Security Analyst I - Identity & Access Management (IAM) & Compliance

Aqua America
Bryn Mawr, United States of America
9 days ago

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Junior

Job location

Bryn Mawr, United States of America

Tech stack

Computer Security
Identity and Access Management
Information Technology Audit
Information Technology Operations
Data Logging
Information Technology
Operational Systems
CIS Benchmarks

Job description

The Security Analyst I - Identity & Access Management (IAM) & Compliance is a hands-on cybersecurity role primarily responsible for supporting the operation and governance of enterprise IAM controls, with additional involvement in compliance monitoring and control execution. This position assists with access governance activities, audit support, and identity-related compliance processes across both Information Technology (IT) and Operational Technology (OT) environments. The role collaborates with IT, OT Engineering, and Application Owners to help ensure access and change controls are secure, compliant, and auditable., * Participates as a member of the Information Security Governance, Risk, and Compliance (GRC) team with primary focus on Identity & Access Management and access governance.

  • Assists in the administration and operation of IAM and access-related audit and governance toolsets, including access certifications, provisioning validation, privileged access reporting, and identity governance workflows.
  • Execute and document periodic access reviews, role validations, and privileged access attestations for enterprise systems under guidance.
  • Support the enforcement of least-privilege and role-based access models across on-premises, cloud, and OT environments.
  • Monitor IAM control effectiveness, track exceptions, and coordinate remediation of access control gaps with system and application owners.
  • Support IAM-related audit activities by collecting evidence, responding to auditor requests, and documenting control procedures.
  • Assist in maintaining and improving IAM processes, tooling, and reporting related to joiner, mover, and leaver (JML) lifecycle management.
  • Maintain documentation, metrics, and dashboards that communicate access risk posture, trends, and remediation status to Information Security leadership.
  • Support the administration and operation of the File Integrity Monitoring (FIM) solution, including alert review, tuning, and validation of authorized changes.
  • Assist in compliance processes related to user access controls, including JML validation and privileged access oversight.
  • Support compliance activities related to Sarbanes-Oxley (SOX) application and system change management controls.
  • Assist with investigating unauthorized or unapproved changes identified through FIM or audit activities.
  • Help maintain audit-ready control documentation, evidence repositories, and process descriptions supporting SOX, internal audit, and regulatory reviews.
  • Participate in efforts to improve compliance processes tied to access management and system change controls.
  • Collaborate with Information Security, IT Operations, Application Owners, and Internal Audit for access and compliance matters.
  • Contribute to the review of policies, standards, and procedures related to access control and compliance monitoring.
  • Participate in risk assessments and control testing activities related to IAM and compliance domains.
  • Support IAM and compliance activity within OT environments, learning the unique requirements of industrial control and supervisory systems.
  • Assist with access governance and monitoring for OT systems in coordination with OT Engineering teams.

Requirements

  • Bachelor's degree in Information Security, Information Technology, Computer Science, or a related field, or equivalent experience.
  • 0-2 years of experience in cybersecurity, Identity & Access Management, compliance, or risk-related roles (including internships or academic experience).
  • Familiarity with IAM concepts, access control processes, or audit/compliance activities.
  • Exposure to or familiarity with security or compliance tools (e.g., IAM platforms, logging tools, or monitoring solutions).
  • Foundational understanding of cybersecurity frameworks or standards (e.g., NIST CSF, SOX ITGCs, CIS Controls).
  • Strong attention to detail, documentation skills, and willingness to learn.
  • Effective communication and collaboration skills., * Internship or academic experience supporting IAM, IT audit, or compliance-related activities.
  • Familiarity with identity governance, privileged access management (PAM), and change management controls.
  • Exposure to Operational Technology or industrial environments preferred but not required.
  • Entry-level security certifications (e.g., Security+, ISC2 CC, or similar).

About the company

Essential Utilities, Inc. delivers safe, clean, reliable services that improve quality of life for individuals, families, and entire communities. Operating as the Aqua (water and wastewater services) and the Peoples and Delta (natural gas) brands, Essential serves approximately 5.5 million people across 10 states. We are committed to sustainable growth, operational excellence, a superior customer experience, and premier employer status - including a competitive and comprehensive benefits package as well as a commitment to career growth opportunities. We are advocates for the communities we serve and are dedicated stewards of natural lands, protecting more than 7,600 acres of forests and other habitats throughout our footprint. Our company is one of the most significant publicly traded water, wastewater service and natural gas providers in the U.S.

Apply for this position