About the job
We are seeking an Identity Access Management (IAM) Subject Matter Expert (SME) to serve as the senior technical authority for enterprise IAM capabilities supporting the SEC ISS contract. This role will lead the design, implementation, governance, and modernization of Microsoft Entra ID and Microsoft ICAM solutions across cloud and on-premises environments, enabling secure identity services aligned with zero-trust principles, federal security requirements, and SEC compliance objectives.
Responsibilities
- Serve as the enterprise subject matter expert for Identity and Access Management architecture and services
- Provide technical leadership for identity and access solutions across complex enterprise environments
- Design and implement secure authentication and authorization models using Microsoft Entra ID, Microsoft ICAM, and RBAC
- Lead integration of identity services with Microsoft 365 and enterprise applications
- Develop IAM standards, architectures, operating procedures, and governance frameworks aligned with zero-trust principles
- Manage identity lifecycle processes, including joiner, mover, and leaver workflows
- Implement and maintain Conditional Access, MFA, Privileged Identity Management (PIM), Privileged Access Management (PAM), and Identity Protection controls
- Establish and manage access reviews, entitlement management, and governance processes.
- Design and oversee Role-Based Access Control (RBAC) strategies, assignments, and recertification activities
- Support Authorization to Operate (ATO) objectives through documentation, control evidence, and operational readiness activities
- Ensure alignment with NIST, ISO 27001, CISA SCuBA, FISMA, and SEC/OIT security requirements
- Produce technical artifacts and audit evidence for assessments, audits, and compliance reviews
- Lead remediation efforts related to IAM findings, risks, and control deficiencies
- Drive automation of identity provisioning, deprovisioning, policy enforcement, and reporting processes
- Collaborate with security, cloud, endpoint, and service management teams to implement identity-dependent controls
- Provide strategic guidance on IAM roadmaps, modernization initiatives, and risk management strategies
- Lead troubleshooting and resolution of complex identity and access incidents
- Participate in on-call, surge support, travel, and overtime activities as required
Required Skills
- 8+ years of experience in Identity and Access Management, Identity Governance, Cybersecurity, or related enterprise security roles
- Hands-on expertise with Microsoft Entra ID (Azure AD) and Microsoft ICAM
- Strong experience implementing and managing Multifactor Authentication (MFA)
- Deep knowledge of Conditional Access policies and enforcement
- Expertise in Role-Based Access Control (RBAC)
- Experience with Privileged Identity Management (PIM) and Privileged Access Management (PAM)
- Strong understanding of Entra Identity Governance
- Experience managing identity lifecycle and account governance processes
- Experience integrating Microsoft 365 and enterprise applications with identity services
- Knowledge of compliance frameworks including NIST, ISO 27001, CISA SCuBA, and FISMA
- Strong understanding and practical application of zero-trust security principles
- Experience automating IAM processes using scripting and platform-native capabilities
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Engineering, or a related field
- Ability to obtain and maintain SEC Public Trust clearance or higher
Preferred Skills
- Experience leading IAM modernization programs within federal government or highly regulated enterprise environments
- Experience supporting SEC, financial regulatory, or other mission-critical public sector organizations
- Experience implementing phishing-resistant authentication methods, including FIDO-aligned solutions
- Experience deprecating legacy authentication protocols and modernizing identity platforms
- Hands-on experience integrating IAM controls into DevSecOps environments
- Experience supporting audit remediation programs, corrective action plans, and executive-level risk reporting
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)