网络安全、IGA 高级工程师 - 远程
Principal Engineer, Cybersecurity, IGA - Remote
工作灵活性:远程办公
优先考虑居住在东部或中部时区的候选人。
作为IGA首席工程师,您将构建和运营企业身份治理、认证和授权服务,以保护组织内的访问权限。您将与高级业务、应用和基础设施利益相关者合作,将需求转化为可扩展的身份架构、标准和控制措施。
您将负责的工作
技术职责:
- 构建、配置和运营企业IGA平台,包括SailPoint、Saviynt或Microsoft Entra ID Governance,以及支持的目录和认证服务。
- 设计入职者、调动者和离职者的身份生命周期工作流,包括自动化供应和撤销。
- 实施并维护访问请求、审批工作流、访问认证和再认证活动、RBAC模型、角色挖掘和职责分离规则。
- 配置权威源、身份对齐和身份数据质量修复。
- 使用SAML、OAuth、OpenID Connect和SCIM实现SSO、MFA、联合和基于风险的认证。
- 开发PowerShell、Microsoft Graph、REST API和SCIM自动化和集成,将应用程序接入IGA服务。
- 生成身份报告、集成治理和访问相关控制的审计证据。
- 排查IGA、供应和目录问题;维护文档;执行支持SOX、HIPAA、ISO 27001和NIST CSF合规性的IAM控制措施。
知识和能力:
- 从高级业务、应用和基础设施利益相关者处收集需求,并提供范围和架构咨询。
- 与高级利益相关者定义、沟通并嵌入企业身份治理标准、模式和控制措施。
- 分析复杂的身份问题,清晰地传达技术概念,并保持精确的配置和治理实践。
您需要具备的条件
必备资格
- 计算机科学、网络安全、信息系统、工程或相关领域的学士学位,或同等的实际经验。
- 至少8年IT或网络安全工作经验。
- 至少5年实际操作和管理IGA或IAM环境的经验。
- 具有SailPoint、Saviynt或Microsoft Entra ID Governance的经验,以及Active Directory和Microsoft Entra ID的经验。
查看英文原文
Work Flexibility: Remote
Preference will be given to candidates residing in the Eastern or Central time zones.
As an IGA Principal Engineer, you will build and operate enterprise identity governance, authentication, and authorization services that protect access across the organization. You will partner with senior business, application, and infrastructure stakeholders to translate requirements into scalable identity architecture, standards, and controls.
WHAT YOU WILL DO
Technical Responsibilities:
- Build, configure, and operate enterprise IGA platforms, including SailPoint, Saviynt, or Microsoft Entra ID Governance, with supporting directory and authentication services.
- Engineer identity lifecycle workflows for joiners, movers, and leavers, including automated provisioning and deprovisioning.
- Implement and maintain access requests, approval workflows, access certification and recertification campaigns, RBAC models, role mining, and segregation-of-duties rules.
- Configure authoritative sources, identity reconciliation, and identity data quality remediation.
- Implement SSO, MFA, federation, and risk-based authentication using SAML, OAuth, OpenID Connect, and SCIM.
- Develop PowerShell, Microsoft Graph, REST API, and SCIM automations and integrations to onboard applications to IGA services.
- Produce identity reporting, integration governance, and audit evidence for access-related controls.
- Troubleshoot IGA, provisioning, and directory issues; maintain documentation; and execute IAM controls supporting SOX, HIPAA, ISO 27001, and NIST CSF compliance.
Knowledge and Capabilities:
- Gather requirements from senior business, application, and infrastructure stakeholders and provide scope and architecture consultation.
- Define, communicate, and embed enterprise identity governance standards, patterns, and controls with senior stakeholders.
- Analyze complex identity issues, communicate technical concepts clearly, and maintain precise configuration and governance practices.
WHAT YOU NEED
Required Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related discipline, or equivalent practical experience.
- Minimum 8 years of experience in IT or cybersecurity.
- Minimum 5 years of hands-on experience engineering and operating IGA or IAM environments.
- Experience with SailPoint, Saviynt, or Microsoft Entra ID Governance, plus Active Directory and Microsoft Entra ID.
- Experience with identity lifecycle management, provisioning and deprovisioning, access certification, RBAC, and segregation-of-duties enforcement.
- Working knowledge of SAML, OAuth, OpenID Connect, and SCIM.
- Experience with PowerShell, Microsoft Graph, or REST APIs.
Preferred Qualifications
- SailPoint IdentityIQ or IdentityNow Engineer, Saviynt, Microsoft Certified: Identity and Access Administrator Associate (SC-300), or CISSP certification.
United States of America Pay Ranges:
- USN: $135,600 - $225,900 USD Annual
- US5: $142,400 - $237,200 USD Annual
- US10: $149,200 - $248,500 USD Annual
- US15: $155,900 - $259,800 USD Annual
- US20: $162,700 - $271,100 USD Annual
- US30: $176,300 - $293,700 USD Annual
View the U.S. work location and transparency guide to find the pay range for your location.
Travel Percentage: NoneStryker Corporation is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, gender identity, sexual orientation, national origin, disability, or protected veteran status. Stryker is an EO employer – M/F/Veteran/Disability.Stryker Corporation will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information.Originally posted on Himalayas