Responsibilities
Translate complex business requirements into IAM and IGA service functionality
Develop highly scalable identity service serving enterprise, customer access, and external partner requirements
Produce technical solutions that meet NBCU business objectives and drive compliance with NBCU's information security goals
Partner with technology and security teams across NBCU to provide technical expertise, design guidance, and drive best practices
Catalog risk embedded in legacy authorization implementations and help define a path to industry-aligned secure designs and services
Partner in product evaluations and new technology adoptions
Lead the execution of a comprehensive IGA enterprise-level program for the organization
Implement, manage, lead, and document identity governance processes and tools
Provide ongoing reporting on the program metrics to ensure the quality of the program's services is meeting business objectives
Ensure that IGA process and workflow documentation is created and maintained
Mentoring/advising other team members
Qualifications
Basic Requirements:
Bachelor of Information Security or equivalent work experience
5+ years' experience designing solutions in IAM technical role(s) for large enterprise
Significant hands-on and design experience with modern and legacy IGA services
Experience developing Identity Lifecycle Management automation solutions
Experience with application connection design and consulting experience on IGA functions like user life cycle management, access control policies, federation, certifications, Access management, MFA and role management
Experience designing infrastructure, on-boarding of applications, role-based access controls, policy and password management, certifications, workflows, work items and rules
Deep knowledge and hands on technical experience with Lifecycle Manager, Compliance Manager, Access Request, Automated Provisioning Password Management
Understanding of RBAC, Identity Policies, Identity Lifecycle automation and reporting, Password Policies, Separation of duties, User Provisioning, and approval workflows in Saviynt, Microsoft EntraID, SailPoint IIQ and IDN
Ability to make source code level changes and has worked in a large multinational organization providing hands-on technical architecture services with J2EE development, Database, Java, Bean Shell/JavaScript, JSP/Servlets, SQL
Experience with Rest Web services, SAML 2.0, JDKs, OAuth, WS-Security, etc.
Experience with enterprise directory services, including significant knowledge of Active Directory and Entra ID
Exceptional communication and interpersonal skills; including negotiation, facilitation, and consensus building skills; ability to influence, persuade, and manage polarities without direct control
Ability to balance the long-term big picture and short-term implications of tactical decisions
Possesses an innovative technical mindset with a focus on architecture, strategy, and design
Strong desire to drive change
Desired Characteristics:
Excellent Communications Skills
Experience building and delivering large-scale Enterprise SailPoint service instances
Experience developing and delivering Zero Trust designs
Additional Requirements:
Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee's residence.
This position is eligible for company sponsored benefits, including medical, dental and vision insurance, 401(k), paid leave, tuition reimbursement, and a variety of other discounts and perks. Learn more about the benefits offered by NBCUniversal by visiting the Benefits page of the Careers website.
Salary range: $100,000 - $135,000
We are accepting applications for this position on an ongoing basis.