Cloud Engineer Identity and Access Management

at  Spektrum

Brussels, Région de Bruxelles-Capitale - Brussels Hoofdstedelijk Gewest, Belgium -

Start DateExpiry DateSalaryPosted OnExperienceSkillsTelecommuteSponsor Visa
Immediate01 Sep, 2024Not Specified02 Jun, 2024N/AAutomation Tools,Regulatory Standards,Communication Skills,Groups,Analytical Skills,Azure Active Directory,Training,Security,Collaboration,Access Control,AdherenceNoNo
Add to Wishlist Apply All Jobs
Required Visa Status:
CitizenGC
US CitizenStudent Visa
H1BCPT
OPTH4 Spouse of H1B
GC Green Card
Employment Type:
Full TimePart Time
PermanentIndependent - 1099
Contract – W2C2H Independent
C2H W2Contract – Corp 2 Corp
Contract to Hire – Corp 2 Corp

Description:

Spektrum have a wide range of exciting opportunities in several global locations.
We are always looking to add great new talent to our team and look forward to hearing from you.
Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects.

WHO WE ARE SUPPORTING

The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO’s member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium.

The NCIA provides a wide range of services, including:

  • Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO’s communication networks and information systems against cyber threats.
  • Command and Control Systems: The NCIA develops and maintains the systems used by NATO’s military commanders to plan and execute operations.
  • Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.
  • Electronic Warfare: The NCIA provides electronic warfare services to support NATO’s mission to detect, deny, and defeat threats to its communication networks.
  • Information Management: The NCIA manages NATO’s information technology infrastructure, including its databases, applications, and servers.

Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO’s communication and information technology capabilities.

ESSENTIAL SKILLS AND EXPERIENCE

Technical Expertise:

  • In‐depth knowledge of Microsoft Entra ID (Azure Active Directory) and Amazon AWS identity and access management services.
  • Proficiency in PowerShell scripting and automation tools (e.g., Azure Automation, Microsoft Graph API).
  • Experience with IAM solutions and tools, including role‐based access control RBAC), multi‐factor authentication (MFA), and conditional access policies.
  • Expertise in Azure AD Privileged Identity Management (PIM) and privileged access control.

Analytical and Problem‐Solving Skills:

  • Strong analytical skills to assess and improve IAM processes and workflows.
  • Ability to troubleshoot complex IAM issues and implement effective solutions.

Security and Compliance Knowledge:

  • Understanding of security best practices and compliance requirements related to identity and access management.
  • Experience conducting audits and ensuring adherence to regulatory standards.

Communication and Collaboration:

  • Excellent communication skills to effectively collaborate with IT teams, stakeholders, and end‐
  • Ability to document processes clearly and provide training on IAM tools and practices.

Organizational Skills:

  • Strong organizational skills to manage multiple tasks and priorities effectively.
  • Attention to detail in managing user accounts, groups, and access controls.

Team Collaboration:

  • Ability to work effectively as part of a team and share knowledge and resources.
  • Willingness to collaborate with colleagues to solve complex issues.

Others:

  • They have strong customer relationship skills, including negotiating complex and sensitive situations under pressure.
  • They must have the nationality of one of the NATO nations.

Responsibilities:

ROLE BACKGROUND

Supporting NATO throughout all its geographical locations, the NCI Agency is looking for a Cloud Engineer (Remote), Identity and Access Management, joining the journey of NATO’s modernisation of IT services, through leveraging the public cloud (Microsoft Azure, M365 and Amazon AWS), delivering managed, protected, security‐centric and reliable IT Services.
NCI Agency – Cloud Operations Team
The NATO Communications and Information Agency (NCI Agency) is dedicated to supporting NATO’s strategic objectives, including the ambitious NATO 2030 agenda. As part of this commitment, we are spearheading the modernization and digital transformation of NATO’s IT services. Our focus is on leveraging public cloud technologies like Microsoft 365 and Intune, incorporating a security‐by‐design approach, and ensuring a seamless transition to a modern, collaborative workplace environment.
To achieve these goals, we are building a Cloud Operations team under the Cloud Center of Excellence, operating under the NATO Enterprise Cloud Operating Model (NECOM). The NECOM framework provides a standardized approach for cloud service management, ensuring interoperability, scalability, and security across NATO’s IT infrastructure. The Cloud Center of Excellence will serve as a hub for best practices, innovation, and expertise, driving the adoption and optimization of cloud technologies within NATO. This team will play a crucial role in our journey towards providing managed, protected, and reliable End User Services.
Embracing the latest technological advancements, this initiative will foster innovation and ensure NATO remains at the cutting edge of IT capabilities. By continuously evolving and integrating new technologies, we aim to enhance operational efficiency and readiness for future challenges. This remote position offers an exciting opportunity to be at the forefront of NATO’s technological evolution and contribute to the security and efficiency of our operations.
NCI Agency – Cloud Centre of Excellence (CCoE)
The Cloud Centre of Excellence (CCoE) within the NCI Agency is focused on driving successful cloud adoption and maximizing the potential of cloud technologies across the organization. It serves as a central governing body, promoting best practices, enabling knowledge sharing, and ensuring alignment between business objectives and cloud initiatives. The CCoE supports various cloud‐ based solutions, ensuring their effective and efficient implementation and management. By fostering a culture of continuous improvement and innovation, the CCoE helps the NCI Agency leverage cloud technologies to enhance operational efficiency, scalability, and agility.
The ideal candidate will have expertise in Entra ID, AWS IAM, PowerShell scripting, RBAC, MFA, and conditional access policies. Strong analytical, problem‐solving, and organizational skills are required, along with the ability to document processes and provide training on IAM tools and practices.
This role is critical for maintaining a secure and efficient IAM environment, supporting internal users and external collaborators. If you are a motivated IAM specialist passionate about security, automation, and multi‐cloud environments, we invite you to apply and join our dynamic team.

