> Markdown version of [/jobs/ext/1282494-identity-and-access-management-iam-analyst-portsmouth-nh](https://www.wearedevelopers.com/jobs/ext/1282494-identity-and-access-management-iam-analyst-portsmouth-nh). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity and Access Management (IAM) Analyst - Portsmouth, NH - **Company:** Service Credit Union - **Location:** Portsmouth, NH, United States - **Salary:** $70,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Word, Microsoft Excel, Microsoft Windows, Active Directory, User Authentication, Microsoft Outlook, Cloud Computing, Cyber Security, Relational Databases, Multi-Factor Authentication, Hardware Security Module, Identity and Access Management, Information Technology Operations, Lightweight Directory Access Protocols (LDAP), Microsoft SQL Server, MySQL, OAuth, OpenID, Oracle (Applications), Password Management, Microsoft PowerPoint, Role-Based Access Control, Azure Active Directory, Phishing, Security Assertion Markup Language (SAML), Single Sign-On, Software Engineering, Web Applications, Information Technology, SailPoint - **Published:** July 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d4c348426036bfc0 ## About the Role · Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or equivalent relevant work experience. · Minimum 3+ years of hands-on experience in Identity and Access Management, with demonstrated exposure to an enterprise IGA platform (SailPoint preferred) and at least 1+ year supporting modern authentication technologies (MFA, SSO, or passwordless). · SailPoint IdentityNow / IdentityIQ Engineer or Administrator; Microsoft SC-300 (Identity and Access Administrator); CISSP, CISM, CRISC, or CISA. Or ability to acquire in first year of hire. · Experience in a financial services, credit union, or other regulated environment is a plus. · Working knowledge of identity governance concepts including lifecycle management, application on-boarding, access request, automated provisioning, password management, and role-based access control (RBAC). · Hands-on experience with SailPoint IdentityIQ or Identity Security Cloud (workflows, rules, certifications, connectors) is strongly preferred. · Working knowledge of passwordless / phishing-resistant authentication technologies: FIDO2, WebAuthn, passkeys, platform authenticators, and hardware security keys. · Demonstrated experience administering Active Directory and Microsoft 365 / Entra ID environments. · Familiarity with authentication and federation protocols: SAML, OAuth 2.0, OIDC, SCIM, LDAP. · Knowledge of MFA platforms (e.g., Duo, Entra MFA) and PAM concepts. · Familiarity with enterprise directories and relational databases (MSSQL, Oracle, MySQL). · Strong analytical, organizational, and documentation skills; attention to detail. · Excellent interpersonal, presentation, and written/verbal communication skills, able to translate technical concepts for business audiences. · Proficient with Microsoft Excel, Outlook, Word, PowerPoint, and web-based administrative consoles. · Ability to foster productive working relationships with internal staff, vendors, and cross-functional partners. ## Description Service Credit Union is seeking an Identity and Access Management (IAM) Analyst who will serve as a guardian of employee and member-facing identity, safeguarding critical and confidential information belonging to Service Credit Union. This is a hybrid identity role with two anchor accountabilities: 1. Co-administration of the SailPoint IdentityIQ platform, including identity lifecycle management, role-based access control (RBAC), access certifications, and automated provisioning across enterprise systems. 2. Business and technical liaison for the Passwordless Authentication platform, supporting rollout, day-to-day operations, user enrollment, exception handling, integration with SSO/MFA, and continuous improvement of the passwordless user experience. The IAM Analyst also supports adjacent identity functions, including Multi-Factor Authentication (MFA), Single Sign-On (SSO), Privileged Access Management (PAM), and directory services, ensuring access is granted, modified, and removed in accordance with policy, approvals, and the principle of least privilege. The role works closely with Information Security, Infrastructure, Application Development, HR, and business units to deliver secure, compliant, and frictionless identity experiences. "Members are the priority at Service Credit Union, and every role at the credit union is responsible for supporting member solutions and contributing positively to the member experience.", · Co-administer the SailPoint platform in partnership with the IAM Administrator and Engineering team, including configuration of lifecycle events, application onboarding, access request workflows, and certification campaigns. · Execute and refine the RBAC model, reconciling discrepancies between assigned access rights and the access required for users to perform their job duties. · Support access provisioning, de-provisioning, transfers, and offboarding events in alignment with established policies, standards, and procedures. · Design, schedule, and monitor periodic access certification and Segregation of Duties (SoD) reviews, tracking remediation to closure. · Maintain accurate documentation for SailPoint configurations, role models, connectors, and operational procedures. Passwordless Authentication Platform Liaison & Support · Act as the primary business liaison and Tier 2 support owner for the Passwordless Authentication platform, coordinating between the vendor, Information Security, IT Operations, and end users. · Manage user enrollment, credential lifecycle (registration, recovery, revocation), device binding, and exception handling for passwordless authenticators (FIDO2 / passkeys / platform authenticators). · Partner with Engineering to integrate passwordless authentication with SSO, conditional access, and downstream applications; validate authentication flows and fallback paths. · Monitor platform health, authentication success/failure metrics, and user adoption; produce reports and recommend improvements to increase adoption and reduce friction. · Develop end-user communications, FAQs, knowledge articles, and training materials to support the ongoing rollout and steady-state operation of passwordless authentication. · Serve as subject matter resource for phishing-resistant authentication concepts and align platform practices with NIST 800-63 guidance and emerging industry standards. Broader Identity & Access Functions · Support the enrollment and administration of Multi-Factor Authentication (MFA), Single Sign-On (SSO), Privileged Access Management (PAM), and Mobile Device Management (MDM) integrations. · Administer Active Directory, Entra ID (Azure AD), and related enterprise directory services in support of identity lifecycle events. · Enforce organizational policies and procedures to ensure only authorized personnel have access to information, in compliance with the Minimum Necessary Rule and least-privilege principles. · Ensure evidence of authorization is documented and archived according to internal standards, and support audit, examiner, and risk-assessment requests. · Troubleshoot identity, authentication, and workflow issues independently or in collaboration with other IS teams, adhering to internal service standards and SLAs. · Recommend and implement process improvements, automation, and orchestration of repeatable IAM tasks. · Participate in projects to implement new IAM integrations, provisioning points, and RBAC extensions. · Support incident research, evidence gathering for audits, and remediation of identity-related risks. · Regular and reliable attendance is an essential function of this position. · Other duties as assigned. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [No More Post-its: Boost your login security with APIs](https://www.wearedevelopers.com/videos/1043-no-more-post-its-boost-your-login-security-with-apis) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [The top 200 passwords of 2024 can be cracked in less than a second](https://www.wearedevelopers.com/magazine/502-the-top-200-passwords-of-2024-can-be-cracked-in-less-than-a-second) - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 156: Enterprise dead, all about Bluesky and <img> CC theft!](https://www.wearedevelopers.com/magazine/552-dev-digest-156-enterprise-dead-all-about-bluesky-and-img-cc-theft)