Lead IAM Security Engineer

Strategic Staffing Solutions

Lutz (FL)

On-site

USD 130,000 - 190,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

TECO Energy is seeking a senior IAM Security Engineer/Lead with Saviynt IGA expertise to drive maturity and strategic execution across TECO Energy and its subsidiaries. The role emphasizes SAP and non-SAP application security, RBAC and IGA processes, and cross-department collaboration with Cyber Security, HR, RPA, and LoBs.

The candidate will lead design and implementation of access controls, SSO, and regulatory compliance efforts, ensuring confidentiality, integrity, and availability of IAM

Qualifications

  • Proficient understanding of RBAC concepts and authorization object concepts.
  • Advanced knowledge of identity lifecycle management and onboarding/offboarding workflows.
  • Advanced understanding of developing scripts or custom code to enhance IAM functionality.
  • Advanced knowledge of position-based security and HR data access controls.
  • Advanced knowledge of HR data authorization and org-structure based access.
  • Advanced/Expert knowledge of reporting tools and privileges concepts.
  • Experience integrating IAM with other applications, directories, and platforms.

Responsibilities

  • Lead the strategic IAM roadmap aligned with business goals.
  • Design and implement access control policies and least-privilege principles.
  • Design, implement, and maintain IGA processes (RBAC, certification, audits).
  • Enforce authentication, password, and session management policies; monitor incidents.
  • Serve as SME for audit/compliance for IAM, SOX, and PII; document and report findings.
  • Deploy and manage SSO solutions; enable cross-system authentication.
  • Collaborate with technical and business owners to optimize IAM tooling.

Job description

JOB-247302 Lead IAM Security Engineer- Saviynt IGA

Client: Teco

IAM Security Engineer/Lead- Saviynt IGA

Key Direction

The goal is not to hire administrators or analysts performing day-to-day operational work. IBM already provides Tier 1/Tier 2 support and routine administration.

The organization needs senior-level IAM and Data Security professionals who drive maturity, innovation, and strategic execution.

Primary focus: Saviynt IGA

POSITION CONCEPT

The IAM Security Engineer is responsible for operating the company’s information security systems, ensuring that all procedures are followed on a daily, weekly, and monthly basis. Provides expert level support, within a team environment, for all systems used to secure the enterprise information technology assets, the scope includes all network infrastructure, operating systems, and web server platforms throughout TECO Energy and its subsidiaries. Direct assistance with the development and enhancing of IAM systems including SSO, authentication, and access controls ensuring confidentiality, integrity, and availability of IAM systems and data. Provides IAM Security support for the TECO environment primarily focusing on SAP and Non-SAP Corps applications, NERC Applications. Responsible for adhering to established policies, following best practices, developing, and possessing an in-depth understanding of exploits and vulnerabilities, resolving issues by taking the appropriate corrective action, or following the appropriate escalation procedures. Supports the enforcement of corporate, regulatory, and risk management policies and assists in developing, maintaining, and publishing corporate IAM security standards, procedures, and guidelines for enterprise computing platforms. Position will be responsible for collaborating with multiple business units across Tampa Electric (TEC), Peoples Gas (PGS), New Mexico Gas (NMG), and Emera.

PRIMARY DUTIES AND RESPONSIBILITIES

1. Lead, develop and maintain a strategic roadmap for Identity and Access Management (IAM) aligned with both business and technological objectives. Collaborate closely with teams including Cyber Security, Human Resources, RPA, and Lines of Business (LoBs) to create efficient and user-friendly IAM solutions. (20%)

2. Lead, design, and implement access control policies and authorization mechanisms to govern user access to systems, applications, and data. Enforce the principle of least privilege to minimize security risks. (20%)

3. Design, Implement and maintain IGA processes, including role-based access control (RBAC), certification, and compliance monitoring. Conduct regular access reviews and audits to ensure compliance with policies and regulations. (20%)

4. Enforce security policies related to authentication, password management, and session management. Monitor, respond to security incidents related to unauthorized access attempts and troubleshoot the incidents. (10%)

5. Serve as Subject Matter Expert (SME) for audit, compliance, and regulatory efforts pertaining to IAM, SOX, and PII through investigating, documenting, and reporting to management. (10%)

