TC-CS-IAM-RSA Implementation-Manager

at EY

Location:

Employment Type: full_time


Job Description

<p><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px">At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. </span></span></p><p> </p><p> </p><p> </p><p> </p><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">RSA Implementation:</span></strong></p><p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">As a Senior Developer, you will lead connector development, workflow orchestration, and application onboarding within RSA Identity Governance &amp; Lifecycle (IGL / RSA Via). You’ll build scalable integrations to enterprise and cloud systems, design approval and provisioning workflows, optimize collections and certifications, and enforce governance policies (RBAC/SoD) across complex environments.</span></p><p> </p><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Key Responsibilities</span></strong></p><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Connector Development (AFX &amp; Custom Integrations)</span></strong></p><p> </p><ul><li style="list-style-type:none"><ul><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Design, develop, and maintain provisioning and deprovisioning connectors using AFX (Aveksa Fulfillment Express), including:</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Out-of-the-box (OOTB) connectors: AD/LDAP, Databases (JDBC), SAP, ServiceNow, Azure AD, AWS, G Suite, O365.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Web Service connectors: REST/SOAP with OAuth2/JWT/API keys.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Scripting-based connectors: PowerShell, SSH, Unix shell, Python for on-prem targets.</span></li></ul></li></ul><p style="font-weight:bold"> </p><p style="font-weight:bold"><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Build Collectors for data aggregation (accounts, groups, entitlements) from applications using:</span></strong></p><ul><li style="list-style-type:none"><ul><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">JDBC (Oracle, SQL Server, MySQL), LDAP, Flat files/SFTP, REST APIs.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Implement attribute mappings, transformation rules, and correlation logic (user-to-account, multi-attribute matching, fuzzy logic as needed).</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Handle delta/ incremental collections, error handling, retries, and idempotency.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Secure credentials and secrets via vaulting or platform key stores; apply least-privilege for connector service accounts.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Performance tune connectors: paging, throttling, parallelism, connection pooling, and API rate-limit strategies.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Document runbooks, deployment steps, and rollback procedures.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Workflow Design &amp; Orchestration</span></li></ul></li></ul><p> </p><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Build business workflows for:</span></strong></p><ul><li style="list-style-type:none"><ul><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Joiner–Mover–Leaver (JML) lifecycle automation.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Access requests / approvals (multi-level, manager/owner/risk-based).</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Provisioning workflows with branching (success, failure, rollback, re-try).</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Emergency access (firefighter) requests with time-bound access and post-use review.</span></li></ul></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Configure Change Request (CR) rules, rule sets, and task handlers.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Implement dynamic approval routing (manager DAC, entitlement owner, application owner, SoD compensating control approvers).</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Integrate with ticketing/ITSM (ServiceNow/Jira) for fulfillment tasks and status sync.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Add notifications/SLAs (reminders, escalations, auto-approvals/auto-revokes with justification capture).</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Ensure auditable trails: request provenance, approver comments, task logs, and evidence.</span></li></ul><p> </p><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Application Onboarding &amp; Governance</span></strong></p><ul><li style="list-style-type:none"><ul><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Drive end-to-end onboarding: authoritative sources, applications, accounts, entitlements, ownership, and risk scoring.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Establish role models (enterprise roles, IT roles), entitlement catalogs, and birthright access.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Define and maintain SoD policies (conflict matrices, rule libraries), exception workflows, and compensating controls.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Configure and run Access Certification Campaigns (manager, app owner, role owner, SoD remediation).</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Implement data quality checks: orphan accounts, toxic combinations, excessive privilege detection.</span></li></ul></li></ul><p> </p><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Operations, Hardening &amp; Performance</span></strong></p><ul><li style="list-style-type:none"><ul><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Schedule collections, provisions, certifications; monitor job queues and AFX tasks.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Patch and upgrade RSA IGL components; validate customizations post-upgrade.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Implement backup/restore, DR, and high availability patterns.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Deliver KPIs: request SLA adherence, provisioning success rate, collection freshness, certification completion %, SoD violations trend.</span></li></ul></li></ul><p> </p><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Day to Day Deliverables</span></strong></p><ul><li style="list-style-type:none"><ul><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Connector specification (interfaces, auth, payloads, mappings, error taxonomy).</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Workflow definitions (BPM diagrams, approver logic, SLAs, escalation paths).</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Data model mapping (source → person → account → entitlement).</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Test assets: unit tests for scripts, UAT scenarios, negative tests, performance tests.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Deployment artifacts: packages, encryption keys, environment configs.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Operational documentation and handover runbooks.</span></li></ul></li></ul><p> </p><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Technical Stack &amp; Environment</span></strong></p><ul><li style="list-style-type:none"><ul><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">RSA IGL Core: Lifecycle, Governance, Access Requests, Certifications, Policies, AFX, Collectors.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Programming/Scripting: Java, Groovy (where applicable), PowerShell, Python, Bash.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Integrations: REST/JSON, SOAP/XML, JDBC, LDAP, SFTP, OAuth2/OIDC/SAML.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Databases: Oracle / SQL Server (schema tuning, indexes, partitioning guidance).</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Infra/App Server: Linux-based deployment; JBoss/WildFly/WebLogic (as per customer stack).</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Directories/Clouds: AD/LDAP, Entra ID (Azure AD), Okta (as target/peer), AWS IAM, GCP, SAP.</span></li></ul></li></ul><p> </p><p> </p><p><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"><b>EY | Building a better working world </b></span></span></p><p><br><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"> <br>EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.  </span></span></p><p><br><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"> <br>Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.  </span></span></p><p><br><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"> <br>Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.  </span></span></p>