Leeds, Yorkshire
Masento
OVERVIEW:
A skilled Identity and Access Management (IAM) Specialist to join the CPS Programme. Ideal candidate will have expertise in implementing SailPoint Access Risk Management (ARM) and IdentityNow (IdN), as well as proficiency in Privileged Access Management (PAM) technologies specifically where those applications intersect and provision to SAP S4, SuccessFactors, Ariba and Concur.
This role will involve configuring ARM and IdN based on designs specified by the technical lead and client stakeholders, providing advice on best practice in both applications maintaining the overall IAM solution to ensure secure and efficient access to the client’s resources.
The role will be supported by a technical lead, a Security and IAM focused PM, and a competency within the client who already maintain some elements of the Identity solution. Finally, SAP development/interface and Basis teams.
RESPONSIBILITIES:
Implementation of SailPoint IdentityNow (IdN):
1.Technically implement and configure SailPoint IdN solution to manage user access and streamline identity governance processes including:
a)User creation via synchronisation via SuccessFactors
b)Authentication via Azure AD and MFA via DUO
c)Automation of user provisioning and de-provisioning.
2.Understanding of best practice when enforcing role-based access controls (RBAC).
3.An understanding of the elements required to enable single sign-on (SSO) via SAML and technologies like SAP Principal propagation.
4.Working with the project to provide auditing and compliance capabilities for user access.
5.Customising workflows, policies, and rules within SailPoint to align with organisational requirements.
6.Integrating SailPoint solutions with existing client systems and applications to facilitate seamless access management (and those for whom out-of-the-box integrations do not exist such as Ariba).
Implementation of SailPoint ARM:
1.Technically implement and configure SailPoint ARM solution to manage user access risk analysis and reporting.
2.Understanding of how Rulesets are developed and managed.
3.Expertise in managing non-SAP ABAP system conflicts (non-transactional systems)
4.The candidate will have:
a.Expertise in Compliance and Governance: The candidate should have a strong understanding of compliance standards and governance frameworks related to segregation of duties, such as Sarbanes
-Oxley (SOX), GDPR, or industry-specific regulations.
b.Understanding of Risk Management: An understanding of risk management principles is crucial for assessing the impact of potential access conflicts and designing effective mitigation strategies.
c.Analytical Skills: Strong analytical skills are necessary for analysing access permissions, identifying SoD conflicts, and developing risk mitigation plans tailored to the client’s needs.
Privileged Access Management (PAM) Integration:
1.Collaborate with stakeholders to identify privileged accounts and define access controls and workflows for privileged users.
2.Implement PAM technologies to secure, monitor, and manage privileged access to critical systems and data.
3.Integrate PAM solutions with IAM platforms to enforce consistent access policies across the client.
Collaboration and Stakeholder Engagement:
5.Work closely with cross-functional teams, including IT operations, security, and compliance, to ensure alignment of IAM initiatives with business objectives.
6.Collaborate with application owners and system administrators to onboard applications and systems into IAM platforms.
7.Communicate effectively with stakeholders to gather requirements, provide updates, and address concerns related to IAM projects.
REQUIREMENTS:
Proven experience implementing SailPoint ARM and IdentityNow (IdN) solutions in enterprise environments. Ensuring IAM program enhances security, compliance, and efficiency in the SAP S/4HANA deployment by managing user identities and controlling access to resources.
Strong understanding of identity and access management principles, including authentication, authorisation, and identity life cycle management.
Familiarity with Privileged Access Management (PAM) technologies such as SAP FireFighter, CyberArk, BeyondTrust, or Thycotic.
Experience with LDAP, Active Directory, and other directory services.
Excellent communication and interpersonal skills, with the ability to collaborate effectively with technical and non-technical stakeholders.
Strong problem-solving skills and the ability to troubleshoot complex IAM issues.
Relevant certifications such as CISSP, CISM, or SailPoint IdentityIQ certification are a plus.
