UAM Consultant
· Delivery of Native Identity & Access Management Tooling and automation, providing identity and access management capability which serves our customers need, while aligning to our control obligations. Key native capabilities include:
· Build and maintenance of automated devops / CICD pipelines
· Code curation using terraform (GCP) and powershell (azure)
· Building the processes and controls associated with native identity and access management processes:
· User access management
· Identity & access monitoring and alerting
· Value Stream and Workstream onboarding
· Service account lifecycle management
· Integrating Public Cloud with LBG’s incumbent Identity tooling (Oracle Identity Manager), as well as migration to new tooling when available (Sailpoint, PING Identity), delivering integration into enterprise Identity & Access Management controls:
· Joiners, Movers, Leavers
· Recertification
· Identity Federation and Identity Provider design
· Delivery of new SaaS products (Saviynt) and integration into public cloud to deliver improved Privileged Access Management controls and colleague experience.
What’s needed to be considered for this job?
Our engineering function is split in two (Google Cloud and Azure) however there are opportunities for cross skilling across cloud platforms. The
· Understanding of Public Cloud platforms, including CICD pipeline technologies
· Ability to code and build automation, experience in a language such as Python, Powershell, Java\Groovy
· Proven track record of delivering technical solutions and automation of solutions at scale
· Proactively seeks out opportunities and implements service improvements whilst building customer satisfaction
· Understanding of the bank’s control environments and the role of compliance and security as part of technology design and implementation.
Desirable:
· Experience working in an Identity & Access Management or IT Security function and relevant Security qualifications (CISA, CISM, CISMP, CISSP)
· Experience and understanding of Microsoft Azure, Google Cloud (GCP) or AWS including security and identity capabilities and tools.
· Experience working in agile sprints, understanding of Atlassian product suite (Jira and Confluence) for collaboration
· Capability to identify technical risks, articulate the associated IT costs and business impacts, and propose options for resolution
· Ability to operate and influence in a complex, large scale and diverse environment
· Highly articulate with good verbal and written communication, Experience with data querying and analysis using languages such as SQL and KQL
· Experience with Privileged Access Management methodology and technical solutions such as CyberArk, Azure PIM, Saviyant, BeyondTrust