Jobs and Careers
GE

Sr Staff Cyber Security Architect - Directory / PAM Architecture

GE
UKRemotefull_timeVerifiedPosted 4 Dec 2023
💰 $194,100/yr($116,100/yr$194,100/yr)

About the role

Job Description Summary

Job Description

Role Summary/Purpose 

 

As a Sr Staff Cyber Security Architect, you will be responsible for maintaining the architecture surrounding Active Directory DS, inclusive of Azure AD services, for GE Vernova’s Identity and Access Management (IAM) Privileged Access Management (PAM) solutions. The Sr Staff Risk Advisor will be responsible for the support, performance, lifecycle management, and continuous maintenance and improvement of the architecture surrounding Active Directory. Our central and downstream directories are critical to ensure proper architecture, business processes, and resiliency of our platform. 

 

Essential Responsibilities 

  • In this role, you will have a strong understanding of the Microsoft technology stack including but not limited to: 

  •  Azure AD Constructs 

  • Traditional Active Directory 

  •  Kerberos Authentication 

  • CyberArk 

  • Azure’s Privileged Identity Management [PIM] solution 

  • AWS Secrets Manager 

  • Work cross functionally with other business departments to align activities and deliverables. 

  • Privileged Identity Management (PAM) and the transition of services from the existing platform from a Coretech-owned solution to a Vernova-owned solution.   

  • Partner with required teams / personnel including CoreTech, Separation Management Office, Identity and Access Management teams across the various businesses and application and infrastructure teams.    

  • Successfully migrate all existing PAM components (e.g., safes, accounts, and groups) with minimal disruption. 

  • Apply principles of SDLC and methodologies like Lean/Agile/XP, CI, Software and Product Security, Scalability, Documentation Practices, refactoring, and Testing Techniques. 

  • Write code that meets standards and delivers desired functionality using the technology selected for the project. 

  • Partner with technical and functional teams external to the project to ensure their tasks are completed as required. 

  • Engage key business stakeholders and customers as it relates to all supported systems and applications to verify, validate, and audit system access. 

  • Support strategy planning and assist in the design and implementation of Directory Services solutions 

  • Ability to self-direct and work independently when necessary and clearly articulate technical concepts / issues to both technical and non-technical peers and management. 

Basic Qualifications 

  • Bachelor's Degree in Information Systems, Information Technology (IT), Computer Science, or Engineering or 8 years of IT technical experience 

  • Minimum 3 years of architecture and automation experience 

  • Some experience in Privileged Access Management (PAM) tool experience leveraging either CyberArk, AWS Secrets Manager or Azure Privileged Identity Management 

Desired Characteristics 

  • Understanding of various directory structures and configurations (LDAP, Active Directory, etc.). 

  • Working knowledge of APIs or other forms of application integrations. 

  • Experience with the RadiantLogic VDS platform. 

  • Experience with or general understanding of SSO (SAML/Oauth2.0). 

  • Understanding of PCI, SOX, HIPAA, EU-GDPR regulations for IAM. 

  • Working knowledge or better of industry standard IGA tools such as SailPoint, Saviynt and/or Sun/Oracle. 

  • Advanced knowledge and experience with the Microsoft Directory Stack and Azure and supporting components. 

  • General understanding of SOX, HIPAA and/or other global data regulations. 

  • Knowledge in Group Policy Management 

  • Knowledge in Sites and Services Management 

  • Experience in using, deploying, maintaining QUEST Tools 

  • Experience with AD Trusts 

  • Working knowledge of Powershell 

  • Advanced knowledge of PKI Infrastructure Management and practices 

  • Experience with Mergers and Divestitures preferred 

  • Knowledge about Kerberos Authentication, SMB, NTLM 

  • Working knowledge with WSUS and SCCM 

  • Experience with DFS 

  • Strong troubleshooting and root cause analysis experience 

  • Recognizes patterns and complexity in problems. Extracts decomposition algorithms, and strategically plans how to execute programs by understanding how best to decompose to expose / protect against risk. 

  • Thorough knowledge of Software Development Life Cycle principles. 

  • Good understandi

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

GE

View company profile →