IAM Security Engineer

Next Level Business Services Inc
United States
3 months ago
Apply on dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Agile Methodology ARM Architecture JIRA User Authentication Cloud Computing Cyber Security Identity and Access Management Information Model Platform as a Service (PAAS) Role-Based Access Control Data Logging Software Security
+1 more
Splunk

Job description

Client s IAM ( Identity and Access Management ) team is leading an initiative to implement enhanced logging and monitoring of access changes across high-risk applications, leveraging technologies such as Splunk and Cortex. The IAM Security Engineer will be responsible for Highly Privileged Access (HPA) Logging and Monitoring. This role partners closely with client s technology teams to onboard applications to the Monitoring Framework which includes determining the applications logging capabilities through the discovery process and onboarding the applications to Splunk.

In addition, the IAM team is leading an initiative to enhance the implementation of a system that identified secret keys across our environment and reports on secrets that are approaching or beyond the required secret key rotation date, based on requirements in our standards. The IAM Security Engineer will be responsible for understanding test cases, executing testing of functionality, and identifying/reporting defects throughout development.

Scope of Services: Company is requesting Contractor to provide support for the HPA Logging and Monitoring Discovery and Onboarding phases, and testing of functionality for secrets rotation tool. Based on negotiations between the parties, the scope of services to be provided by Contractor shall be limited to those activities described in this Section. Contractor shall provide assistance to Company to accelerate onboarding of Apps to Splunk, and testing of functionality for secrets rotation tool.

The services shall consist of the following: Facilitate discovery and engagement with application owners. Conduct interviews, working sessions, and document onboarding. Document and escalate risk mitigation plan for apps that cannot onboard. Coordinate troubleshooting efforts when preparing apps for onboarding. Report ongoing status and raise required escalations. Analyze log data to identify relevant log events to map to Splunk data models. Develop Splunk technology add-ons to properly parse, event type, and tag application security data. Test and quality assure Splunk configurations (e.g., confirm appropriate events are in logs and properly mapped to Common Information Model, confirm Splunk standards are followed). Release apps to production Splunk team. Develop and execute test plans and cases for new application functionality Collaborate with developers to reproduce and troubleshoot issues Maintain detailed test documentation

Requirements

A total of 3 years working experience, with a minimum of 1 years engineering and/or architecture experience in IAM or adjacent InfoSec domains, such as Data Protection or Security Engineering and in lieu of a degree 5+ years of working experience. A minimum of 1-year hands-on experience with IAM technologies Deep understanding of Splunk Cloud and Splunk Processing Language (SPL) Experience working in a cloud (PaaS) environment Knowledge of foundational IAM concepts Authentication, Authorization, RBAC, etc Exceptional written and verbal communication skills Ability to prioritize work efforts based on risk and project timelines Experience working in Agile methodology, leveraging Jira and Jira Align

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all