Summary:
Client
is seeking a senior IT Security/IAM professional who can act as the primary
security SME for the Child Support Services department. The key focus is deep
expertise in Active Directory, Microsoft Entra ID, Okta, IAM integrations,
RBAC, SSO, MFA, and enterprise identity security across on-prem and cloud
environments. They also need someone experienced in security operations,
SIEM, risk assessments, compliance frameworks (NIST/ISO/CIS), and
security-related projects. Strong leadership, technical mentoring,
communication, and ideally public-sector/HHS or modernization experience
are important.
Here
are some of the specific details:
Job
Title: Senior Information Security Analyst / IAM Administrator
Location:
Frankfort,
KY (Remote)
Duration:
Long-term
Indefinite Contract
Job Description:
We are seeking an experienced Information Security Analyst and
Administrator to support the Department of Child Support Services’ security
related technologies, processes, and implementations. This position will serve
as the primary IT Security subject matter expert especially with the deployment
of a new Identity Access Management solution and case management system. The
ideal candidate will have demonstrated experience serving in both project and
IT operation capacities within the security domain. They will have
knowledge and experience with both on-premises and cloud environments
especially within OKTA, Azure platform, and Active Directory. Candidates must
possess strong communication and organization skills, and a deep understanding
of Identity and Access Management solutions. This position will work closely
with the OIS, COT, and other technical team stakeholders.
Duties and Responsibilities:
· Server as primary IT
Security Subject Matter Expert (SME) for the Department of Child Support
Services.
· Manage user
authentication, authorization, and access control policies to prevent
unauthorized access
· Support the design
and build of role-based access control security frameworks for the department,
· Perform
vulnerability scans, penetration tests, and risk assessments to identify and
mitigate threats
· Monitor security
alerts, investigate breaches, and respond to incidents promptly
· Develop, enforce,
and update security policies; ensure compliance with legal and regulatory
requirements
· Educate staff on
security best practices and protocols
· Support the creation
and maintenance of business continuity and disaster recovery plans
· Administer identity
and access management (IAM) systems including OKTA, Active Directory, Azure AD,
and privileged access workstations
· Monitor SIEM
platforms (Splunk, Microsoft Sentinel, QRadar) for security events, tune alert
rules, and escalate confirmed incidents
· Implement and
enforce multi-factor authentication, certificate management, and single sign-on
configurations across enterprise applications
· Develop and maintain
security policies, standards, and procedures aligned with NIST CSF, ISO 27001,
or CIS Controls frameworks
· Support security
audits and compliance assessments for SOC 2, HIPAA, PCI-DSS, or FedRAMP by
gathering evidence and remediating findings
· Perform security
reviews on new systems, applications, and vendors as part of the change
management and third-party risk process
· Investigate phishing
incidents, malware infections, and unauthorized access events; document
findings and implement corrective controls
· Identify and
mitigate security replated project risks, issues, and dependencies, and develop
contingency plans to ensure project success.
MUST-HAVE Requirements (non-negotiable):
· Deep technical
expertise in Microsoft Active Directory and Microsoft Entra ID.
· Experience designing
and implementing IAM integrations, provisioning workflows, and access controls.
· Proven experience
implementation & maintaining role based access control frameworks.
· Proven ability to
lead and mentor technical engineering teams.
· Strong understanding
of identity security principles and enterprise authentication models.
· Previous experience
with NIST CSF, ISO 27001, or CIS Controls frameworks
· Bachelor's degree,
preferably in Computer Science, Information Technology, Computer Engineering,
or related IT discipline; or equivalent experience
Preferred Qualifications:
· Strong understanding
of identity security principles and enterprise authentication models. (SAML,
OIDC, SCIM) and access control models like Fine-Grained Authorization (FGA)
· Public sector child
support/HHS; modernization programs.
· Firewalls and
network security: Palo Alto Networks, Fortinet FortiGate, Cisco ASA/FTD — rule
writing, NAT, VPN configuration
· SIEM: Splunk (SPL
queries), Microsoft Sentinel (KQL), IBM QRadar — correlation rule tuning,
dashboard creation
· Endpoint security:
CrowdStrike Falcon, Microsoft Defender for Endpoint, Carbon Black — alert
triage, isolation, policy management
· IAM: Active
Directory, Azure Active Directory, Okta, CyberArk for PAM
· Scripting:
PowerShell and Python for automation of repetitive security tasks (log parsing,
alert enrichment, AD queries)
· Experience with
ServiceNow and integration with prevalent identity access management platforms.
Tools and Platforms:
· ServiceNow, Active
Directory, Okta, Ping Identity, Azure AD, Cisco ASA, Fortinet FortiGate, Palo
Alto PA OS, Check Point, FortiGate, Splunk, IBM QRadar, Microsoft Sentinel,
eSet, Proofpoint Nessus, Qualys, NDiscovery, OpenVAS, ISO 27001 compliance
checklists, CJIS compliance tools, SSAE 16 audit frameworks, NIST & Fed
Ramp frameworks.
Certifications:
· CISSP – Certified
Information Systems Security Professional
· CompTIA Security+
· Microsoft Azure
Security Engineer Associate (AZ-500)
· Microsoft Applied
Skills: Administer Active Directory Domain Services
Let
me know if you are interested in this job and/or if you can assist us by referring
to someone who is interested in this job, since we offer lucrative referral
bonuses.
I
am looking forward to speaking with you today.
About
us:
Harvey
Nash is a national, full-service talent management firm specializing in
technology positions. Our company was founded with a mission to serve as the
talent partner of choice for the information technology industry.
Our
company vision has led us to incredible growth and success in a relatively
short period of time and continues to guide us today. We are committed to
operating with the highest possible standards of honesty, integrity, and a
passionate commitment to our clients, consultants, and employees.
We
are part of Nash Squared Group, a global professional services organization
with over forty offices worldwide.
For
more information, please visit us at https://www.harveynashusa.com/