Identity Security Analyst

IDM Group, LLC
Los Angeles, CA, United States
17 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$135,200.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Microsoft Windows Access Network Active Directory Application Programming Interfaces (APIs) Amazon Web Services Audit Trail User Authentication Microsoft Azure Backup Devices Software as a Service CompTIA Security+
+26 more
Databases Data Recovery Dynamic Host Configuration Protocol Domain Name System (DNS) Multi-Factor Authentication Identity and Access Management Python (Programming Language) Network Security Lightweight Directory Access Protocols (LDAP) Network Architecture OAuth OpenID Windows PowerShell Role-Based Access Control Cloud Services Security Assertion Markup Language (SAML) Single Sign-On Systems Integration User Provisioning Software Virtual Machines Backup and Restore Transport Layer Security Enterprise Software Applications Okta Cloud Connectors Firewall Services Module

Job description

Schedule: Monday through Friday; hybrid schedule with three days onsite and two days remote, subject to management approval and operational requirements, We are seeking an experienced Identity Security Analyst to provide hands-on administration, maintenance, troubleshooting, monitoring, and operational support for enterprise identity, security, network infrastructure, and backup platforms.

The selected candidate will support Okta identity and access management, Zscaler Internet Access and Private Access, Infoblox DNS, DHCP and IPAM, and enterprise backup and recovery technologies. This position requires a technically strong and detail-oriented professional who can resolve production issues, implement configuration changes, support audits and access reviews, prepare operational reports, and maintain accurate technical documentation.

This is not a governance-only, compliance-only, or SOC-monitoring position. The selected candidate must have direct, hands-on experience administering enterprise technology platforms.

Key ResponsibilitiesOkta Identity and Access Management

  • Administer Okta users, groups, applications, policies, and integrations.
  • Support single sign-on, multi-factor authentication, lifecycle management, and user provisioning.
  • Troubleshoot SSO, MFA, authentication, provisioning, and directory synchronization issues.
  • Review Okta system logs to investigate failed logins, policy denials, access problems, and user activity.
  • Support integrations with Active Directory, Microsoft 365, SaaS applications, and other enterprise systems.
  • Maintain sign-on, MFA, application-access, and device-trust policies.
  • Support account lifecycle events, user deactivation, access reviews, and group-membership validation.
  • Assist with security assessments, audits, and identity-related reporting.
  • Maintain Okta configuration documents, procedures, and troubleshooting guides.

Zscaler Administration

  • Administer Zscaler Internet Access and Zscaler Private Access policies and configurations.
  • Manage application segments, forwarding rules, access controls, and user or group assignments.
  • Troubleshoot issues involving ZIA, ZPA, PAC files, tunnels, App Connectors, Cloud Connectors, and Client Connector.
  • Review logs and analytics to investigate blocked traffic, denied access, policy enforcement, and application-access failures.
  • Support SSL inspection, URL filtering, cloud firewall rules, security policies, and approved exceptions.
  • Maintain PAC files and forwarding profiles.
  • Support Client Connector deployment, upgrades, and end-user troubleshooting.
  • Monitor Zscaler service health, connector status, and policy effectiveness.
  • Maintain operational procedures and Zscaler troubleshooting runbooks.

Infoblox DNS, DHCP and IPAM

  • Administer Infoblox DNS, DHCP, IPAM, Grid, and DNS-view configurations.
  • Create, modify, and remove DNS records, DHCP scopes, reservations, fixed addresses, and IPAM objects.
  • Support DNS zones, forwarders, views, name servers, and delegated domains.
  • Troubleshoot DNS resolution, DHCP leases, Grid replication, synchronization, and service-availability issues.
  • Monitor Grid health, replication status, system alerts, and member availability.
  • Support Infoblox upgrades, hotfixes, system backups, and configuration validation.
  • Manage role-based access controls for DNS, DHCP, and IPAM administration.
  • Review audit logs and administrative activity.
  • Assist with cloud-hosted Infoblox appliances in Microsoft Azure or AWS, where applicable.

Enterprise Backup and Recovery

  • Administer backup policies, schedules, retention rules, and backup plans.
  • Monitor daily backup jobs, warnings, failures, and success rates.
  • Investigate and resolve failed or incomplete backup jobs.
  • Perform file-level, server-level, application-level, and database recovery.
  • Support backups for virtual machines, physical servers, databases, file shares, and cloud workloads.
  • Validate backup coverage for business-critical systems.
  • Install, upgrade, configure, and remove backup agents.
  • Support disaster-recovery testing and recovery-readiness activities.
  • Prepare backup compliance, capacity, health, and operational reports.
  • Maintain backup procedures, configurations, escalation instructions, and recovery documentation.

Operational and Documentation Responsibilities

  • Investigate incidents and provide timely technical resolution.
  • Prepare incident, problem, and root-cause summaries.
  • Document configuration changes, implementation procedures, validation results, and rollback plans.
  • Prepare weekly or monthly operational status reports.
  • Maintain technical standards, operating procedures, and system runbooks.
  • Support access reviews, security audits, and evidence requests.
  • Coordinate with application, server, storage, network, cloud, and cybersecurity teams.
  • Identify recurring problems and recommend operational or security improvements.
  • Follow established incident, problem, change-management, and escalation procedures.

Requirements

  • Five or more years of experience in identity and access management, cybersecurity engineering, enterprise infrastructure administration, network security, or a related technical field.
  • Three or more years of recent hands-on experience administering enterprise security or infrastructure platforms in a production environment.
  • Direct production-administration experience with at least three of the following:
  • Okta
  • Zscaler ZIA and ZPA
  • Infoblox DNS, DHCP, and IPAM
  • Enterprise backup and recovery platforms
  • Ability to support and develop proficiency across all four technology areas.
  • Strong understanding of identity concepts and protocols, including SSO, MFA, SAML, OIDC, OAuth, SCIM, LDAP, Active Directory, and role-based access control.
  • Experience troubleshooting authentication, network access, DNS, DHCP, provisioning, directory-synchronization, and backup failures.
  • Experience reviewing system logs and translating findings into corrective actions.
  • Experience supporting production incidents and controlled configuration changes.
  • Strong technical documentation and report-writing skills.
  • Ability to communicate effectively with technical teams, management, vendors, and business stakeholders.
  • Ability to work onsite in Los Angeles County three days per week and accommodate operational schedules established by management.

Preferred Qualifications

  • Hands-on administration experience with all four required technology areas.
  • Okta Certified Administrator or Okta Certified Consultant.
  • Current Zscaler administrator or engineer certification or formal training.
  • Infoblox DDI certification, accreditation, or equivalent hands-on experience.
  • Certification for the applicable enterprise backup platform.
  • CompTIA Security+, SSCP, CISSP, CISM, or a comparable cybersecurity certification.
  • Experience with Microsoft Azure, AWS, Microsoft 365, and Active Directory.
  • Experience supporting large, highly available, regulated, government, or enterprise environments.
  • Experience using PowerShell, Python, APIs, or other automation tools for administration and reporting.
  • Experience preparing evidence for security assessments and operational audits.

Successful Candidate Profile

The successful candidate will be organized, responsive, analytical, and comfortable working in a production enterprise environment. The individual must be able to independently investigate technical issues, clearly document actions and findings, coordinate with multiple technical teams, and manage competing operational priorities.

Candidates should clearly describe the specific platforms they personally administered, the configurations they performed, the size of the environments they supported, and examples of incidents or technical problems they resolved.

Equal Employment Opportunity

The employer is committed to providing equal employment opportunities. Employment decisions are based on qualifications, experience, business requirements, and demonstrated ability to perform the responsibilities of the position.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all