The Identity and Access Management (IAM) Identity Engineer will assist in the development, implementation, and maintenance of IAM solutions that adhere to the University's security policies and requirements. Key responsibilities include supporting the evaluation of hosting platforms and configuration technologies to ensure consistency across production and non-production environments. This role requires collaboration with IAM Managers, Senior Engineers, Administrators, Analysts, various University departments, and external vendors to ensure secure, compliant, and efficient access and identity data management. As a member of the Identity and Lifecycle Management team, the IAM Identity Engineer will help design, implement, and maintain the technical infrastructure that supports the lifecycle of user identities within UCSF. This involves working with various IAM tools and technologies to securely manage identities from creation to deactivation, ensuring compliance with UCSF policies and regulatory requirements.
The IAM Identity Engineer should have experience in administering and supporting identity and governance (IGA) solutions. Additionally, they must possess knowledge and experience with advanced identity infrastructures. Strong troubleshooting skills are essential. Hands-on experience with technologies such as SailPoint, Bravura ID, or similar platforms is also required.
The IAM Identity Engineer will positively impact UCSF’s operations and culture by ensuring UCSF’s IT infrastructure is operable, secure, efficient, and effective in service of the University’s mission. This team member will advance the University’s mission by delivering exceptional information technology services comprehensively and consistently across customers and stakeholders. This role will execute UCSF’s vision while modeling UCSF’s culture and values.
Department Overview
University of California, San Francisco (UCSF) is distinguished as a leading academic healthcare organization, home to groundbreaking discoveries, world-class education, and exceptional healthcare services. Infrastructure Services (IS) is the backbone of the technological infrastructure, assuring the technical services that enable the academic, medical, and research missions of the organization. Beyond a focus on maintaining systems and resolving issues, we are committed to nurturing the potential of our team members and empowering them to excel. UCSF Infrastructure Services provides 24x7 support to the University community, always upholding the highest level of responsiveness and reliability for our customers. IS values innovation and excellence in ensuring secure and efficient Information Technology (IT) services, regardless of the hour or complexity of the issue.
The Identity and Access Management Services team within Infrastructure Services protects UCSF’s resources through access management, including accounts, authentication, access, and role-based provisioning at the enterprise level. This team implements rigorous regulation of UCSF data through granular access control and the auditing of all UCSF assets on the premises and in the cloud. By ensuring information security at UCSF, the IAM Services team enables the academic, medical, and research mission of UCSF.
% of Time
Essential Function (Yes/No)
Key Responsibilities
25%
Yes
Identity and Lifecycle Management
Participates in the design, implementation, and integration of Identity and Access Management (IAM) solutions to support identity lifecycle management, including provisioning, maintenance, and de-provisioning of user identities.
Develops and configures workflows and automation scripts to streamline identity management processes, including identity provisioning, de-provisioning, reconciliation, and remediation of discrepancies.
Collaborates with IAM analysts and stakeholders to gather requirements, design, and implement IAM processes and technologies that align with the University's security policies and goals.
Implements and maintains role-based access control (RBAC) models, defining and managing roles and entitlements to ensure they meet business requirements and security policies.
Supports monitoring and analysis of IAM system performance, security, and compliance, recommending improvements and enhancements as necessary.
Troubleshoots and resolves IAM system issues, working with appropriate teams to identify root causes and implement corrective actions.
Develops and maintains technical documentation, including solution design documents, configuration guides, and process workflows.
20%
Yes
Problem Solving
Maintains network security systems by applying system patches and other periodic tasks, as needed. Reviews and monitors security appliances and enacts changes based on operational requirements. Builds network security infrastructures and responds to network-related incidents in a timely fashion.
20%
Yes
Customer Service
10%
Yes
Continuous Improvement
Stays current with IAM technologies, trends, and regulatory requirements, and recommend changes to the University's IAM program, as needed.
10%
Yes
Project Planning and Management
10%
Yes
Communications and Training
5%
Yes
Other
Actively promotes the University’s core values and consistently integrates innovation, employee fulfillment, teamwork, respect, excellence, integrity, service, and accountability into each aspect of their work.
Maintains current knowledge of university policies and procedures; effectively, consistently, and fairly applies university policy and/or campus/division procedures for assigned area and team members supervised; complies with university, campus, and division policies and procedures regarding privacy of information, authorized use of university resources and the security of university systems and data.
Participates in an on-call rotation for high and critical 24x7 incident response, as needed.
Total 100%
REQUIRED QUALIFICATIONS
Bachelor’s Degree or equivalent combination of experience/training in one or more of the following fields: cybersecurity, information technology, computer science, public administration, business administration, communications
PREFERRED QUALIFICATIONS
