Summary
Clientis seeking a senior IT Security/IAM professional who can act as the primarysecurity SME for the Child Support Services department. The key focus is deepexpertise in Active Directory, Microsoft Entra ID, Okta, IAM integrations,RBAC, SSO, MFA, and enterprise identity security across on-prem and cloudenvironments. They also need someone experienced in security operations,SIEM, risk assessments, compliance frameworks (NIST/ISO/CIS), andsecurity-related projects. Strong leadership, technical mentoring,communication, and ideally public-sector/HHS or modernization experienceare important.
Here are some of the specific details
JobTitle: Senior Information Security Analyst / IAM Administrator
Location: Frankfort,KY (Remote)
Duration: Long-termIndefinite Contract
Job Description
We are seeking an experienced Information Security Analyst andAdministrator to support the Department of Child Support Services’ securityrelated technologies, processes, and implementations. This position will serveas the primary IT Security subject matter expert especially with the deploymentof a new Identity Access Management solution and case management system. Theideal candidate will have demonstrated experience serving in both project andIT operation capacities within the security domain. They will haveknowledge and experience with both on-premises and cloud environmentsespecially within OKTA, Azure platform, and Active Directory. Candidates mustpossess strong communication and organization skills, and a deep understandingof Identity and Access Management solutions. This position will work closelywith the OIS, COT, and other technical team stakeholders.
Duties and Responsibilities
- Server as primary ITSecurity Subject Matter Expert (SME) for the Department of Child SupportServices.
- Manage userauthentication, authorization, and access control policies to preventunauthorized access.
- Support the designand build of role-based access control security frameworks for the department,
- Performvulnerability scans, penetration tests, and risk assessments to identify andmitigate threats.
- Monitor securityalerts, investigate breaches, and respond to incidents promptly.
- Develop, enforce,and update security policies; ensure compliance with legal and regulatoryrequirements.
- Educate staff onsecurity best practices and protocols.
- Support the creationand maintenance of business continuity and disaster recovery plans.
- Administer identityand access management (IAM) systems including OKTA, Active Directory, Azure AD,and privileged access workstations.
- Monitor SIEMplatforms (Splunk, Microsoft Sentinel, QRadar) for security events, tune alertrules, and escalated confirmed incidents
- Implement andenforce multi-factor authentication, certificate management, and single sign-onconfigurations across enterprise applications.
- Develop and maintainsecurity policies, standards, and procedures aligned with NIST CSF, ISO 27001,or CIS Controls frameworks.
- Support securityaudits and compliance assessments for SOC 2, HIPAA, PCI-DSS, or FedRAMP by gathering evidence and remediating findings
- Perform securityreviews on new systems, applications, and vendors as part of the changemanagement and third-party risk process.
- Investigate phishingincidents, malware infections, and unauthorized access events; documentfindings and implement corrective controls.
- Identify andmitigate security replated project risks, issues, and dependencies, and developcontingency plans to ensure project success.
MUST-HAVE Requirements (non-negotiable)
- Deep technicalexpertise in Microsoft Active Directory and Microsoft Entra ID.
- Experience designingand implementing IAM integrations, provisioning workflows, and access controls.
- Proven experienceimplementation & maintaining role based access control frameworks.
- Proven ability tolead and mentor technical engineering teams.
- Strong understandingof identity security principles and enterprise authentication models.
- Previous experiencewith NIST CSF, ISO 27001, or CIS Controls frameworks.
- Bachelor's degree,preferably in Computer Science, Information Technology, Computer Engineering,or related IT discipline; or equivalent experience
Preferred Qualifications
- Strong understandingof identity security principles and enterprise authentication models. (SAML,OIDC, SCIM) and access control models like Fine-Grained Authorization (FGA)
- Public sector childsupport/HHS; modernization programs.
- Firewalls andnetwork security: Palo Alto Networks, Fortinet FortiGate, Cisco ASA/FTD — rulewriting, NAT, VPN configuration.
- SIEM: Splunk (SPLqueries), Microsoft Sentinel (KQL), IBM QRadar — correlation rule tuning,dashboard creation.
- Endpoint security:CrowdStrike Falcon, Microsoft Defender for Endpoint, Carbon Black — alerttriage, isolation, policy management.
- IAM: ActiveDirectory, Azure Active Directory, Okta, CyberArk for PAM.
- Scripting:PowerShell and Python for automation of repetitive security tasks (log parsing,alert enrichment, AD queries)
- Experience withServiceNow and integration with prevalent identity access management platforms.
Tools and Platforms
- ServiceNow, ActiveDirectory, Okta, Ping Identity, Azure AD, Cisco ASA, Fortinet FortiGate, PaloAlto PA OS, Check Point, FortiGate, Splunk, IBM QRadar, Microsoft Sentinel,eSet, Proofpoint Nessus, Qualys, NDiscovery, OpenVAS, ISO 27001 compliancechecklists, CJIS compliance tools, SSAE 16 audit frameworks, NIST & FedRamp frameworks.
Certifications
- CISSP – CertifiedInformation Systems Security Professional
- CompTIA Security+
- Microsoft AzureSecurity Engineer Associate (AZ-500)
- Microsoft AppliedSkills: Administer Active Directory Domain Services
About us
HarveyNash is a national, full-service talent management firm specializing intechnology positions. Our company was founded with a mission to serve as thetalent partner of choice for the information technology industry.
Ourcompany vision has led us to incredible growth and success in a relativelyshort period of time and continues to guide us today. We are committed tooperating with the highest possible standards of honesty, integrity, and apassionate commitment to our clients, consultants, and employees.
Weare part of Nash Squared Group, a global professional services organizationwith over forty offices worldwide.
Formore information, please visit us at https://www.harveynashusa.com/