
Identity and Access Management (IAM) Analyst
- Hoover, AL
- Permanent
- Full-time
- Analyze and respond to cyber threats within various security tools according to documented procedures
- Collaborates with various stakeholders within Cyber Security/Technology departments and standard owners to properly document and communicate security risks
- Proactively supports a feedback loop related to information and events in order to identify and support the remediation of improving precision and accuracy of analysis
- Review and understand Policies, Standards, and Procedures for improved process flows.
- Performs threat hunting, participate in tabletop exercises, and assist in Incident Response on a rotational job-duty basis as needed
- Maintains meticulous records of all work performed, including root cause analysis, indicators of compromise, remediation steps, timeline of events, and impact assessment using clear and concise annotations as needed
- Stays abreast of global cybersecurity threat trends
- Supports and collaborates with various cybersecurity teams to document security posture and assess environment for relevant IOCs and gaps
- Participates in and ensures proper documentation of various security assessments (i.e. Security Architecture Reviews, Red Team assessments, Purple Team engagements, and formal tabletop exercises) as needed
- Analyzes software for violations in Regions Cyber Security standards as needed
- Acts as a coach and mentor to junior analysts
- May lead special projects
- High School Diploma or GED and (8) years of related post-secondary education and/or experience in Information Security or Information Technology
- Minimum of two (2) relevant certification in Information Security or the ability to obtain relevant certification within twelve months of start date in this position, such as CompTIA Network+/Security+/CySA+, EC-Council Certified Ethical Hacker (CEH), Cisco CCNA/CCNA-Security, GIAC GSEC, etc.
- Willingness and availability to work on a pre-determined shift and rotational on call
- Minimum of one (1) Intermediate to Advanced Amazon Web Services (AWS) or Azure Architect/Administrator and/or Security specialty certification
- Advanced Incident Response, Cyber Leadership, Penetration Testing certification – GCIH, GSOM, GPEN, CISSP, CISM, OSCP
- Prior working experience in a Security Operations Center (SOC) environment
- Prior experience developing use cases for a Security Operations Center (SOC) from threat hunting and threat detection engineering to investigation playbook and response procedure development
- Understanding of MITRE ATT&CK Framework and Cyberattack Kill Chain and how these frameworks can be used to identify gaps as well as orient analysts in attack progression
- Ability to be a self-starter with initiative and drive for continuous improvement.
- Ability to be a team-oriented individual who works well with others and places a premium on the group’s success
- Advanced understanding of information security principles, controls, and technologies
- Demonstrated strong organizational, research, analytical and problem-solving skills to evaluate situations and respond appropriately
- Excellent writing and verbal communication skills
- Strong familiarity with concepts related to security disciplines such as: malware analysis, computer forensics, cyber incident response, network intrusion detection, network traffic and packet analysis, penetration testing, vulnerability scanning, compliance, audit, or cyber threat intelligence.
- Strong investigative and problem-solving skills
- Partner with other business and IT organizations within Regions to gather requirements for application onboarding to Sailpoint IIQ
- Coordinate and assist with leading meetings to gather requirements
- Create and maintain onboarding and provisioning documentation
- Perform analysis for role-based access controls (RBAC) and define/modify roles in Sailpoint
- Troubleshoot connection failures for applications defined in Sailpoint
- Troubleshoot access provisioning failures and determine root cause
- Coordinate with other IGA team members to ensure timelines are met
- May serve as an SME and provides support for IGA solution
- Sailpoint IIQ or Sailpoint Identity Security Cloud experience
- Experience with role-based access controls and configuring automated provisioning and deprovisioning in Sailpoint
- Experience with ServiceNow
- Experience with JIRA
- Experience with Structured Query Language (SQL)
- Paid Vacation/Sick Time
- 401K with Company Match
- Medical, Dental and Vision Benefits
- Disability Benefits
- Health Savings Account
- Flexible Spending Account
- Life Insurance
- Parental Leave
- Employee Assistance Program
- Associate Volunteer Program