- Salary
- $73k – $171k
- Location
- Poughkeepsie, United States of America
- Type
- Full-time
- Department
- Management
- Experience
- 5+ years
- Education
- Master
- Closing date
- Today
- Source
- Workday
Description
Benefits:
Competitive compensation
Medical, Dental, and Vision insurance
401(k) Retirement Savings Plan with substantial company match
Life and Travel Insurance
Tuition Assistance
Wellness Reimbursement Program
Paid Holidays and Vacation
What is an Identity & Access Management Analyst?
We are seeking a diligent and experienced Identity and Access Management (IAM) Analyst to join our team. In this role, you will be working within a group of highly motivated Information Technology and Cybersecurity professionals committed to keeping Central Hudson safe. The IAM Analyst will be responsible for managing and securing user identities, access controls, and authentication and authorization systems across the organization’s IT and OT environments. This includes the administration and governance of identity lifecycle management, access provisioning, role-based access control, privileged access management, and ensuring compliance with security policies and regulatory requirements. The ideal candidate will have a strong understanding of IAM principles, directory services, SSO/MFA technologies, excellent analytical skills, and the ability to communicate effectively with internal stakeholders and vendors alike.
What does an Identity & Access Management Analyst do?
Administers and maintains identity and access management platforms, including Azure Entra ID (Azure AD), Active Directory, SailPoint and related IAM solutions to ensure secure and efficient access across the organization
Design, create, and manage Microsoft Entra ID (Azure AD) Enterprise Applications and App Registrations, including configuration of authentication methods (OAuth2/OIDC/SAML), API permissions, secrets/certificates, and lifecycle governance aligned with enterprise security standards
Manages the full identity lifecycle including provisioning, de-provisioning, transfers, and role changes for employees, contractors, and service accounts
Implements and maintains role-based access control (RBAC) models, ensuring access rights are aligned with job functions and the principle of least privilege
Administers and supports multi-factor authentication (MFA), single sign-on (SSO), and conditional access policies to strengthen authentication controls
Manages and monitors privileged access management (PAM) solutions to secure elevated accounts and reduce risk of credential-based attacks
Conducts regular user access reviews and certification campaigns to validate access appropriateness and ensure compliance with internal policies and regulatory requirements (e.g., SOX, NERC CIP)
Investigates and resolves access-related incidents, including unauthorized access attempts, account lockouts, and permission escalation issues
Develops and maintains IAM policies, procedures, and standard operating documentation
Partners with HR, IT, and business units to ensure timely and accurate access provisioning aligned with onboarding, offboarding, and role change processes
Supports the integration of applications and systems with centralized IAM platforms, including SAML, OAuth, OIDC, and SCIM-based integrations
Monitors IAM systems for anomalies, misconfigurations, and potential security risks; escalates findings and recommends remediation actions
Generates reports and dashboards on IAM metrics, including access review completion rates, provisioning SLAs, and policy compliance
Automates IAM workflows and processes using scripting and orchestration tools to improve efficiency and reduce manual effort
Stays updated with the latest IAM trends, threats, and technologies, and applies this knowledge to strengthen the organization’s identity security posture
Supports audit and compliance activities by providing evidence of access controls, policy enforcement, and identity governance
Promotes and raises awareness by educating others about the importance of identity security and access hygiene best practices
Supports project planning and execution for IAM-related initiatives, including tracking timelines and resource needs
Participates in on-call rotation as needed to respond to access-related incidents outside of regular working hours
Provides storm/emergency response support
What does it take to be an Identity & Access Management Analyst?
Required:
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science or related field of study and IAM or related experience. In lieu of a bachelor’s degree, an associate degree in the aforementioned fields and 3+ years of IAM or related experience or a high school diploma or equivalency degree and 5+ years of IAM or related experience will be considered
Experience administering identity and access management solutions such as Azure Entra ID (Azure AD), Active Directory, or other IAM/IGA platforms
Understanding of IAM concepts including identity lifecycle management, RBAC, least privilege, SSO, MFA, and conditional access
Experience with user provisioning, de-provisioning, and access certification processes
Experience configuring and administering Windows Servers, Active Directory & Group Policy, Microsoft 365, Azure Entra ID, and Azure compute and networking resources
Experience with scripting for automation and analysis (e.g., PowerShell, Python, Bash)
Familiarity with authentication and federation protocols such as SAML, OAuth, OIDC, and SCIM
Familiarity with Microsoft Entra ID application integration, including Enterprise Applications and App Registration concepts, authentication flows, and API permissions
Understanding of privileged access management (PAM) principles and tools
Understanding of regulatory and compliance frameworks as they relate to access controls (e.g., SOX, NERC CIP, NIST)
Understanding of Operational Technology (OT) systems and their access management requirements
Effective communication skills, with the ability to collaborate with diverse teams and communicate complex concepts clearly and concisely
Excellent analytical, decision-making, multitasking, and organizational skills
Ability to work with limited direct supervision and professionally respond to constructive feedback
Ability to be available for on-call and after-hour access-related incidents
Valid driver’s license
Preferred:
5+ years of experience in identity and access management or a closely related cybersecurity discipline
Experience with Identity Governance and Administration (IGA) platforms such as SailPoint, Saviynt, or Microsoft Identity Governance
Experience in Security and/or Regulatory Frameworks such as NIST, CIS Benchmarks, SOX, NERC CIP, etc.
Experience in Energy & Utilities or services industry
Experience implementing or managing PAM solutions such as CyberArk, BeyondTrust, or Delinea
Experience with data visualization tools and building IAM operational dashboards
Experience developing IAM automation workflows and integrations
Relevant certifications such as Certified Identity and Access Manager (CIAM), Certified Information Systems Security Professional (CISSP), CompTIA Security+, Microsoft Certified: Identity and Access Administrator Associate (SC-300), SailPoint Certified IdentityNow Engineer
Applications will be accepted until August 4, 2026.
This position has a career path which allows for advancement opportunities within the Cybersecurity Analyst job series. The title and level are commensurate with experience. Pay range: $73,000 - $171,300
Please go to https://www.cenhud.com/employment. Click the “Search Career Opportunities” button. Follow the directions to submit an application and upload your resume for the desired position.
Applications sent via e-mail and US Mail will not be accepted. No phone calls or agencies, please. All replies will be held in strict confidence.
All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, creed, color, ethnicity, arrest or conviction record, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, citizenship, genetic information, familial status, marital status, pregnancy-related condition, domestic violence victim status, veteran or military status, or any other characteristic protected by federal, state or local laws. Central Hudson Gas & Electric Corporation takes affirmative action in support of its policy to employ and advance employment in individuals who are protected veterans and individuals with disabilities.
VEVRAA FEDERAL CONTRACTOR