Security Senior Analyst - Identity Security Engineering

Elevance Health
St. Louis, MO, United States
1 day ago
Apply on www.techcareers.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Data Analysis Cloud Computing Cloud Computing Security Configuration Management Databases Cyber Security Computer Networks Disaster Recovery Middleware Identity and Access Management Intrusion Detection and Prevention Kerberos (Protocol)
+17 more
Network Security Lightweight Directory Access Protocols (LDAP) OAuth Role-Based Access Control Openid Connect Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Data Logging Scripting Google Cloud Cyberark SailPoint Restful APIs Network Server Software Version Control Servicenow

Job description

Location: This role requires associates to be in-office 1 day per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace. Ideal candidates will be able to report to one of our Pulse Point locations in Indianapolis, IN or St. Louis, MO. Alternate locations may be considered if candidates reside within a commuting distance from an office.

Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.

The Security Senior Analyst - Identity Security Engineering is responsible for engineering and operating identity security controls across human, privileged, non-human, cloud, and emerging agentic AI identities. The role has a primary focus on CyberArk Idira Endpoint Privilege Manager (EPM), with supporting responsibilities across CyberArk PAM and PSM capabilities, and helps advance least privilege, Just-in-Time access, Zero Standing Privilege, software control, and privileged access governance. This role partners with IAM, Identity Governance, Cyber Security, Cloud Security, Infrastructure, ServiceNow, and application teams to design, automate, monitor, and continuously improve secure access while supporting operational, audit, compliance, and 24x7 service requirements.

How you will make an impact:

  • Engineers and operates CyberArk Idira EPM, including policy design, application control, software-installation governance, temporary elevation, agent health, and troubleshooting.
  • Supports CyberArk PAM and PSM capabilities, including privileged credentials, session controls, emergency access, and JIT/ZSP use cases.
  • Translates business and security requirements into RBAC, ABAC, policy-based, risk-based, and time-bound access controls.
  • Supports identity governance processes, including access requests, approvals, provisioning, certification, revocation, segregation of duties, and exception management.
  • Extends identity security controls across workforce identities, privileged accounts, service and workload identities, NHIs, cloud identities, and agentic AI identities.
  • Integrates CyberArk capabilities with ServiceNow, SailPoint, directories, CMDB, and cloud platforms using supported APIs and workflow automation.
  • Automates identity discovery, directory queries, entitlement analysis, reconciliation, telemetry, reporting, and audit evidence using secure and supportable engineering practices.
  • Analyzes telemetry, audit records, and identity security events to identify misuse, policy gaps, access drift, and opportunities to reduce standing privilege.
  • Develops testing plans, operational procedures, runbooks, metrics, and audit evidence while supporting incident investigation, root-cause analysis, and continuous improvement.

Requirements

  • Requires a bachelor’s degree or equivalent combination of education and experience that would provide the knowledge to perform such work.
  • Experience must include a minimum of 3 years of experience in a support and operations or design and engineering role in any of the following areas: access management or network security technologies, servers, networks, network communications, telecommunications, operating systems, middleware, disaster recovery, collaboration technologies, hardware/software support or other infrastructure services role; or any combination of education and experience, which would provide an equivalent background.

Preferred Skills, Capabilities and Experiences:

  • Three to five years of experience in Identity Security, IAM, PAM, IGA, access engineering, or security operations preferred.
  • Hands-on experience with CyberArk Idira EPM; familiarity with CyberArk PAM, PSM, Privilege Cloud, or related privileged access technology preferred.
  • Strong understanding of least privilege, JIT access, ZSP, Zero Trust, privileged-access tiering, and Identity Threat Detection preferred.
  • Experience applying RBAC, ABAC, policy-based access, risk-based access, and role or entitlement design preferred.
  • Understanding of Identity Governance processes, including joiner-mover-leaver lifecycle, access requests, certifications, segregation of duties, and exception governance preferred.
  • Familiarity with NHI, workload, cloud, and agentic AI identities, including service accounts, secrets, certificates, and access controls in Microsoft Entra ID, AWS IAM, and Google Cloud preferred.
  • Knowledge of IAM standards and protocols such as SAML, OAuth 2.0, OpenID Connect, SCIM, LDAP, Kerberos, and REST APIs preferred.
  • Experience using scripting, query, workflow, or low-code tools to automate identity discovery, AD/LDAP queries, entitlement analysis, access lifecycle workflows, reporting, and audit evidence preferred.
  • Strong foundation in identity-focused automation and orchestration, including APIs, AD/LDAP queries, data analysis, reusable workflows, logging, error handling, testing, version control, and secure credentials preferred.
  • Experience supporting large, regulated, and highly available enterprise environments; relevant CyberArk, identity, cloud, or security certifications preferred.

Benefits & conditions

At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.

We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.

Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.

The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.

About the company

Elevance Health is a health company dedicated to improving lives and communities - and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

46 sec

Brokering third-party APIs with OAuth federation

Deepu Deepu · World Congress 2025

Videos

See all

Related articles

See all