Identity & Access Management Analyst
Central Hudson · Poughkeepsie, NY · 3 days ago
Business Development$73k–$171k/yrFull-time
About the role
We are seeking a diligent and experienced Identity and Access Management (IAM) Analyst to join our team. In this role, you will be working within a group of highly motivated Information Technology and Cybersecurity professionals committed to keeping Central Hudson safe.
Responsibilities
- Administers and maintains identity and access management platforms, including Azure Entra ID (Azure AD), Active Directory, SailPoint and related IAM solutions to ensure secure and efficient access across the organization
- Create, manage Microsoft Entra ID (Azure AD) Enterprise Applications and App Registrations, including configuration of authentication methods (OAuth2/OIDC/SAML), API permissions, secrets/certificates, and lifecycle governance aligned with enterprise security standards
- Manage the full identity lifecycle including provisioning, de-provisioning, transfers, and role changes for employees, contractors, and service accounts
- Implement and maintain role-based access control (RBAC) models, ensuring access rights are aligned with job functions and the principle of least privilege
- Administer and support multi-factor authentication (MFA), single sign-on (SSO), and conditional access policies to strengthen authentication controls
- Manage and monitor privileged access management (PAM) solutions to secure elevated accounts and reduce risk of credential-based attacks
- Conduct regular user access reviews and certification campaigns to validate access appropriateness and ensure compliance with internal policies and regulatory requirements (e.g., SOX, NERC CIP)
- Investigate and resolve access-related incidents, including unauthorized access attempts, account lockouts, and permission escalation issues
- Develop and maintain IAM policies, procedures, and standard operating documentation
- Partner with HR, IT, and business units to ensure timely and accurate access provisioning aligned with onboarding, offboarding, and role change processes
- Support the integration of applications and systems with centralized IAM platforms, including SAML, OAuth, OIDC, and SCIM-based integrations
- Monitor IAM systems for anomalies, misconfigurations, and potential security risks; escalate findings and recommend remediation actions
- Generate reports and dashboards on IAM metrics, including access review completion rates, provisioning SLAs, and policy compliance
- Automate IAM workflows and processes using scripting and orchestration tools to improve efficiency and reduce manual effort
- Stay updated with the latest IAM trends, threats, and technologies, and apply this knowledge to strengthen the organization’s identity security posture
- Support audit and compliance activities by providing evidence of access controls, policy enforcement, and identity governance
- Promote and raise awareness by educating others about the importance of identity security and access hygiene best practices
- Support project planning and execution for IAM-related initiatives, including tracking timelines and resource needs
- Provide storm/emergency response support as needed
Requirements
- Required: Bachelor’s degree in Cybersecurity, Information Technology, Computer Science or related field of study and IAM or related experience. In lieu of a bachelor’s degree, an associate degree in the aforementioned fields and 3+ years of IAM or related experience or a high school diploma or equivalency degree and 5+ years of IAM or related experience will be considered
- Experience administering identity and access management solutions such as Azure Entra ID (Azure AD), Active Directory, or other IAM/IGA platforms
- Understanding of IAM concepts including identity lifecycle management, RBAC, least privilege, SSO, MFA, and conditional access
- Experience with user provisioning, de-provisioning, and access certification processes
- Experience configuring and administering Windows Servers, Active Directory & Group Policy, Microsoft 365, Azure Entra ID, and Azure compute and networking resources
- Familiarity with scripting for automation and analysis (e.g., PowerShell, Python, Bash)
- Familiarity with authentication and federation protocols such as SAML, OAuth, OIDC, and SCIM
- Familiarity with Microsoft Entra ID application integration, including Enterprise Applications and App Registration concepts, authentication flows, and API permissions
- Understanding of privileged access management (PAM) principles and tools
- Understanding of regulatory and compliance frameworks as they relate to access controls (e.g., SOX, NERC CIP, NIST)
- Understanding of Operational Technology (OT) systems and their access management requirements
- Effective communication skills, with the ability to collaborate with diverse teams and communicate complex concepts clearly and concisely
- Excellent analytical, decision-making, multitasking, and organizational skills
- Ability to work with limited direct supervision and professionally respond to constructive feedback
- Ability to be available for on-call and after-hour access-related incidents
Qualifications
- Preferred: 5+ years of experience in identity and access management or a closely related cybersecurity discipline
- Experience with Identity Governance and Administration (IGA) platforms such as SailPoint, Saviynt, or Microsoft Identity Governance
- Experience in Security and/or Regulatory Frameworks such as NIST, CIS Benchmarks, SOX, NERC CIP, etc.
- Experience in Energy & Utilities or services industry
- Experience implementing or managing PAM solutions such as CyberArk, BeyondTrust, or Delinea
- Experience with data visualization tools and building IAM operational dashboards
- Experience developing IAM automation workflows and integrations
- Relevant certifications such as Certified Identity and Access Manager (CIAM), Certified Information Systems Security Professional (CISSP), CompTIA Security+, Microsoft Certified: Identity and Access Administrator Associate (SC-300), SailPoint Certified IdentityNow Engineer