Sr. Information Security Analyst / IAM Administrator (# 8358)

Summary:

Client is seeking a senior IT Security/IAM professional who can act as the primary security SME for the Child Support Services department. The key focus is deep expertise in Active Directory, Microsoft Entra ID, Okta, IAM integrations, RBAC, SSO, MFA, and enterprise identity security across on-prem and cloud environments. They also need someone experienced in security operations, SIEM, risk assessments, compliance frameworks (NIST/ISO/CIS), and security-related projects. Strong leadership, technical mentoring, communication, and ideally public-sector/HHS or modernization experience are important.

 

Here are some of the specific details:

Job Title: Senior Information Security Analyst / IAM Administrator

Location: Frankfort, KY (Remote)

Duration: Long-term Indefinite Contract

 

Job Description:
 We are seeking an experienced Information Security Analyst and Administrator to support the Department of Child Support Services’ security related technologies, processes, and implementations. This position will serve as the primary IT Security subject matter expert especially with the deployment of a new Identity Access Management solution and case management system. The ideal candidate will have demonstrated experience serving in both project and IT operation capacities within the security domain. They will have knowledge and experience with both on-premises and cloud environments especially within OKTA, Azure platform, and Active Directory. Candidates must possess strong communication and organization skills, and a deep understanding of Identity and Access Management solutions. This position will work closely with the OIS, COT, and other technical team stakeholders.

Duties and Responsibilities:

·       Server as primary IT Security Subject Matter Expert (SME) for the Department of Child Support Services.

·       Manage user authentication, authorization, and access control policies to prevent unauthorized access

·       Support the design and build of role-based access control security frameworks for the department,

·       Perform vulnerability scans, penetration tests, and risk assessments to identify and mitigate threats

·       Monitor security alerts, investigate breaches, and respond to incidents promptly

·       Develop, enforce, and update security policies; ensure compliance with legal and regulatory requirements

·       Educate staff on security best practices and protocols

·       Support the creation and maintenance of business continuity and disaster recovery plans

·       Administer identity and access management (IAM) systems including OKTA, Active Directory, Azure AD, and privileged access workstations

·       Monitor SIEM platforms (Splunk, Microsoft Sentinel, QRadar) for security events, tune alert rules, and escalate confirmed incidents

·       Implement and enforce multi-factor authentication, certificate management, and single sign-on configurations across enterprise applications

·       Develop and maintain security policies, standards, and procedures aligned with NIST CSF, ISO 27001, or CIS Controls frameworks

·       Support security audits and compliance assessments for SOC 2, HIPAA, PCI-DSS, or FedRAMP by gathering evidence and remediating findings

·       Perform security reviews on new systems, applications, and vendors as part of the change management and third-party risk process

·       Investigate phishing incidents, malware infections, and unauthorized access events; document findings and implement corrective controls

·       Identify and mitigate security replated project risks, issues, and dependencies, and develop contingency plans to ensure project success.


MUST-HAVE Requirements (non-negotiable):

·       Deep technical expertise in Microsoft Active Directory and Microsoft Entra ID.

·       Experience designing and implementing IAM integrations, provisioning workflows, and access controls.

·       Proven experience implementation & maintaining role based access control frameworks.

·       Proven ability to lead and mentor technical engineering teams.

·       Strong understanding of identity security principles and enterprise authentication models.

·       Previous experience with NIST CSF, ISO 27001, or CIS Controls frameworks

·       Bachelor's degree, preferably in Computer Science, Information Technology, Computer Engineering, or related IT discipline; or equivalent experience


Preferred Qualifications:

·       Strong understanding of identity security principles and enterprise authentication models. (SAML, OIDC, SCIM) and access control models like Fine-Grained Authorization (FGA)

·       Public sector child support/HHS; modernization programs.

·       Firewalls and network security: Palo Alto Networks, Fortinet FortiGate, Cisco ASA/FTD — rule writing, NAT, VPN configuration

·       SIEM: Splunk (SPL queries), Microsoft Sentinel (KQL), IBM QRadar — correlation rule tuning, dashboard creation

·       Endpoint security: CrowdStrike Falcon, Microsoft Defender for Endpoint, Carbon Black — alert triage, isolation, policy management

·       IAM: Active Directory, Azure Active Directory, Okta, CyberArk for PAM

·       Scripting: PowerShell and Python for automation of repetitive security tasks (log parsing, alert enrichment, AD queries)

·       Experience with ServiceNow and integration with prevalent identity access management platforms.


Tools and Platforms:

·       ServiceNow, Active Directory, Okta, Ping Identity, Azure AD, Cisco ASA, Fortinet FortiGate, Palo Alto PA OS, Check Point, FortiGate, Splunk, IBM QRadar, Microsoft Sentinel, eSet, Proofpoint Nessus, Qualys, NDiscovery, OpenVAS, ISO 27001 compliance checklists, CJIS compliance tools, SSAE 16 audit frameworks, NIST & Fed Ramp frameworks.


Certifications:

·       CISSP – Certified Information Systems Security Professional

·       CompTIA Security+

·       Microsoft Azure Security Engineer Associate (AZ-500)

·       Microsoft Applied Skills: Administer Active Directory Domain Services

 

Let me know if you are interested in this job and/or if you can assist us by referring to someone who is interested in this job, since we offer lucrative referral bonuses.

 

I am looking forward to speaking with you today.

 

About us:

Harvey Nash is a national, full-service talent management firm specializing in technology positions. Our company was founded with a mission to serve as the talent partner of choice for the information technology industry.

 

Our company vision has led us to incredible growth and success in a relatively short period of time and continues to guide us today. We are committed to operating with the highest possible standards of honesty, integrity, and a passionate commitment to our clients, consultants, and employees.

 

We are part of Nash Squared Group, a global professional services organization with over forty offices worldwide.

 

For more information, please visit us at https://www.harveynashusa.com/

 

Apply

Apply for this role

Additional questions

The following error(s) occurred:

Hi I'm Shyam

I manage this role

Harvey Nash Benefits & Perks

Medical, dental, and vision coverage
401(k) retirement plan
Voluntary benefits and insurance options
Referral bonus opportunities
Pre-tax commuter benefits
spinner

Processing...