CIAM-Developer-AVP-2
Description
Do you want your voice heard and your actions to count?
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
EDUCATION
- Degree or equivalent work experience equally preferable.
- Degree in computer science, technology, or related field.
CERTIFICATIONS
- [Include information as needed.]
WORK EXPERIENCE
- • Proven experience in IAM work including access control (role-based and discretionary), authentication, authorization, provisioning, approvals, and workflows
- • Hands on experience developing and supporting security solutions for identity management and access control
- • Strong understanding of information security risk analysis, Identity Access Management and access control methodologies with working knowledge of business applications
- • Successful experience working in global, complex, matrix-managed organization
- • Experience in the financial services or banking industry preferred
FUNCTIONAL SKILLS
- Deep understanding of IAM principals, methodology, and solutions
- Programming/debugging skills: Unix Shell, Perl, Java, JavaScript
- Solid understanding of web-based technologies including multi-tier applications and security standards (Secure Sockets Layer (SSL), Hyper Text Transfer Protocol (HTTP), cookie handling, Security Assertion Markup Language (SAML), WS-Security)
- Solid understanding of relational database management systems (RDBMS) and directory services Lightweight Directory Access Protocol (LDAP), in particular active directory) including system architecture, configuration, and monitoring
- Understanding of security issues, application-level security, encryption, and vulnerabilities
- Excellent Excel skills (for example, macros, formulas, query from backend database)
- Control knowledge around access management and ability to articulate risk and impact
- Knowledge in industry and government security standards (National Institute of Standards and Technology (NIST), Center for Information Security (CIS), etc.)
- Solid understanding of system logical access and audit controls are desirable.
- Programming and scripting abilities; specifically in Pentaho (PDI), JavaScript, Perl, PowerShell
- Experience with presentation applications such as Tableau or QlikView preferred
- Strong database, operating system (OS), software engineering skills
- Strong background in use of ASP.Net, JScript, c#, RDBMS, Office Suite, Win2k8, AIX, RHL 5, xml, php, IIS, PowerShell
- Strong structured query language (SQL) background, ability to write complex SQL queries, stored procedures.
- Knowledge of RSA Identity Access life cycle governance is required
- Strong understanding of information security risk analysis, Identity Access Management and access control methodologies with working knowledge of business applications
- Single Sign On (SSO), Lightweight Directory Access Protocol (LDAP), and federation experience including system architecture, configuration, monitoring, and ongoing compliance
- Practical experience with application integrations including: SSO architecture, configuration, monitoring, and compliance
- Experience with the following web servers: Internet Information Systems (IIS), Apache, or IBM
- Experience with the following application servers: WebSphere, JBoss, or WebLogic
- Experience working with leading IAM tools and services
- Knowledge of privileged or elevated access tools
- Control knowledge around access management and ability to articulate risk and impact
- Programming and scripting abilities; specifically in Pentaho (PDI), JavaScript, Perl, PowerShell
- Strong database, operating system (OS), software engineering skills. Azure/AWS experience is a plus
- Strong structured query language (SQL) background, ability to write complex SQL queries, stored procedures
- Ability to document and explain technical details in a concise, understandable manner
FOUNDATIONAL SKILLS
- Communicates effectively
- Identifies multiple paths to success using analytical and critical thinking as well as decision-making skills
- Exercises sound judgement, prioritizes effectively, and strives for continuous improvement
- Effectively collaborates with colleagues
- Leverages available technology to drive efficiency and results
- Understands and applies industry trends and best practices
- Exhibits optimism, resilience, flexibility, and openness to others' ideas
- Values learning as a lifelong professional objective
- Engages inclusively and with intent
- Always acts with integrity
- Iterative problem-solving
- Serving as a trusted advisor
- Ability to establish and maintain business relationships
- Solid organizational skills with the ability to multi-task various initiatives and activities
RESPONSIBILITIES
- High level responsibilities include::
- Educate, train, and support end-users and MIS (Management Information System) staff members on information security best practices, policies, and procedures such as hard copy materials containing sensitive information. Perform user provisioning, authentication, and access governance adhering to established guidelines. Publish, monitor, and mandate information and computer security policies and security awareness information and programs. Provide recommendations on mitigating or removing vulnerabilities within IT systems, while administering firewall components and implementing daily network support. Assist in the configuration and implementation of IAM systems and applications. Schedule and supervise periodic network security assessments across multiple platforms and/or distributed networks. Conduct vulnerability assessments to improve security standards and procedures within the organization that support strategic, tactical and operational objectives on a cost-effective basis. Conduct regular reviews on user access authorization, through working with other department such as Human Resource, Legal functions. Perform complex security resource and access rule maintenance; develop and implement security monitoring and violation reports that identify any attempt to access unauthorized materials. Develop guidelines and reports on the usage, control, maintenance and auditing of information and computer resources. Troubleshoot technical and operational problems about IAM system and access control processes. Provide security support in a distributed environment; participate in technical evaluations of enterprise security access control products.
- Details:
- • Develop password requirements and deploy to major systems and applications
- • Protect the transmission and storage of passwords, personal identification numbers (PINs), digital certificates, and other credentials using encryption
- • Develop standards and manage multi-factor authentication, including tokens and/or biometrics for systems that contain sensitive data
- • Ensure SSO and password synchronization systems meet organizational standards and baselines
- • Analyze, design, and implement a cohesive ecosystem that includes active directory, identity federation, multi-factor authentication, privileged access and identity management
- • Troubleshoot network connectivity issues as they pertain to authentication and authorization
- • Research evolving IAM techniques and tools in support of future IAM efforts
- • Stay current with information security program