Job Description
JOB SUMMARY:
The Azure Identity & Access Management Analyst is responsible for supporting the administration, security, and continuous improvement of our Microsoft identity environment. This role is responsible for helping manage user access, authentication controls, enterprise applications, role-based access, and identity governance processes that protect systems supporting healthcare operations and sensitive information, including electronic protected health information.
KEY RESPONSIBILITIES:
• Administer Microsoft Entra ID and Active Directory Domain Services users, groups, administrative roles, authentication methods, and access assignments in accordance with least-privilege principles.
• Support Conditional Access policies, multi-factor authentication, passwordless authentication, self-service password reset, and secure sign-in practices.
• Assist with role-based access control, privileged access reviews, and access request workflows for subscriptions, resource groups, enterprise applications, and related services.
• Perform identity lifecycle administration, including onboarding, role changes, transfers, terminations, group membership updates, and periodic access certification activities.
• Support enterprise application registrations, single sign-on configurations, managed identities, service principals, and certificate or secret lifecycle tracking.
• Monitor identity-related alerts, audit logs, risky sign-ins, access anomalies, and security recommendations; escalate issues as appropriate.
• Partner with infrastructure, security, application, service desk, compliance, and business teams to resolve access issues and improve identity governance processes.
• Maintain documentation for access procedures, identity controls, administrative processes, and compliance evidence.
• Support HIPAA, HITRUST, SOC 2, and internal security control activities related to access management, audit logging, authentication, and privileged access.
• Participate in incident response, service restoration, root-cause analysis, and continuous improvement efforts related to identity and access management.
• Assist with implementation of Zero Trust security practices, including identity-first access, least privilege, secure administration, monitoring, and periodic access review.
• Perform other job-related duties as required or assigned.
QUALIFICATIONS:
• Knowledge in Conditional Access, multi-factor authentication, single sign-on, enterprise applications, access reviews, and privileged access concepts.
• Understanding of least privilege, segregation of duties, Zero Trust principles, audit logging, and secure administrative practices.
• Ability to troubleshoot access issues, document findings, follow established procedures, and communicate clearly with technical and non-technical stakeholders.
• Strong attention to detail and commitment to protecting sensitive healthcare information.
• Familiarity with PowerShell, Azure CLI, and other scripting tools preferred.
• Working knowledge of Microsoft Entra ID, Active Directory Domain Services, Azure RBAC, user and group administration, authentication methods, and access lifecycle processes preferred.
• Professional, service-oriented approach to supporting internal customers and business partners preferred.
• Ability to manage multiple priorities, follow change control processes, and maintain confidentiality preferred.
• Strong analytical thinking, problem-solving skills, and willingness to learn new Microsoft cloud identity technologies preferred.
• Successful completion of Health Care Sanctions background check.
EDUCATION/EXPERIENCE:
• Associate degree in information technology, computer science, cybersecurity, business information systems, or a related field is required; bachelor’s degree preferred.
• A minimum of 2 years of relevant hands-on experience supporting identity administration, access management, Azure administration, cloud services, security operations, or enterprise IT support.
• Experience working in a hybrid identity environment with Microsoft Entra Domain Services and Active Directory Domain Services.
• Experience with Microsoft Entra ID Governance, Privileged Identity Management, Azure Monitor, Log Analytics, Microsoft Defender for Cloud, or Microsoft Sentinel preferred.
• Experience supporting HIPAA, SOC 2, NIST, or other security and compliance frameworks preferred.
• Experience supporting SaaS integrations, application access reviews, service principals, managed identities, and certificate or secret management processes preferred.
• Healthcare, financial services, or other regulated industry experience preferred.
• Microsoft certification such as Identity and Access Administrator Associate or Azure Administrator Associate preferred.
CommunityCare is an equal opportunity at will employer and does not discriminate against any employee or applicant for employment because of age, race, religion, color, disability, sex, sexual orientation or national origin