Sr Cyber Security Engineer (SailPoint, J2EE, Rest) - NBCUniversal
Englewood Cliffs, NJ 07632-3312
About the Job
We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our theme parks and consumer experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, MSNBC, CNBC, NBC Sports, Telemundo, NBC Local Stations, Bravo, USA Network, and Peacock, our premium ad-supported streaming service. We produce and distribute premier filmed entertainment and programming through Universal Filmed Entertainment Group and Universal Studio Group, and have world-renowned theme parks and attractions through Universal Destinations & Experiences. NBCUniversal is a subsidiary of Comcast Corporation.
Here you can be your authentic self. As a company uniquely positioned to educate, entertain and empower through our platforms, Comcast NBCUniversal stands for including everyone. Our Diversity, Equity and Inclusion initiatives, coupled with our Corporate Social Responsibility work, is informed by our employees, audiences, park guests and the communities in which we live. We strive to foster a diverse, equitable and inclusive culture where our employees feel supported, embraced and heard. Together, we’ll continue to create and deliver content that reflects the current and ever-changing face of the world.
Job DescriptionJoin the NBCUniversal Identity and Access Management team and help drive strategy for the growing Identity and Access Management (IAM) service portfolio. The Sr. IGA Engineer is responsible for supporting IAM in driving technology planning, application development, implementation, operations, and support for the company's digital identity and access for all enterprise workforce members.
This Sr Cyber Security Engineer role is a critical member of the NBCU IAM team responsible for the technical leadership of the Identity Governance service (IGA). You'll be responsible for designing and developing on-prem and cloud-based IGA services with the goal of reducing cyber risk where our personas, devices, and applications consume identity. Successful candidates will couple a technical mindset with a balanced business solution approach, while applying knowledge, flexibility, and strong communication skills.
Responsibilities
- Translate complex business requirements into IAM and IGA service functionality
- Develop highly scalable identity service serving enterprise, customer access, and external partner requirements
- Produce technical solutions that meet NBCU business objectives and drive compliance with NBCU’s information security goals
- Partner with technology and security teams across NBCU to provide technical expertise, design guidance, and drive best practices
- Catalog risk embedded in legacy authorization implementations and help define a path to industry-aligned secure designs and services
- Partner in product evaluations and new technology adoptions
- Lead the execution of a comprehensive IGA enterprise-level program for the organization
- Implement, manage, lead, and document identity governance processes and tools
- Provide ongoing reporting on the program metrics to ensure the quality of the program's services is meeting business objectives
- Ensure that IGA process and workflow documentation is created and maintained
- Mentoring/advising other team members
Basic Requirements:
- Bachelor of Information Security or equivalent work experience
- 5+ years’ experience designing solutions in IAM technical role(s) for large enterprise
- Significant hands-on and design experience with modern and legacy IGA services
- Experience developing Identity Lifecycle Management automation solutions
- Experience with application connection design and consulting experience on IGA functions like user life cycle management, access control policies, federation, certifications, Access management, MFA and role management
- Experience designing infrastructure, on-boarding of applications, role-based access controls, policy and password management, certifications, workflows, work items and rules
- Deep knowledge and hands on technical experience with Lifecycle Manager, Compliance Manager, Access Request, Automated Provisioning Password Management
- Understanding of RBAC, Identity Policies, Identity Lifecycle automation and reporting, Password Policies, Separation of duties, User Provisioning, and approval workflows in Saviynt, Microsoft EntraID, SailPoint IIQ and IDN
- Ability to make source code level changes and has worked in a large multinational organization providing hands-on technical architecture services with J2EE development, Database, Java, Bean Shell/JavaScript, JSP/Servlets, SQL
- Experience with Rest Web services, SAML 2.0, JDKs, OAuth, WS-Security, etc.
- Experience with enterprise directory services, including significant knowledge of Active Directory and Entra ID
- Exceptional communication and interpersonal skills; including negotiation, facilitation, and consensus building skills; ability to influence, persuade, and manage polarities without direct control
- Ability to balance the long-term big picture and short-term implications of tactical decisions
- Possesses an innovative technical mindset with a focus on architecture, strategy, and design
- Strong desire to drive change
Desired Characteristics:
- Excellent Communications Skills
- Experience building and delivering large-scale Enterprise SailPoint service instances
- Experience developing and delivering Zero Trust designs
Additional Requirements:
- Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee’s residence.
This position is eligible for company sponsored benefits, including medical, dental and vision insurance, 401(k), paid leave, tuition reimbursement, and a variety of other discounts and perks. Learn more about the benefits offered by NBCUniversal by visiting the Benefits page of the Careers website. Salary range: $100,000 - $135,000
We are accepting applications for this position on an ongoing basis.
Additional Information
As part of our selection process, external candidates may be required to attend an in-person interview with an NBCUniversal employee at one of our locations prior to a hiring decision. NBCUniversal's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law.
If you are a qualified individual with a disability or a disabled veteran and require support throughout the application and/or recruitment process as a result of your disability, you have the right to request a reasonable accommodation. You can submit your request to AccessibilitySupport@nbcuni.com.
For LA County and City Residents Only: NBCUniversal will consider for employment
qualified applicants with criminal histories, or arrest or conviction records, in a manner
consistent with relevant legal requirements, including the City of Los Angeles' Fair Chance
Initiative For Hiring Ordinance, the Los Angeles' County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable.