Identity & Access Management Specialist (Active Directory • Microsoft Entra ID • CyberArk) - Hybrid
mtb
·Today
- Salary
- $62k – $104k
- Location
- Buffalo, NY, United States of America · Wilmington, DE
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Management
- Seniority
- Director
- Education
- Bachelor
- Source
- Workday
Description
Overview:
Join a team that plays a critical role in keeping the organization running. The Identity Management team is responsible for managing user access throughout the employee lifecycle, ensuring team members have the right access to the right systems at the right time. From employee onboarding and role changes to departures, this team helps safeguard the organization's systems while enabling employees to do their jobs effectively. As an Identity & Access Management Specialist, you will manage and support access provisioning, deprovisioning, recertification, and remediation activities across a complex enterprise environment. You'll work extensively with technologies such as Active Directory, Microsoft Entra ID, CyberArk, and other identity management tools while handling a high volume of requests and supporting key security initiatives. This role is ideal for a detail-oriented, self-motivated professional who thrives in a fast-paced environment, enjoys solving complex access challenges, and values being part of a highly collaborative team.
What You'll Do:
Manage user access throughout the employee lifecycle, including onboarding, job transfers, and offboarding activities.
Provision, modify, and remove access across a wide range of enterprise applications, platforms, and systems while ensuring compliance with security policies and access governance standards.
Administer and support identity management technologies including Active Directory, Microsoft Entra ID, CyberArk, and related IAM solutions.
Perform access reviews, certifications, and audits to ensure appropriate user permissions are maintained.
Investigate, troubleshoot, and resolve complex identity and access issues, serving as an escalation point for challenging requests.
Conduct root cause analysis and implement corrective actions to improve security, efficiency, and user experience.
Partner with technology teams, cybersecurity teams, and business stakeholders to gather requirements, resolve issues, and support access-related initiatives.
Support Privileged Access Management (PAM) processes and controls.
Contribute to both day-to-day operational work and strategic projects focused on improving identity and access management capabilities.
Utilize Jira and queue-based workflows to prioritize, track, and complete requests efficiently.
Develop and maintain standard operating procedures and process documentation.
Train and mentor newer team members and share knowledge across the team.
Participate in an on-call rotation to support critical production access issues outside of normal business hours.
What Makes This Role Unique:
Play a direct role in enabling employees across the organization to access the systems and tools they need to perform their jobs.
Work with industry-leading identity and privileged access management technologies.
Gain exposure to a large-scale enterprise environment with a diverse application landscape.
Participate in impactful security, automation, and process improvement initiatives.
Join a highly collaborative team that values knowledge sharing, teamwork, and continuous learning.
Ideal Candidate:
We're looking for someone who enjoys tackling complex problems, works well in a high-volume environment, and is eager to learn and grow within the identity and access management space. Successful candidates will demonstrate:
Experience in Identity & Access Management (IAM), identity governance, access administration, or related cybersecurity disciplines.
Knowledge of Active Directory, Microsoft Entra ID, CyberArk, or similar identity management platforms.
Experience supporting Privileged Access Management (PAM) programs and controls.
Familiarity with identity management tools, enterprise file systems, Exchange administration, or related technologies.
Experience working within ticketing and workflow management systems such as Jira.
Strong organizational skills with the ability to manage multiple priorities simultaneously.
A detail-oriented mindset and commitment to accuracy.
Strong problem-solving and analytical thinking abilities.
Excellent verbal and written communication skills.
A collaborative, team-first approach and willingness to support colleagues.
The ability to quickly learn new technologies, processes, and business requirements.
Education and Experience Required:
Associates degree, or equivalent work experience.
4+ years’ relevant work experience.
Basic understanding of identity and access management.
Education and Experience Preferred:
Bachelor's degree in Information Technology, Cybersecurity, Business, or a related field.
Experience in Identity & Access Management, information security, systems administration, or a related technology field.
Experience supporting user access provisioning, deprovisioning, and access governance activities.
Experience with Active Directory, Microsoft Entra ID, CyberArk, or similar IAM technologies.
Experience with Privileged Access Management (PAM).
Experience within a large enterprise technology or cybersecurity environment.
Knowledge of identity governance, access certifications, and compliance requirements.
Work Model & Office Location:
This is a hybrid role that combines the value of in-person collaboration with workplace flexibility. Employees are expected to work onsite four days per week and may work remotely one day per week, with the flexibility to choose their preferred remote workday. To support regular onsite collaboration, candidates must reside within a reasonable commuting distance of one of the following office locations:
1 Seneca Street, Buffalo, NY 14203
1100 North Market Street, Wilmington, DE 19801
Work Schedule:
This position is primarily scheduled Monday through Friday, with core business hours of 8:00am to 5:00pm.
While the standard schedule falls within these hours, the role offers flexibility in start times. Employees may begin their workday as early as 6:00am or as late as 8:00am, with corresponding adjustments to their end time.
On-Call Expectations:
This role requires participation in a rotating on-call support schedule approximately once every six to eight weeks.
When assigned on-call duty, employees are expected to be available from 5:00pm to 8:00am on weekdays, and 24/7 on weekends and holidays.
On-call responsibilities are limited to production-related emergencies and may involve little to no activity during a given rotation. However, candidates should be comfortable being available outside of normal business hours and responding to critical issues when needed.
All on-call responsibilities are performed remotely, allowing employees to respond to production issues without traveling to the office.