Role: Information Security Consultant | Location: Washington, DC | Job Type: Contract

Duties and Accountabilities:

The primary responsibilities of the Information Security Architect will include, but are not limited to, a combination of the following:

• Provide information security support to ICAM work group by specifying security requirements and recommend implementation options that are in line with the information security and technology standards.

• Work with project and development teams of new business solution to define information security requirements that are in line with the enterprise information security architecture.

• Maintain an up-to-date understanding of emerging trends in identity and access management, especially in the area of authorization and identity lifecycle management; apply new techniques and trends to design a centralized authorization framework, taking into consideration the business and IT environment.

• Interface with other ITS teams including, but not limited to, Certification and Accreditation, Security Engineering, Incident Response, and Event Management, to gather identified information security risks; develop risk profiles for enterprise-wide business applications and identify areas where existing security architecture requires change or development.

• Evaluate emerging authentication and authorization technologies for cloud and mobile applications. Test and integrate new IAM solutions with business applications.

• Document security architecture design review results and follow up on the implementation of recommended controls.

• Peer-review security architecture design artifacts produced by colleagues and provide feedback.

Selection Criteria:

1. Master’s degree in Computer Science or Information Systems with at least 5 years of relevant experience. (BS/BA is minimum education requirement with at least 7 years of relevant experience).

2. Preferably experience as an Information Security Professional designing secure solutions in an environment comprising of financial and trading systems, systems handling strictly confidential, personnel and proprietary information.

3. Demonstrated knowledge and experience of applying advanced modeling techniques in developing security architecture for enterprise-level business applications and data security.

4. Advanced experience in designing security architecture for provisioning interoperable and portable identities and credentials across multiple business applications and platforms, preferably in a federated environment, and experience with multi-factor authentication technologies systems (includes token, smart card, adaptive and biometric solutions).

5. Demonstrated knowledge in Identity and Access Management (IAM), Collaboration, Account Provisioning, Role Engineering, Federation Services, etc. on common platforms such as MS SharePoint 2013. Hands-on experience in supporting Identity and Access Management products would be an added advantage.

6. Sound knowledge of designing secure interfaces between heterogeneous systems using advanced web services such as SOAP, REST, JSON and defining data models, and security techniques on common database servers such as Oracle, MS SQL, and MongoDB.

7. Good understanding of OpenID Connect, SAML, OAuth and SCIM protocols.

Required Skills Identity and Access Management, Information Security;


