|
Job Summary: The Identity Access Management Engineer.is responsible for administering and enhancing identity and access management processes that support secure, compliant access to Firm systems, applications, and data. This role executes user provisioning, deprovisioning, access reviews, role maintenance, and documentation activities in accordance with Firm policies and security standards. The position exercises discretion and independent judgment when evaluating access requests, resolving exceptions, identifying control gaps, and recommending process improvements. This role partners with Information Technology, People & Culture, Compliance, the Office of the CISO, the Office of General Counsel, and business stakeholders to maintain appropriate access controls, protect confidential information, and support operational and regulatory requirements. The position may require occasional alternative schedules, on-call support, weekend work, and moderate travel. Job Duties:
- Administers user access to internal and external systems, applications, and network-based resources
- Reviews, approves, coordinates, and completes provisioning, modification, and deprovisioning activities in accordance with Firm policies, access standards, and security requirements
- Evaluates access requests and exceptions using discretion and independent judgment to ensure appropriate authorization, segregation of duties, and least-privilege access
- Prepares and maintains documentation for operating standards, access standards, policies, and system access guides and procedures
- Identifies process gaps and control weaknesses and develop improvements for granting, modifying, and revoking access
- Performs periodic audits and access reviews to confirm compliance with approved access models, internal controls, and Firm requirements
- Develops and maintain access guides for applications supported by the Identity Access Management function and validate access configurations through testing
- Tests and supports identity and access management provisioning tools and related workflows
- Maintains and updates business rules, role structures, and automation logic within IAM tools
- Validates approvals, business justification, and supporting documentation before granting or modifying access
- Determines whether requested access aligns with least-privilege principles, segregation of duties requirements, and established security standards
- Assesses access-related risk considerations and identify exceptions before permissions are granted or modified
- Develops and maintains IAM policies, access standards, onboarding requirements, and governance documentation for applications introduced into the environment
- Partners with project teams, vendors, and business stakeholders to define identity lifecycle requirements, access models, provisioning methods, and ongoing governance controls for new applications
- Designs, configures, and maintains automated provisioning workflows, exception handling processes, and identity lifecycle automation within IAM tools
- Manages identity and access administration activities for assigned business domains, including evaluating access requirements, validating approvals, and ensuring compliance with applicable security and regulatory requirements
- Applies technical expertise, risk assessment, and decision-making in support of the Firm's security and compliance objectives
- Completes assigned work items, service requests, and queue responsibilities within established service levels
- Other duties as required
Supervisory Responsibilities:
Qualifications, Knowledge, Skills and Abilities: Experience:
- Three (3) or more years of experience in identity access management, information security administration, or access governance, required
- Experience administering user lifecycle processes, including provisioning, deprovisioning, transfers, and access reviews, required
- Experience supporting regulated or highly controlled environments involving confidential or protected information, required
- Understanding of authentication protocols, such as SAML 2.0 or OAuth/SSO, required
- Experience with implementing automated provisioning of end-point by using custom provisioning flows, SCIM, API, or JIT, required
- Experience with ISO 20071, QC-1000, SOC2 frameworks and controls, preferred
- Experience identifying process improvements and implementing access control enhancements, preferred
License/Certifications:
- Microsoft identity or Azure security certification, required
- Active Directory administration training or certification, required
- Certified Identity Access Manager (CIAM), preferred
Software:
- Windows Active Directory Administration, required
- Microsoft Entra ID, required
- ServiceNow, required
- Microsoft 365 Admin, preferred
- Workato provisioning tools, preferred
Language:
Other Knowledge, Skills & Abilities:
- Strong verbal and written communication skills
- Excellent interpersonal and customer relationship skills
- Capacity to work in a deadline-driven environment while handling multiple complex projects/tasks simultaneously with a focus on details
- Capable of successfully multi-tasking while working independently or within a group environment
- Ability to rely on extensive experience and judgment to plan and accomplish goals
- Capable of working well under pressure while dealing with unexpected problems in a professional manner
- Capacity to communicate and interact with all levels of employees and management
- Ability to interact and build relationships and consensus among people
- Advanced knowledge and understanding of Firm standard applications and all aspects of the desktop environment
- Capacity to effectively instruct end users in the use of equipment and/or software by providing advice regarding policies and procedures
- Ability to research and resolve problems, acquire and maintain knowledge of relevant software solutions, and support firm policies and procedures
- Ability to travel for Firm business on a moderate basis
Individual salaries that are offered to a candidate are determined after consideration of numerous factors including but not limited to the candidate's qualifications, experience, skills, and geography.
National Range: $85,000 - $105,000
Maryland Range: $85,000 - $105,000
NYC/Long Island/Westchester Range: $85,000 - $105,000 At BDO, how we show up matters. We build strong relationships by supporting one another, our clients, and our communities with care, curiosity, and a commitment to helping one another grow and succeed. Here, you'll find meaningful work, leaders invested in your success, and opportunities to build a career around what matters most to you. Our purpose is to be the people our clients count on to grow with confidence and achieve what matters most. Our values guide how we bring that purpose to life each day. Together, they shape how we work with one another, serve our clients, and create meaningful impact. BDO provides assurance, tax, and advisory services to clients across the U.S. and around the world. No matter your role, you'll be part of a team helping clients navigate complexity and move forward with clarity. We are proud to be an ESOP company, offering participants a stake in the firm's success through beneficial ownership and a unique opportunity to enhance their financial well-being. As a qualified retirement plan, the ESOP is a meaningful addition to our comprehensive compensation and Total Rewards benefits* offerings. It also reinforces an ownership mindset that strengthens our connection to one another, our clients, and the future we're building together. Learn more about our benefits: BDO Total Rewards encompass more than traditional benefits. Click here to find out more! *Benefits may be subject to eligibility requirements. Equal Opportunity Employer, including disability/vets Click here to find out more!
|