ForgeApply · Job listing
Security Senior Analyst – Identity Security Engineering
Elevance Health
See all 233 open roles at Elevance Health →
Tailor your resume for this Elevance Health job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Elevance Health's site. Free trial, no card required.
About this role
Anticipated End Date: 2026-09-18 Position Title: Security Senior Analyst – Identity Security Engineering Job Description: Security Senior Analyst – Identity Security Engineering
Location: This role requires associates to be in-office 1 day per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace. Ideal candidates will be able to report to one of our Pulse Point locations in Indianapolis, IN or St. Louis, MO. Alternate locations may be considered if candidates reside within a commuting distance from an office.
Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.
The Security Senior Analyst – Identity Security Engineering is responsible for engineering and operating identity security controls across human, privileged, non-human, cloud, and emerging agentic AI identities. The role has a primary focus on CyberArk Idira Endpoint Privilege Manager (EPM), with supporting responsibilities across CyberArk PAM and PSM capabilities, and helps advance least privilege, Just-in-Time access, Zero Standing Privilege, software control, and privileged access governance. This role partners with IAM, Identity Governance, Cyber Security, Cloud Security, Infrastructure, ServiceNow, and application teams to design, automate, monitor, and continuously improve secure access while supporting operational, audit, compliance, and 24x7 service requirements.
How you will make an impact: • Engineers and operates CyberArk Idira EPM, including policy design, application control, software-installation governance, temporary elevation, agent health, and troubleshooting.
• Supports CyberArk PAM and PSM capabilities, including privileged credentials, session controls, emergency access, and JIT/ZSP use cases.
• Translates business and security requirements into RBAC, ABAC, policy-based, risk-based, and time-bound access controls.
• Supports identity governance processes, including access requests, approvals, provisioning, certification, revocation, segregation of duties, and exception management.
• Extends identity security controls across workforce identities, privileged accounts, service and workload identities, NHIs, cloud identities, and agentic AI identities.
• Integrates CyberArk capabilities with ServiceNow, SailPoint, directories, CMDB, and cloud platforms using supported APIs and workflow automation.
• Automates identity discovery, directory queries, entitlement analysis, reconciliation, telemetry, reporting, and audit evidence using secure and supportable engineering practices.
• Analyzes telemetry, audit records, and identity security events to identify misuse, policy gaps, access drift, and opportunities to reduce standing privilege.
• Develops testing plans, operational procedures, runbooks, metrics, and audit evidence while supporting incident investigation, root-cause analysis, and continuous improvement.
Minimum Requirements: • Requires a bachelor’s degree or equivalent combination of education and experience that would provide the knowledge to perform such work.
• Experience must include a minimum of 3 years of experience in a support and operations or design and engineering role in any of the following areas: access management or network security technologies, servers, networks, network communications, telecommunications, operating systems, middleware, disaster recovery, collaboration technologies, hardware/software support or other infrastructure services role; or any combination of education and experience, which would provide an equivalent background.
Preferred Skills, Capabilities and Experiences: • Three to five years of experience in Identity Security, IAM, PAM, IGA, access engineering, or security operations preferred.
• Hands-on experience with CyberArk Idira EPM; familiarity with CyberArk PAM, PSM, Privilege Cloud, or related privileged access technology preferred.
• Strong understanding of least privilege, JIT access, ZSP, Zero Trust, privileged-access tiering, and Identity Threat Detection preferred.
• Experience applying RBAC, ABAC, policy-based access, risk-based access, and role or entitlement design preferred.
• Understanding of Identity Governance processes, including joiner-mover-leaver lifecycle, access requests, certifications, segregation of duties, and exception governance preferred.
• Familiarity with NHI, workload, cloud, and agentic AI identities, including service accounts, secrets, certificates, and access controls in Microsoft Entra ID, AWS IAM, and Google Cloud preferred.
• Knowledge of IAM standards and protocols such as SAML, OAuth 2.0, OpenID Connect, SCIM, LDAP, Kerberos, and REST APIs preferred.
• Experience using scripting, query, workflow, or low-code tools to automate identity discovery, AD/LDAP queries, entitlement analysis, access lifecycle workflows, reporting, and audit evidence preferred.
• Strong foundation in identity-focused automation and orchestration, including APIs, AD/LDAP queries, data analysis, reusable workflows, logging, error handling, testing, version control, and secure credentials preferred.
• Experience supporting large, regulated, and highly available enterprise environments; relevant CyberArk, identity, cloud, or security certifications preferred.
Job Level: Non-Management Exempt Workshift:
Job Family: IFT > IT Security & Compliance Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health.
Who We Are Elevance Health is a health company dedicated
Salary insight
This posting doesn't disclose pay. Across 172 Indianapolis jobs with disclosed salaries on ForgeApply, the median is $105k.
See full Security Engineer salary data for Indianapolis →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Elevance Health role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior Security Analyst — OutSystems · Remote
- Senior Security Analyst — Bb Insurance · Daytona Beach, FL | Plano, TX
- Senior Security Analyst — Marathon Health · Remote
- Senior Security Analyst — Tmhcc · Texas - Houston (Corporate Office)
- Security Engineer — Application Security & Identity — Realchemistry · Boston - Massachusetts; Carmel - Indiana; Chicago - Illinois; Lambertville - New Jersey; Remote - USA
- Information Security Senior Engineer - Identity Governance — Equinix · Dallas Infomart Office DAI
- Senior Identity Security Engineer — Palantir · Palo Alto, CA
- Senior Identity Security Engineer — Palantir · Washington, D.C.
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Indianapolis · Browse all jobs
Free ATS checker · No Salary on the Job Posting? How to Find the Number Before You Interview