Technology Risk Management Analyst Resume
5.00/5 (Submit Your Rating)
SUMMARY
- 11+ yrs in Identity Access Management Administration, Information Security Control, Access Reviews, Audits, Access Control, User Entitlements, Manage Applications Credentials, User Access Policy Management, User life cycle management in Retail and Banking Services.
- Experienced in helping to improve 3rd party auditors to help improve SOX compliance.
- As onboarding lead specialized in guiding applications that use the file transfer connectors to oracle based IAM solution through onboarding process.
- Hands on Experience on IEM Manager on the User Entitlements management functions of the Identity/Access Management department.
- Working knowledge on Privileged Accounts and Critical roles.
- Responsible within the Oracle product (OIM) and perform provisioning and de - provisioning within these tools and on boarding of applications into these tools.
- Performed Access management and reporting using Compliance Manager, Key responsibilities included assisting the client in their (RBAC) Role Based Access.
- Involved in requesting and performing file transfer as part of on boarding process to create production/NAS folders that will be used for NDM/DTS connections to receive
- Involved in administration of Identity and Access Management (IAM) solutions, including user provisioning, role-based access control, authentication, and authorization.
- Developed reports, analytics using the SUN IDM, ARM provided role/user/audit search
- Working closely with Application owner and project team to develop processes around role-based identity.
- Integration of salesforce application using SAML protocol.
- Configuration MFA polies.
- Configuration of Sign-on policies.
- Managed User Accounts on Windows NT and UNIX Platform (Creation, Deletion, Permissions.
- Identifies and recommends solutions for manual processes that could be automated
- Managing Windows User ID and Oracle and Sun Identity and Access Management.
- Gathering the Requirements and Building a workflow in Sun IDM tool and working on Workflows.
- Worked on Okta which is a cloud based IAM solution.
- Hands on Windows, Mainframe and Banking Application with Risk assessment.
- Work on RBAC project (Role Based Access Control) for consolidating the User ID’s, Role Profiles and data cleanup.
- Integration and Configuration of Active Directory with Okta.
- Monitor current security state and provide reporting and trending.
- Access Provisioning and governance across various applications.
- Gathering the Requirements and Building a workflow in Sun IDM, OIM, ARM, OKTA and working on Workflows.
- Hands on access Control and Separation of Duties (SOD) policies initiatives.
- Assigning the Predefined SAP id as per the Role base access as per the DB predefined SATRE
- Successfully trained 40 new hires and existing staff on SOP’s and new updates for different locations through classroom and video conferencing.
- Working knowledge on Sun/Oracle IDM, Mainframe, AS400, Active
- Directory, RSA VPN/Remote Access, ISO standards and frameworks.
- Experienced in Security & Risk, Identity and Access Management and Technology Security Controls.
- Hands on experience in Windows server 2003, 2008, Active directory
- Infrastructure Mainframe and Windows accounts.
PROFESSIONAL EXPERIENCE
Confidential
Technology Risk Management Analyst
Responsibilities:
- Perform data analysis and risk reporting able to identify risks in the IAM processes (authentication, authorization)
- Developed, maintain, and execute Second Line of Defense team’s standard operating procedures (SOP).
- Evaluating the adequacy and effectiveness of IAM policies, standards, procedures, processes, and internal controls and recommend enhancements as needed; partner with first line technology partners, business owners and corporate technology groups to maintain awareness of policies and standards and consult on enhancement opportunities to continuously improve compliance working knowledge on Assess compliance with regulatory requirements from an IAM perspective
- Deployment of Okta AD agent.
- Resolving user’s day to day access issues with respective okta integrated application.
- Integration and Configuration of Active Directory with Okta.
- Creation of Dynamic groups in Okta. provisioning of users in target applications
- Tracking and troubleshooting routine activities and scheduled tasks
- Working on Incidents/Tickets using ITSM.
- Integration of salesforce application using SAML protocol.
- Configuration MFA polies.
- Configuration of Sign-on policies.
- Working knowledge on assess the current RCSA, applications, and tools for compliance against published IAM policies and standards and recommend continuous improvement
- Working closely with stakeholders to gather, interpret, and mature required IAM metric
- Creation of Sign on rules based on the different applications sign on requirements.
- Customization of Email templates.
- Tracking remediation efforts associated with internal/external audit findings.
- Helping the Customers in resolving their regular activities
- Customization of Okta Sign in Page.
- Configuration of delegated authentication and just in time provisioning for AD.
- Leading the Off-site team throughout the lifecycle of the project.
- Connecting with Okta vendor with respect to tool capability quarries.
- Helping the Customers with different tool capabilities.
Confidential, Dallas, TX
Oracle Application Onboarding Lead
Responsibilities:
- I as a file transfer onboarding lead specializes in guiding applications that use the file transfer connectors to oracle based IAM solution through onboarding process. Also, Work within the Oracle product (OIM) and perform provisioning and deprovisioning within these tools and on boarding of applications into these tools.
- Working with technical team, vendor and business to ensure file transfer process is defined and resolve any issues with the file transfer.
- Responsible within the Oracle product (OIM) and perform provisioning and de-provisioning within these tools and on boarding of applications into these tools.