6. Deploy and manage SSO solutions to enhance user convenience while maintaining security. Integrate applications to enable seamless and secure authentication across multiple systems. (10%)

7. Effectively collaborate with both Technical and Non-technical business owners, highlighting strong interpersonal skills. Actively seek opportunities to optimize the use of IAM toolsets and processes in support of business goals and provide innovative ideas. (10%)

Required:

  • Proficient understanding of RBAC roles, including their assignment, coupled with a practical grasp of authorization object concepts.
  • Advanced/Expert knowledge of the identity lifecycle management by designing workflows for user onboarding, offboarding and changes.
  • Advanced/Expert understanding of Developing scripts, connectors, or custom code to enhance IAM functionality and address specific requirements.
  • Advanced Knowledge of position based security and how roles are assigned to positions on the org structure. This includes advanced troubleshooting of access issues related to position-based security
  • Advanced knowledge of how structural authorization is used via the org structure to restrict access to HR data. Authorizations are based on a user’s position within the org structure. Should also have advanced knowledge of the other configuration, organizational structure, and structural profile considerations, which govern what users, can do & on what HR data they can operate
  • Advanced/Expert knowledge of the use of reporting tools and privileges concepts
  • Advance knowledge of Customizing IAM solutions to align with specific business needs and processes and Integrate IAM systems with other applications, directories, and platforms.
  • Advanced knowledge of Reporting tool security as it relates to securing access to various reports, applications, connections, WEBI's, performing certain functions within certain related objects along with creating users.
  • Advanced knowledge of the SAP portal architecture and user administration and how it handled through portal frontend along with troubleshooting knowledge of said architecture. Perform SAP security and authorizations duties, including Portal Roles, Single-Sign-On, Directory services, and securing Internet Transaction Server / web services
  • Advanced knowledge of established system security control policies as it relates to GRC. Ability to analyze application authorization/privileges assignments and segregation of duties (SOD) conflicts, works with internal audit and compliance teams to resolved identified violations. Functional knowledge and implementation experience of GRC Access Control
  • Working knowledge of the processes that ensure compliance with NERC, CIP, SOX, NIST and PCI;

Preferred:

  • General knowledge of Active Directory (AD) or other LDAP Directory Services, especially querying/updating through scripts/programs
  • Multi-Factor Authentication (MFA) technology – skills deploying and supporting MFA technology for internal and internet-facing application requirements.
  • Single Sign-On (SSO) technology – skills deploying and supporting Single Sign-on (SSO) applications within an organization. Must include support skills such as tracing, logging, and real-time troubleshooting. Federated SSO - Security Assertion Markup Language (SAML) and/or OpenID Connect (OIDC) skills required to support both internal and vendor authentication.
  • Knowledge of Privilege Management and Muti factor Authentication (MFA) tools. Knowledge and support of Azure AD groups
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead IAM Security Engineer- Saviynt IGA
Lead IAM Security Engineer- Saviynt IGA

Strategic Staffing Solutions • Lutz (FL)

On-site
USD 125,000 - 180,000
Senior IAM Engineer
Senior IAM Engineer

Total Quality Logistics • Cincinnati (OH)

Hybrid
USD 120,000 - 180,000
Hybrid work model
Relocation assistance
Health, dental, vision
Sr Identity and Access Management Analyst
Sr Identity and Access Management Analyst

Chicago Bridge & Iron Company • The Woodlands (TX)

On-site
USD 100,000 - 130,000
IAM Engineer
IAM Engineer

Gravity IT Resources • Cincinnati (OH)

On-site
USD 130,000 - 170,000
IAM Engineer-
IAM Engineer-

Associates Systems LLC • Irving (TX)

On-site
USD 120,000 - 160,000
Sr Identity and Access Management Analyst
Sr Identity and Access Management Analyst

CB&I • The Woodlands (TX)

On-site
USD 120,000 - 160,000
IGA Lead
IGA Lead

Securdi LLP. • United States

Hybrid
USD 120,000 - 150,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000
Sr. Security Engineer
Sr. Security Engineer

SherlockTalent • Orlando (FL), Fort Lauderdale (FL)

On-site
USD 90,000 - 150,000
Sr IAM Developers - US Location
Sr IAM Developers - US Location

Bridgesoftsol • United States

On-site
USD 100,000 - 130,000