This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Senior Identity and Access Management Lead will be responsible for implementing, operating, and maintaining Authorization Platform designed to securely manage and control the connection between digital identities and assets across the enterprise. This role requires high-level business acumen coupled with deep technical knowledge of identity management products and system design principles. In addition to being technically proficient, the candidate should have exceptional time management and communication skills.
Job Responsibility:
Review the design for Modern Policy Based Access Control Authorization (PBAC) infrastructure with architecture and engineering teams
Deploy system capabilities incrementally and provide user authentication, SSO, federation, Role-Based and Attribute-Based Access Control
Manage auditing and reporting capabilities that are integrated with Citi enterprise logging and monitoring tools
Conduct work on a variety of high-impact, high-profile problems/projects such as creating complex project plans and conducting project-related research
Provide in-depth and sophisticated analyses, technical guidance and direction and identify and monitor key indicators to gauge performance and identify trends
Identify and resolve issues, engaging in Root Cause Analysis (RCA)
Conduct responsibilities such as quality control, work allocation, coaching/mentoring, ensuring ongoing compliance with regulatory requirements
Appropriately assess risk when business decisions are made, demonstrating consideration for the firm's reputation and safeguarding Citigroup, its clients, and assets, by driving compliance with applicable laws, rules and regulations, adhering to Policy, applying sound ethical judgment regarding personal behavior, conduct and business practices, and escalating, managing and reporting control issues with transparency
Understand diverse stakeholder needs and share and influence stakeholder expectations
Requirements:
10+ years of experience implementing, operating, and maintaining access management solutions supporting single sign-on
5+ years of experience in implementing a Modern Policy Based Access Control Authorization (PBAC) Methodology leveraging user Attributes to Enforce Access Controls According to Business Policies Dynamically
Deep understanding of Zero Trust & Secure Access Service Edge (SASE) technologies
Demonstrated experience with authentication and authorization technologies and protocols such as SAML, WS-Fed, OAuth, OpenID/OpenID Connect, one-time passcodes, PKI, derived credentials, FIDO, PBAC, RBAC
Strong knowledge of containerization technologies such as Docker and container orchestration with Kubernetes
Experience in managing projects, leading operational process change and improvement and delivering infrastructure technologies products and services
Experience in financial services or large complex and/or global environment preferred
Experience developing projects for the identification of best practices (design of metrics, analytical tools, benchmarking activities, and related reporting)
Consistently demonstrate clear and concise written and verbal communication with ability to communicate technical concepts to a non-technical audience
Proven analytical, diagnostic, and multitasking skills with focus on execution and attention to detail
Demonstrated ability to both work independently and partner with virtual teams in a high-pressure matrix environment
Demonstrated ability to take ownership of various parts of a project/initiative with tight deadlines or unexpected changes in expectation/ requirements
Bachelor's degree/University degree or equivalent experience
Nice to have:
Experience in financial services or large complex and/or global environment preferred