Softtek

Security Admin Identity & Access Mgt Ex

Softtek  •  Jersey City, NJ (Onsite)  •  1 day ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Experience Profile
12+ years in Cybersecurity/IAM roles, including a minimum of 5 years of hands-on SailPoint and enterprise Active Directory/Entra ID administration; prior experience in financial services or another highly regulated, multi-country environment is strongly preferred.
Acts as the dedicated Cybersecurity/IAM counterpart to the Data Governance-led team, translating approved RBAC/ABAC role and coverage definitions into governed SailPoint roles and Active Directory/Entra ID security groups, and ensuring every entitlement change is provisioned, approved, recertified, and audited through the client's existing identity governance ecosystem.
Key Responsibilities
  • Co-author RBAC/ABAC policy definitions with the Data Governance Architects and Business Analyst, ensuring technical feasibility within SailPoint and AD/Entra ID.
  • Design and configure the role-to-group mapping schema between the entitlement taxonomy and Active Directory security groups.
  • Configure SailPoint roles, access request/approval workflows, and recertification campaigns aligned to SmartApproval and Firmwide Certification.
  • Configure Entra ID roles, access request/approval workflows, and recertification campaigns aligned to SmartApproval and Firmwide Certification.
  • Design SailPoint and Entra ID certification campaigns (scope, reviewers, frequency, and escalation rules) aligned to the tri-annual Firmwide Certification cycle.
  • Administer elevated-permission and break-glass access (HR-for-HR, Operating Committee, senior/peer) with documented approval chains.
  • Integrate SailPoint and Entra ID audit and certification events with Splunk for monitoring, alerting, and evidence capture.
  • Support UAT, negative testing, and production cutover for all IAM-layer components.
  • Co-author the IAM sections of the operational runbook and lead related knowledge-transfer sessions.
Required Technical Skills
  • Hands-on SailPoint (IdentityIQ or IdentityNow) role, workflow, and certification configuration.
  • Hands-on Entra ID role, workflow, and certification configuration.
  • Active Directory / Entra ID security-group administration at enterprise scale (multi-thousand group environments).
  • RBAC and ABAC policy design; entitlement/role-catalog modeling.
  • ServiceNow access-request/workflow integration.
  • Working knowledge of data-layer entitlement enforcement tools (e.g., Immuta, Databricks Unity Catalog) to align IAM groups with downstream policy consumption.
  • Scripting/API experience for SailPoint connectors and automation (e.g., PowerShell, Python, REST APIs).
  • Log/audit integration experience with SIEM platforms (Splunk preferred).
  • Experience operating within regulated, multi-country financial-services environments.
Certifications (Preferred, Not Mandatory)
  • SailPoint Certified IdentityIQ Engineer / IdentityNow Engineer.
  • CISSP or CISM.
  • Microsoft Identity and Access Administrator (SC-300).
  • ITIL Foundation.

Softtek

About Softtek

At Softtek, we drive the strategic development of our clients through software engineering. For more than 40 years, we have helped leading companies develop, implement, and manage technology capable of improving people’s lives. Pioneers of the Nearshore model, Softtek connects innovation to business strategy. We don’t claim to “reinvent” or “reimagine” the business — we deliver results.

For more information on what we do, who we are, and career opportunities, visit www.softtek.com / Follow us on Instagram (@softtekofficial), on X (@Softtek), and be our fan on Facebook www.facebook.com/softtek.

Industry
IT & Software
Company Size
10,000+ employees
Headquarters
Monterrey, MX
Year Founded
1982
Social Media