#NC25CL001 -Support for Cloud Identity and Access Management - Closed
Deadline: January 12, 2025
Requester: NATO
Location: Offsite.
Job type: Contractor
Start date: February 17, 2025
Security clearance: NATO Secret
SCOPE OF WORK / DUTIES / ROLES
- Design, implement, and manage identity and access management (IAM) solutions using Microsoft Entra ID (Azure AD) and Amazon AWS.
- Ensure seamless integration of IAM solutions with internal and external applications and systems.
- Develop and deploy PowerShell scripts and Azure Automation workflows to automate user account and group management tasks.
- Implement self-service capabilities for account and group management to enhance efficiency.
- Oversee the entire account lifecycle management process, from user onboarding to offboarding.
- Provision new accounts and assign appropriate access rights based on role requirements.
- Regularly review and update user roles and permissions to reflect changes in job functions and organizational structure.
- Promptly deprovision accounts when users leave the organization or change roles, ensuring the removal of access rights.
- Implement role-based access control (RBAC) to manage permissions based on job roles.
- Conduct periodic access reviews and certifications to ensure compliance with organizational policies.
- Implement and manage Azure AD Privileged Identity Management (PIM) to control, monitor, and audit privileged access to resources.
- Configure PIM to enforce just-in-time (JIT) access, approval workflows, and access reviews for privileged roles.
- Apply security best practices and ensure compliance with relevant standards and regulations.
- Conduct regular audits and reviews of access controls and permissions.
- Provide support for IAM-related issues, including troubleshooting user access problems and resolving authentication challenges.
- Act as an escalation point for complex IAM issues.
- Maintain comprehensive documentation of IAM processes, configurations, and workflows.
- Provide training and support to IT staff and end-users on IAM best practices and tools.
- Monitor the performance and effectiveness of IAM systems and processes.
- Identify opportunities for improvement and implement optimizations to enhance security and efficiency.
- Collaborate with IT security, compliance, and other relevant teams to ensure cohesive IAM strategies.
- Communicate effectively with stakeholders to understand IAM requirements and address concerns.
- Manage external collaboration and sharing settings in Azure AD to enable secure access for partners and external users.
- Implement and manage B2B (Business-to-Business) collaboration settings and policies through Entra ID.
- Integrate and manage IAM processes for B2B scenarios, ensuring seamless and secure interactions with external partners.
- Integrate and manage IAM processes with Amazon AWS, ensuring secure access and interoperability between Azure AD and AWS environments.
- Implement and manage federated identities and single sign-on (SSO) between Azure AD and AWS environments.
- Monitor and optimize IAM configurations to ensure compliance and security across multi-cloud environments.
- Develop and implement automation scripts using PowerShell to streamline routine support tasks such as software installations, updates, and system checks.
- Utilize Power Automate to create workflows that automate repetitive tasks and improve service efficiency.
- Identify opportunities for efficiency through automation and proactively implement solutions.
- Communicate effectively with users to understand their issues and provide clear instructions.
- Collaborate with IT teams to resolve issues and improve service delivery.
- The contractor will be part of a team providing Technical Level 2 and 3 support, ensuring the secure, available, managed, and compliant delivery of Public Cloud Services to NATO and its Strategic Commands.
- The contractor will work remotely, providing services during the core working hours of the Cloud Operations team (Brussels, Belgium).
REQUIRED SKILLS, KNOWLEDGE AND EXPERIENCE
The consultancy support for this work requires an experienced Cloud Engineer (Remote) specializing in Identity and Access Management (IAM), with the following qualifications:
- In-depth knowledge of Microsoft Entra ID (Azure Active Directory) and Amazon AWS identity and access management services.
- Proficiency in PowerShell scripting and automation tools (e.g., Azure Automation, Microsoft Graph API).
- Experience with IAM solutions and tools, including role-based access control (RBAC), multi-factor authentication (MFA), and conditional access policies.
- Expertise in Azure AD Privileged Identity Management (PIM) and privileged access control.
- Strong analytical skills to assess and improve IAM processes and workflows.
- Ability to troubleshoot complex IAM issues and implement effective solutions.
- Understanding of security best practices and compliance requirements related to identity and access management.
- Experience conducting audits and ensuring adherence to regulatory standards.
- Excellent communication skills to effectively collaborate with IT teams, stakeholders, and end-users.
- Ability to document processes clearly and provide training on IAM tools and practices.
- Strong organizational skills to manage multiple tasks and priorities effectively.
- Attention to detail in managing user accounts, groups, and access controls.
- Ability to work effectively as part of a team and share knowledge and resources.
- Willingness to collaborate with colleagues to solve complex issues.
- Strong customer relationship skills, including the ability to navigate complex and sensitive situations under pressure.
- Full proficiency in English; proficiency in French is an advantage.
Mandatory:
- Citizenship of a NATO member nation.
This position is now closed.
We regularly add new positions. We suggest exploring other available opportunities and staying updated by following our LinkedIn page.
If you don’t find any suitable opportunities, you can send us your CV, as an open application. However, we will not submit you to any vacancies without your written consent.
