Sr. Systems Engineer - PKI - Early Warning Services LLC
San Francisco, CA 94199
About the Job
At Early Warning, we've powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle, Paze, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.
Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.
Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.
Overall Purpose
The Sr. Systems Engineer leads activities that drive discovery, design, and delivery of Active Directory Services and Privileged Access Management platforms in a hybrid environment. In addition, this role is accountable for maintaining proper technical documentation of the supported systems, participating in audit and compliance activities, and a subject matter expert in Identity and Access Management. This person will also be charged with prototyping fresh solutions to Identity challenges and optimize existing systems and considering new technologies as they become available.
Essential Functions
- Provides operational excellence for multiple Active Directory environments including maintaining versions, vulnerability management, and overall health.
- Proactively monitors and maintains Active Directory security assurances such as threat detection, user behavior and privileged user monitoring.
- Provides operational excellence for our Privileged Access Management platforms maintaining versions, vulnerability management, and overall health.
- Proactively monitors and maintains our Privileged Access Management security assurances such as threat detection, user behavior and privileged user monitoring.
- Authors PowerShell scripts, or other related scripting languages to automate repetitive tasks.
- Protects privileged access and accounts utilizing an enterprise Privileged Access Management (PAM) platform.
- Ensures just-in-time and just-enough privileged access is being enforced without hindering productivity or user experience.
- Continuously evaluates the IAM organizational structure, system configuration, application integrations and provides recommendations for operational and/or security enhancements.
- Collaborates with Enterprise Architects, Security Architects and Application Architects to drive the adoption of IAM best practices, adoption, and assist in documentation.
- Develops a relationship with business and technology stakeholders ensuring on-time delivery.
- Actively participates in team stand-up, technical engineering discussions, change control process, audit activities, business continuity efforts, and on-call rotation.
- Mentors, Coaches, and trains junior systems engineers; models strong sense of responsibility, ownership, and pride in delivering quality results.
Support the company's commitment to risk management and protecting the integrity and confidentiality of systems and data.
Identity Governance Focus
- DevOps support for Identity Governance and Administration (IGA) solutions to include Incident and Request management, and implementation of new functionality including new integrations.
- Progressive experience and advanced proficiency with IGA products such as Sailpoint, Oracle Identity Manager or Saviynt.
- Expert understanding of various identity governance administration aspects such as attestations, analytics, connectors, rules, users, accounts, account ownership, roles, entitlement, entitlement ownership, security system, and endpoints.
- Experience integrating IGA solutions with two or more products such as Active Directory, Azure Active Directory, Okta, Workday, ServiceNow, Amazon Web Services.
- Working knowledge of SQL, REST, SOAP, JSON, XML, Groovy and PowerShell.
- Experience developing and testing new integrations and configurations including testing APIs for example through Postman.
Minimum Qualifications
- Education and/or experience typically obtained through completion of Bachelor's degree in computer science, Information Technology or related field or equivalent work experience.
- Minimum 7+ years' relevant experience supporting, maintaining, integrating, and implementing Active Directory in a hybrid environment.
- 5+ years' experience managing Privileged Access Management platforms with demonstrated realized benefits.
- Knowledge in key IAM concepts and methodologies including Single Sign On, Multi-Factor Authentication and Identity Lifecycle Management.
- Demonstrate advanced and practical knowledge of Identity and Access Management platforms and integrations.
- Ability to perform duties independently, without direct supervision and detailed guidance.
- Ability to work in a fast-paced dynamic environment that often requires shifting priorities.
- Great organizational and time management skills with the ability to communicate/collaborate effectively with team members and cross functional teams.
- Comfortable working in Windows and MacOS end user compute environments.
- Must be a US Citizen or US National.
- Background and drug screen.
Preferred Qualifications
- Microsoft Azure and/or AWS cloud experience highly desired.
- Effective delivery in a highly regulated environment such as PCI DSS.
- Proficiency in managing Active Directory PKI, Key Management, Certificate Authority, or related platforms.
- Ability to drive strategy sessions for the planning, development, and delivery of work efforts.
- Other IAM or Information Security role-based certifications.
Physical Requirements
Working conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling, and reaching. Must be able to lift ten pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers. Requires the ability to communicate with internal and/or external customers.
Employee must be able to perform essential functions and physical requirements of position with or without reasonable accommodation.
Candidates responding to this posting must independently possess the eligibility to work in the United States at the date of hire.
The pay scale for this position in:
Phoenix, AZ/Chicago, IL in USD per year is: $110,000 - $140,000.
New York, NY/ San Francisco, CA in USD per year is: $125,000 - $150,000.
This pay scale is subject to change and is not necessarily reflective of actual compensation that may be earned, nor a promise of any specific pay for any specific candidate, which is always dependent on legitimate factors considered at the time of job offer. Early Warning Services takes into consideration a variety of factors when determining a competitive salary offer, including, but not limited to, the job scope, market rates and geographic location of a position, candidate's education, experience, training, and specialized skills or certification(s) in relation to the job requirements and compared with internal equity (peers). The business actively supports and reviews wage equity to ensure that pay decisions are not based on gender, race, national origin, or any other protected classes.
Additionally, candidates are eligible for a discretionary bonus, and benefits.
#J-18808-Ljbffr