multi-year roadmap for IAM.
  • Manages and monitors systems associated with Identity and Access management solutions; provides incident and problem management support.
  • Lead, perform and assist with audits of application access, user accounts, privileged accounts, system accounts, security groups, server groups, segregation of duties, etc.; Responsible for performing discovery audits and environment health checks, and present findings and remediation strategies.
  • Dealer/Dealership administration including GEKO IDs, security certificates, eShop, Star Mobile, V-codes, dealer portal ID coordination, independent repair facility support, Erwin certificate requests, and privileged account maintenance.

Strategy – 20%

  • Develop strategic annual and quarterly road maps for identity and access management services.
  • Define and implement IAM process efficiencies; assesses current environment and makes continuous improvements to align with future state architecture.

Leadership – 10%

  • Lead and mentor a team of IAM administrators
  • Lead team incident and request ticket handling for quick resolution on a variety of 2nd and 3rd level security and access related topics.
  • Address escalations from team members, customers, colleagues and vendors

Qualifications

Years of Experience:

  • 10+ years of experience in Identity and Access Management BS and IT experience
  • 5+ years of Information Security
  • 3+ years of Lead/Supervisory Experience

Required Education:

Bachelor’s degree IT Security, Cybersecurity, Computer Science or related degree or equivalent real life experience

Desired Education:

Master’s degree IT Security, Cybersecurity, Computer Science or related degree

Skills:

  • Ability to convey complex technical concepts (e.g., security IAM designs, technologies, priorities, and concepts) effectively to a variety of audiences
  • Ability to analyze processes, procedures, and architectures for IAM implications
  • Solid analytical/problem solving skills with capability to identify solutions to unusual and complex problems
  • High degree of integrity and trust along with the ability to work independently
  • Strong policy and process knowledge, IT auditing skills and expertise to deal with a variety of technologies and customers
  • Demonstrated exceptional organization, troubleshooting and documentation skills
  • Excellent interpersonal and consultative skills to achieve security goals including ability to communicate well with IT teams and customer, both written and verbally
  • Ability to inform, educate, and influence managers and employees to support goals and initiatives
  • High degree of empathy, assertiveness, and persuasiveness and potential to lead small teams

Required Skills:

  • Strong understanding of IT Security and Information Technology
  • Extensive technical understanding of IAM concepts such as directory services, SSO, federation, MFA, provisioning, access re-certification, role based access control (RBAC) and separation of duties (SOD)
  • Technical expertise with large scale enterprise identity and access management systems including Azure AD (AAD), Microsoft Active Directory (AD) and LDAP
  • Technical knowledge of cloud based IAM external providers, networking and SaaS applications IAM security architecture.
  • Experience with network, systems, and cloud application identity and access management and compliance.
  • Familiarity with current security frameworks, standards and regulations that cover IAM best practices such as SOC2, NIST
  • Demonstrable experience of strategic and tactical thinking and working in information sensitive business(es)
  • Technical SME in Identity and Access Management
  • Ability to communicate complex concepts clearly, both verbally and in writing
  • Ability to approach problems from an IT security perspective coupled with sound business know-how
  • Must be an intelligent, articulate and persuasive leader who can communicate IAM-related concepts to a broad range of technical and non-technical staff
  • Ability to identify security risks and escalate where appropriate
  • Extensive technical IAM experience with the following applications:
  • Active Directory/Azure Active Directory
  • Quest Active Roles
  • LDAP, Sailpoint, SAP, RSA, VPN, SAML
  • Exchange on-prem and online
  • Understanding of core IT service and support practices
  • Working knowledge of ITIL processes
  • Experience with IT Service Management Tools

Desired Skills:

  • Sailpoint Identity IQ experience
  • CyberArk experience
  • Industry security certification (CISSP, CISA, CISM, etc.)
  • ITSM tools (ServiceNow, HP ServiceCenter)

Volkswagen Group of America is an Equal Opportunity Employer. We welcome and encourage applicants from all backgrounds, and do not discriminate based on race, sex, age, disability, sexual orientation, national origin, religion, color, gender identity/expression, marital status, veteran status, or any other characteristics protected by applicable laws.

This role description is a guideline and does not create contractual rights between the Company and any of its applicants. The Company does not enter into any type of employment contract, implied or written, with its applicants regarding job security.

This Organization participates in E-Verify. We maintain a drug free workplace and perform pre-employment substance abuse testing.

Volkswagen Group

About Volkswagen Group

The Volkswagen Group with its headquarters in Wolfsburg is one of the world’s leading automobile manufacturers and the largest carmaker in Europe. The Group is made up of ten brands from seven European countries: Volkswagen, Volkswagen Nutzfahrzeuge, ŠKODA, SEAT, CUPRA, Audi, Lamborghini, Bentley, Porsche and Ducati.

Our group sells vehicles in 153 countries and operates 114 production plants worldwide. Each working day, around 675,000 employees worldwide produce cars, are involved in vehicle-related services or work in the other fields of business.

Our goal is to make mobility sustainable for us and for future generations. Our promise: With electric drive, digital networking and autonomous driving, we make the automobile clean, quiet, intelligent and safe. At the same time, our core product becomes even more emotional and offers a completely new driving experience. It is also becoming part of the solution when it comes to climate and environmental protection. In this way, the car can continue to be a cornerstone of contemporary, individual and affordable mobility in the future. #Shapingmobility

Imprint & Legal: http://vw.de/legal-notice

DAT: http://vw.de/dat

Industry
Automotive & Mobility
Company Size
10,000+ employees
Headquarters
Wolfsburg, DE
Year Founded
Unknown
Social Media