Jobs and Careers
KE

Information Security Senior Consultant (IAM Cloud Security)

KeyBank
For Those Who Work At Home, OH, United StatesRemotefull_timeVerifiedPosted 19 Nov 2024

About the role

Location:

For Those Who Work At Home - Various, Ohio 44144

ABOUT THE JOB (JOB BRIEF)

The IAM Cloud Security Senior Consultant is responsible for governance, oversight, and day to day operations of Identity and Access Management (IAM) in the KeyBank cloud environments which are currently Google Cloud Platform (GCP) and Microsoft Azure.

In close collaboration with Information Security (especially the Sailoint and Cyberark teams) and Cloud Infrastructure teams, the IAM Cloud Security Senior Consultant will serve as a subject matter expert to translate the existing on premise IAM access control governance model into a cohesive set of standards, policies and operating procedures to properly maintain a secure posture in a modern cloud-based ecosystem.   

ESSENTIAL JOB FUNCTIONS

  • Designs and executes access control provisioning and governance reviews for all applications hosted in the KeyBank cloud ecosystem.  The scope of these reviews includes both the people (workforce) as well as service accounts (non-human) that interface with the applications.
  • Establishes the detailed IAM governance policies and procedures applications for cloud environments including Google Cloud Platform (GCP), Microsoft Azure and Office 365.
  • Works closely with Security Architecture and Engineering, Application Security, and Code Automation teams to build, enhance, and monitor detective and preventative controls to ensure programmatic and manual (human) interaction with cloud APIs and configurations meet IAM guidelines for priviledged access.
  • Creation and regular review/tuning of IAM guardrails and procedures to maintain an up-to-date security posture that adjusts to changes made by the underlying cloud provider.
  • Implement centralized review/approval of high/medium risk privileges before application team applies the access in their environment(s).
  • Visibility, monitoring and preventative controls for resource-level (i.e. GCE instance) IAM policy
  • Collaborates with code automation and application security to enforce consistent security policies across application code deployment pipelines.
  • Knowledgeable of relevant industry regulations and standards such as NIST CSF, FFIEC CAT, Sarbanes-Oxley (SOX) and Payment Card Industry Data Security Standard (PCI DSS)
  • Communicates down, sideways, and upwards to effectively keep all stakeholders engaged and informed of program effectiveness, metrics, and issues.
  • Coordinates with other IAM managers and subject matter experts to manage and update metrics (e.g. KRIs, KPIs) to track and report risks and report metrics to senior management​.
  • Facilitate identification, documentation and mitigation of SoD risks with business process owners and stakeholders, through annual business process questionnaire completion and follow-up.
  • Partner with Business Process Risk Identification Program to provide/update content for stakeholder training on roles relating to SoD processes and annual certification, and lead change management iniaitives related to SoD program.
  • Perform validation of controls within IIQ
  • Handle troubleshooting and issue resolution related to IAM processes, ensuring the smooth functioning of the SoD program.
  • Maintain IT policies and standards that include SoD requirements
  • Enhance and maintain IAM operating model to include roles and responsibilities to manage SoD risks
  • Manage and update metrics (e.g. KRIs, KPIs) to track and report SoD risks and report metrics/ risks to senior management​.
  • Champions and maintains effective communication with lines of business and technology groups
  • Participate in technology and line of business projects. 

Create/own new security standards and provide security requirements and decisions as required.

REQUIRED QUALIFICATIONS

Education/Certifications:  Bachelor’s Degree or equivalent work experience required.

Experience:

  • Three plus years of Identity and Access Management experience in a large, highly-regulated environment.
  • Identity and Access Management experience or background
  • Subject matter expert knowledge of both the business and technical aspects of Identity & Access Management and/or Information Securitysecurity and technology with experience in cloud IAM governance.  Sailpoint and/or Cyberark experience a strong plus
  • In-depth knowledge of security and technology, with strong understanding of risk management.
  • Ability to make decisions based on prior experience in a large enterprise environment and solid understanding of the technologies and risks involved.
  • Familiarity with industry-standard Identity Providers including Microsoft Active Directory, IBM RACF, LDAP directories

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

KeyBank

View company profile →