Senior IT Security Engineer - Identity and Access Management
CURRENT EMPLOYEES, CONSULTANTS, AND AGENCY PARTNERS:
If you currently work for Brown-Forman, please apply by clicking the Careers icon on the Workday portal.
For best results, use Google Chrome to view this page.
Meaningful Work From Day One:
The IT Security Senior Engineer will become an integral part of Brown-Forman’s Identity & Access Management (IAM) team supporting the implementation and administration of information security policies, practices, procedures, and technologies to ensure the protection of systems, applications, users, and data. Key responsibilities will be the lifecycle management of all Brown-Forman identities and affiliated user accounts, authentication to systems/applications via single sign-on and multifactor authentication, provisioning/deprovisioning of access (i.e., roles, groups, permissions), as well as privileged access management (PAM). The key security systems you will be interacting with are Active Directory, Google, Okta, Saviynt Cloud PAM, Saviynt Identity Governance and Access (IGA), Workday, including multiple Brown-Forman business applications. This position will partner with both business and IT personnel to deliver security solutions consistent with the IAM strategy.
Identity & Access Management (IAM) Design and Administration
- Primary area of focus will be administering Okta user authentication via single sign-on (SSO) & multifactor authentication (MFA)
- Experienced with Okta authentication methods – SAML 2.0, SWA, OIDC (OAuth 2.0), and WS-Federation
- Intermediate understanding of information security principles, identity & access management, privileged access management, application security
- Knowledgeable in identity governance & administration (IGA) tools and functionality
- Ability to implement security automation to address the organization’s user lifecycle management processes (e.g., new hires, position changes, and terminations) as well as access provisioning/deprovisioning
- Experienced in role-based methodologies to automate and expedite user access
- Implement and test identity governance & administration (IGA) and privileged access management (PAM) tools and processes
- Knowledgeable in privileged access management processes and automation
- Understand the flow of data through various security integrations and be able to identify, diagnose and correct issues/design flaws
- Design and develop IAM solutions that meet both security and business requirements
- Develop relationships with cross-functional teams to influence a security mindset
- Ensure security policies, standards, & methodologies are consistently applied
- Perform periodic reviews and maintenance to IAM processes to ensure compliance
- Prepare reports and presentations to management specific to identity metrics and analytics
Projects & Process Improvement
- Lead both technical and business security projects using formal project management techniques including business justification and funding requirements
- Complete project related tasks within budget and on-time
- Responsible for identifying and justifying security related process improvements
- Communicate & collaborate with cross functional teams on security related processes, systems, and methodologies
- Improve and streamline existing security processes (e.g., automation of manual tasks, employee/manager self-service, optimization of workflows)
- Prepare security documentation, such as presentations, flowcharts, procedures, etc.
- Identify risks associated with business processes, operations, information security programs and technology projects. Provide suggestions and options for remediation of the identified risks
- Stay abreast of cybersecurity risks and trends as well as emerging security practices
Security Awareness and Production Support
- Promote security awareness throughout all levels of organizations
- Deliver excellent customer service as it relates to security issues, questions, or concerns
- Perform 2nd & 3rd level support, by investigating & resolving escalated production support incidents and providing remediation for discovered problems
- Provide guidance, direction, and documentation to 2nd level support as it relates to user and access management issues
- Provide periodic on-call security support
We Are Looking For People Who:
- Bachelor’s or Master's degree in Computer Science or a related area of study. Work experience accepted in lieu of education
- 8 years of experience in IT Security or related field with a minimum of 3 years Okta specific experience
- Experienced with SAML 2.0, SWA, OIDC (OAuth 2.0), and WS-Federation
- IAM expertise with regards to API interfaces (SOAP/REST), data interchanges (JSON/XML) and programming languages (Powershell/VBS)
- Ability to apply a governance and risk based security approach
- Ability to plan, coordinate, and execute multiple assignments to meet deadlines
- Excellent interpersonal skills with ability to maintain effective working relationships with all levels of management and the ability to excel in a team environment with internal and external contacts
- Excellent written and verbal communication skills
- Ability to analyze security activities, identify process strengths and weaknesses, and develop creative solutions to improve efficiency and effectiveness. Includes the ability to understand and describe process flows
- Ability to work in a self-managed environment with a high degree of initiative and inquisitiveness
- Ability to adhere to a strict code of ethics in handling confidential information
What Sets You Apart:
- Master of Business Administration (MBA) or Master in an IT related field
- Okta Certification(s) – Professional, Administrator, Developer, or Consultant
- Security Certification (CompTIA Security+, CISA, CISM, CISSP, CRISC)
- Experience in the beverage alcohol or consumer products industry
Nothing Better in the Market:
Total Rewards at Brown-Forman is designed to engage our people to ensure sustainable and profitable growth for generations to come. As a premium spirits company, we offer premium and equitable pay. We offer a range of premium benefits that reflect our company values and meet the needs of our diverse workforce. We are dedicated to creating a responsible drinking culture, providing a safe, inclusive, and engaging workplace, protecting the environment, and making a positive contribution to our communities.
Locations considered for this opening:
- B-F Headquarters office in Louisville, KY
Requisition Type:
EmployeeManagement Level:
ProfessionalGlobal Job Level:
P6Number of Openings Available:
1