
IAM PAM & SSO Senior Analyst
- 🇺🇸 United States
- Hybrid
- Senior
- 1 day ago
- IAM
- Secrets Management
- System Design
- CyberArk
- Unix
- SQL
- LDAP
- RBAC
- SailPoint
- Oracle
- Zero Trust
- CISSP
- Equity
Strengthen Identity Security at USC
USC is expanding its Cybersecurity IAM capabilities to help protect the university's people, systems and information in an increasingly complex threat environment. As the IAM PAM & SSO Senior Analyst, you will play a key technical role in designing, implementing and supporting enterprise identity solutions across Privileged Access Management (PAM), Single Sign-On (SSO), Multi-Factor Authentication (MFA) and related Identity and Access Management (IAM) services.
This is an opportunity for an experienced IAM professional to work at the intersection of cybersecurity, identity engineering and enterprise technology within a major research university. You will partner with application, infrastructure and cybersecurity teams to deliver secure, scalable and reliable identity services while helping strengthen the technology foundation that supports USC's academic, research and operational mission.
The position reports to the PAM & SSO Services Manager and is based at USC's CAL location in a hybrid work environment.
Job Accountabilities
- Designs, implements, enhances, and maintains PAM, SSO, MFA, and related IAM solutions to support secure, reliable, and scalable identity services. Analyzes business and technical requirements to configure, integrate, and optimize IAM platforms that support authentication, authorization, and privileged access capabilities. Develops reusable technical standards, configurations, and implementation patterns that improve consistency, reliability, and operational supportability across IAM services.
- Partners with application and infrastructure teams to integrate enterprise systems with PAM, SSO, MFA, and related IAM services. Supports onboarding of new applications and services while ensuring adherence to established security and technical requirements.
- Troubleshoots and resolves complex issues involving identities, systems, access, accounts, authentication, authorization, entitlements, permissions, privileged access, and secrets management services. Analyzes system design weaknesses, integration challenges, and operational issues to determine appropriate solutions. Assesses impact, risk, and priorities to recommend and implement corrective actions, perform root cause analysis, and improve service reliability, security, and operational effectiveness.
- Performs platform administration activities including upgrades, patching, monitoring, tuning, maintenance, and system health assessments. Identifies opportunities to improve automation, operational efficiency, service availability, and user experience.
- Develops and maintains technical documentation, configuration standards, architecture artifacts, operational procedures, and support runbooks. Ensures documentation accurately reflects implemented solutions and supports consistent administration, troubleshooting, and ongoing maintenance of IAM services.
- Provides technical guidance and knowledge transfer to team members, operational support personnel, and technology stakeholders. Shares subject matter expertise and promotes adoption of established IAM standards, procedures, and best practices to improve operational effectiveness and service support.
- Encourages a workplace culture where all employees are valued, value others and have the opportunity to contribute through their ideas, words and actions, in accordance with the USC Code of Ethics.
- Researches emerging IAM technologies, vendor capabilities, and industry practices to identify service improvement opportunities. Recommends technical enhancements that strengthen the security, reliability, scalability, and supportability of identity services.
Minimum Qualifications
Great candidates for the position of IAM PAM & SSO Senior Analyst will meet the following qualifications:
- Bachelor's degree
- Bachelor's degree in Instruction Systems Technology Or Computer Science Or in related field(s)
- Combined experience/education as substitute for minimum education
- 4 years in Identity and Access Management.
- Combined experience/education as substitute for minimum work experience
- Hands-on technical experience in implementing and troubleshooting of IAM solutions (e.g., CyberArk, HashiCorp, Delinea/Thycotic, Microsoft Entra, ForgeRock, Shibboleth, Duo).
- Proficiency within a Unix command line.
- Proficiency working with data, with query languages (e.g., SQL) and working with Directories (e.g., LDAP).
- Proficiency with IAM concepts (e.g., PBAC, RBAC, AuthN vs AuthZ).
- Excellent written and verbal communication skills; comfortable driving requirements gathering, architectural discussions and project reporting with non-technical business stakeholders.
- Maintain technical documentation including architecture diagrams, decision records, and runbooks.
Preferred Qualifications
- 6 or more years of experience in Identity and Access Management.
- Hands-on experience with Identity Governance and Administration (IGA) platforms such as SailPoint IIQ or ISC and Saviynt.
- Experience with enterprise directory solutions such as Microsoft Entra and Oracle Unified Directory, as well as identity verification technologies such as Persona or 1Kosmos.
- Experience with IAM within higher education or another complex, decentralized environment such as healthcare, technology, media and telecommunications, or financial services.
- Understanding of Zero Trust architecture, identity-based attack techniques and modern IAM controls.
- Experience leading enterprise identity transformations or directory modernization programs, including large-scale migration from legacy platforms.
- Demonstrated ability to establish and gain visibility into service accounts and secrets across hybrid cloud and on-premises environments.
- Experience working with professional services firms, such as Big Four firms, and/or IAM software vendors.
- CISSP certification or similar.
In addition, the successful candidate must also demonstrate, through ideas, words and actions, a strong commitment toUSC’s Unifying Values of integrity, excellence, community, well-being, open communication, and accountability.
Salary and Benefits
The annual base salary range for this position is $124,765 - $154,478. When extending an offer of employment, the University of Southern California considers factors such as, but not limited to, the scope and responsibilities of the position, the candidate's work experience, education/training, key skills, internal peer equity, federal, state, and local laws, contractual stipulations, grant funding, as well as external market and organizational considerations.
To support faculty and staff well-being, USC provides benefits-eligible employees with a broad range of benefits and perks to help protect their and their dependents’ health, wealth, and future. These benefits are available as part of the overall compensation and total rewards package. You can learn more about USC’s comprehensive benefitshere.
Ready to Make an Impact?
If you are an experienced IAM professional looking to work at the intersection of cybersecurity, identity engineering and enterprise technology, consider joining USC's Cybersecurity IAM team. Apply today and bring your expertise to a role that will help strengthen secure access across one of the nation's leading research universities.
USC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, or any other characteristic protected by law or USC policy. USC observes affirmative action obligations consistent with state and federal law.
Addtional Education Requirements Combined experience/education as substitute for minimum educationAddtional Experience Requirements Combined experience/education as substitute for minimum work experience
Preferred Certifications: Certified Information Systems Security Professional (CISSP) certification or similar.
USC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, or any other characteristic protected by law or USC policy. USC observes affirmative action obligations consistent with state and federal law. USC will consider for employment all qualified applicants with criminal records in a manner consistent with applicable laws and regulations, including the Los Angeles County Fair Chance Ordinance for employers and the Fair Chance Initiative for Hiring Ordinance, and with due consideration for patient and student safety. Please refer to the Background Screening Policy Appendix D for specific employment screen implications for the position for which you are applying.
We provide reasonable accommodations to applicants and employees with disabilities. Applicants with questions about access or requiring a reasonable accommodation for any part of the application or hiring process should contact USC Human Resources by phone at (213) 821-8100, or by email at uschr@usc.edu. Inquiries will be treated as confidential to the extent permitted by law.
- Notice of Non-discrimination
- Employment Equity
- Read USC’s Clery Act Annual Security Report
- USC is a smoke-free environment
- Digital Accessibility
If you are a current USC employee, please apply to this USC job posting in Workday by copying and pasting this link into your browser:
https://wd5.myworkday.com/usc/d/inst/1$9925/9925$155118.htmldIAM PAM & SSO Senior Analyst · USC University of Southern California