- Custom Scheduled tasks and reconciliation based on those requirements
- Involved in requesting and performing file transfer as part of on boarding process to create production/NAS folders that will be used for NDM/DTS connections to receive .CVS flat file for these new applications. The file will be validated and then would be sent over to application owners.
- Created automated scripts to identify if there are any discrepancies between what is stated in AOR, and the provisioning walk through.
- Oversee the file transfer or MDM process. Involved in transferring a file and importing to IES through web service API for automated provisioning.
- Lead in all kick-off meeting to go over the documentation and showing an actual demonstration of provisioning for the application users and help project manager with the project plan.
Confidential, Madison
Sr. Security Operation Analyst - IAM Analyst
Responsibilities:
- Involved in administration of Identity and Access Management (IAM) solutions, including user provisioning, role-based access control, authentication, and authorization.
- Role Based Security Provisioning and ongoing security administration services support.
- Daily job functions related to Identity Access and Audit Management.
- Working on high volume of security requests to the business, this includes assigning security tokens.
- Granting security access in Identity Minder, AD, Mainframe and various systems for new and existing internal resources while adhering to the service level agreement.
- Working on HRSD critical Request and SAM1 SAM2 SAM3 request.
- Hands on experience on ITSM tool and Service Now
- Working on PowerShell to add and modify groups and to send for approval
- Responsible for mentoring and providing guidance to the other team members.
- Hands on experience on working on DB and Mainframe request.
- Working on New users, Transfers and terminations.
- Manage user access management for UNIX servers and AWS, Apex Application Request.
- Involved in minor enhancements on these applications based on the client requirements.
- Experienced on User life cycle management (Joiner/Mover/Leaver) also worked on RBAC.
Confidential
Enterprise Access management Consultant
Responsibilities:
- Global Access Operations is an enterprise service organization that centrally manages access identities, authentication, and authorizations/entitlements on a global scale.
- We deliver access management services to users throughout the enterprise more than 12,000 applications; by provisioning/de-provisioning the access, based on information contained on access provisioning tool, or pre-defined Role Based Access Control definitions.
- Gathering the Requirements and Building a workflow in Sun IDM tool and working on Workflows.
- Access Provisioning and governance across various applications.
- We are supporting FX Applications, GES Applications, Mercury trading Applications and few vendor Applications.
- Provides enhanced service level delivery for applications on-boarded into the security model - Promote user compliance with Confidential Information Security policies.
- Incident Management - Basic application access related issues on Login issues, Password issues, Access Locked/Disabled.
- Working closely with Application owner and project team to develop processes around role-based identity.
- Audit Reports and Inactive users report - Performs inactivity cleanup for users on various applications.
- Adheres to Corporate Information Security guidelines through all tasks.
- Regularly reviews system access procedures related to work assignments, identifies "errors and omissions" and reports discrepancies to management for corrections.
- Responsible for Access Control for e-Trading and Foreign Exchange applications.
- We Create /Reinstate/Modify, User Permissions, User Groups, User Entitlements, Application groups, Application Permissions and Entitlements Systems
- Identify security administration deficiencies, recommend improvements, and assist to implement corrective action
- Develop and maintain procedure documentation.
- Access Review: Follow up with managers after Final notification to complete outstanding Access Review for their associates
- Support of Entitlement Reviews and get the exceptions Approvals as per the Business Requirement.
- Run Audit Reports and Inactive users report and perform Quality Review Weekly Bases.
- Password reset for Sierra and Vendor applications.
- Manage OIM Pending Queue Approvals.
- Assist Clients on Intermittent Access Issues On call Support when Business Required.
- Responsible for maintaining relationships with business leaders and WebEx meetings.
- Hands on Experience on Execution of month end reporting and preparing monthly metrics as part of GIS.
Confidential, CT
IAM Consultant
Responsibilities:
- Identity/Drive Automation Initiative/Efforts to enhance productivity
- Work Closely with Training/Internal Audit team to drive efficiency
- Responsible for Day-Day Operations/Staffing/Team Needs
- Reporting /Adherence to Operational Metrics/SLA
- Responsible for day-to-day administration of all request types
- Ensure/Monitor team to Execute Leave of Absence (LOA) and Return to Work (RTW) requests.
- Ensure execution of daily, weekly checks to ensure access is terminated for exit workers.
- Liaise with Help Desk team members and assist as and when required and develop a customer centric model for increased end user satisfaction.
- Assist and support periodic internal and external IT audit and SOX audits
- First line of contact for any escalations/concerns from business
- Responsible for notifying management of any concerns raised by requestor and/or anticipating escalation.
- Work on RBAC project (Role Based Access Control) for consolidating the User ID’s, Role Profiles and data cleanup; Creation of roles, role profiles, user ID's, and custom authorization objects based on the roles.
- Ensuring team adherence to all Security Administration Standard Operating Procedures. Notify management when discrepancies are found in SOPs and fix it to ensure they are updated accordingly.
- Ensures Standard Operating Procedures are up to date.
- Responsible/Participate in projects and initiatives in support of regulatory, audit and IAM directives when called upon.
- Partner with the Identity Access Management teams to identify and address any IAM specific implications or issues relating to RPs and SAPs.
- SME during various IT and business-initiated projects requiring RP/SAP work
- Responsible for documenting process/technical difficulties being experienced and timely reporting them to management
- Collate statistical data as requested in support of metrics/measurements and publish them on periodical bases.