ROLE DUTIES AND RESPONSIBILITIES

Design and Implement IAM Solutions:

  • Design, implement, and manage identity and access management solutions using Microsoft Entra ID (Azure AD) and Amazon AWS.
  • Ensure seamless integration with internal and external applications and systems.

Automate Account and Group Management:

  • Develop and deploy PowerShell scripts and Azure Automation workflows to automate user account and group management tasks.
  • Implement self‐service capabilities for account and group management to improve efficiency.

Manage Account Lifecycle:

  • Oversee the entire account lifecycle management process, from user onboarding to offboarding.
  • Provision new accounts and assign appropriate access rights based on role requirements.
  • Regularly review and update user roles and permissions to reflect changes in job functions and organizational structure.
  • Deprovision accounts promptly when users leave the organization or change roles, ensuring removal of access rights.
  • Implement role‐based access control (RBAC) to manage permissions based on job roles.
  • Conduct periodic access reviews and certifications to ensure compliance with organizational policies.

Privileged Identity Management:

  • Implement and manage Azure AD Privileged Identity Management (PIM) to control, monitor, and audit privileged access to resources.
  • Configure PIM to enforce just‐in‐time (JIT) access, approval workflows, and access reviews for privileged roles.

Security and Compliance:

  • Implement security best practices and ensure compliance with relevant standards and regulations.
  • Conduct regular audits and reviews of access controls and permissions.

User Support and Troubleshooting:

  • Provide support for IAM‐related issues, including troubleshooting user access problems and resolving authentication issues.
  • Act as an escalation point for complex IAM issues.
  • Maintain comprehensive documentation for IAM processes, configurations, and workflows.
  • Provide training and support to IT staff and end‐users on IAM best practices and tools.

Monitor and Optimize IAM Systems:

  • Monitor the performance and effectiveness of IAM systems and processes.
  • Identify opportunities for improvement and implement optimizations to enhance security and efficiency.

Collaboration and Communication:

  • Collaborate with IT security, compliance, and other relevant teams to ensure cohesive IAM strategies.
  • Communicate effectively with stakeholders to understand IAM requirements and address concerns.

External Collaboration and Sharing:

  • Manage external collaboration and sharing settings in Azure AD to facilitate secure access for partners and external users.
  • Implement and manage B2B (Business to Business) collaboration settings and policies through Entra ID.
  • Integrate and manage identity and access management for B2B scenarios, ensuring seamless and secure interactions with external partners.

AWS Integration:

  • Integrate and manage IAM processes with Amazon AWS, ensuring secure access and interoperability between Azure AD and AWS.
  • Implement and manage federated identities and single sign‐on (SSO) between Azure AD and AWS environments.
  • Monitor and optimize IAM configurations to ensure compliance and security across multi‐cloud environments.

Automation and Efficiency:

  • Develop and implement automation scripts using PowerShell to streamline routine support tasks such as software installations, updates, and system checks.
  • Utilize Power Automate to create workflows that automate repetitive tasks and improve service efficiency.
  • Identify opportunities to enhance efficiency through automation and proactively implement solutions.

Communication and Collaboration:

  • Communicate effectively with users to understand their issues and provide clear instructions.
  • Collaborate with IT teams to resolve issues and improve service delivery.


REQUIREMENT SUMMARY

Min:N/AMax:5.0 year(s)

Information Technology/IT

IT Software - Network Administration / Security

Software Engineering

Graduate

Proficient

1

Brussels, Belgium