We are excited that you are considering joining Nova Southeastern University!
Nova Southeastern University (NSU) was founded in 1964, and is a not-for-profit, independent university with a reputation for academic excellence and innovation. Nova Southeastern University offers competitive salaries, a comprehensive benefits package including tuition waiver, retirement plan, excellent medical and dental plans and much more. NSU cares about the health and welfare of its students, faculty, staff, and campus visitors and is a tobacco-free university.
We appreciate your support in making NSU the preeminent place to live, work, study and grow. Thank you for your interest in a career with Nova Southeastern University.
Primary Purpose:
Designs, implements, and supports the University's identity and access management (IAM) systems and processes to ensure secure, efficient, and compliant access to institutional resources. Responsible for managing the identity lifecycle, authentication and authorization services, access provisioning, and security controls across academic, administrative, research, and clinical environments while supporting the University's cybersecurity, compliance, and operational objectives.
Job Category: Exempt
Hiring Range:
Pay Basis: Annually
Subject to Grant Funding? No
Essential Job Functions:
1. Designs, engineers, and operates the identity lifecycle, including automated joiner, mover, and leaver processing driven by authoritative systems of record for students, faculty, staff, affiliates, and contractors.
2. Responsible for single sign-on and federation services, including SAML and OpenID Connect integrations, application onboarding standards, InCommon and research federation participation, and attribute release governance.
3. Oversees multifactor authentication governance, including enrollment standards, policy scope and exceptions, phishing-resistant authentication adoption, recovery and bypass workflows, and lifecycle of authentication methods.
4. Designs and administers privileged access management, including privileged account discovery and inventory, vaulting, session management, just-in-time elevation, and elimination of standing administrative privilege.
5. Designs and maintains role-based access control and entitlement models, including role definition, entitlement cataloging, segregation of duties analysis, and access request and approval workflow.
6. Designs and operates periodic access certification and attestation campaigns for high-risk systems and privileged entitlements, and tracks revocations to completion.
7. Administers and secures directory services and identity platforms, including Microsoft Entra ID, Active Directory, and LDAP, and maintains identity data quality, matching, and reconciliation across systems.
8. Engineers automated provisioning and deprovisioning integrations, including SCIM and application programming interface-based connectors, to replace manual account administration.
9. Establishes governance for service accounts, application identities, machine identities, and non-human credentials, including ownership, rotation, and least-privilege scoping.
10. Manages identity for guest, affiliate, alumni, emeritus, and sponsored populations, including sponsorship, expiration, and reauthorization controls.
11. Produces access control evidence for internal and external audits, regulatory examination, sponsor requirements, and cyber insurance underwriting.
12. Partners with Information Technology Infrastructure, Enterprise Applications, Human Resources, the Registrar, and Research Administration to integrate identity services with authoritative and consuming systems.
13. Monitors identity-related risk and telemetry, including anomalous authentication, privilege escalation, dormant and orphaned accounts, and excessive entitlement, and drives remediation.
14. Develops and maintains identity architecture documentation, standards, procedures, and end-user guidance.
15. Completes special projects as assigned.
16. Performs other duties as assigned or required.
Job Requirements:
Required Knowledge, Skills, & Abilities: Knowledge:
1. Comprehensive knowledge of identity and access management concepts, including authentication, authorization, federation, provisioning, and access governance.
2. Comprehensive knowledge of directory services and identity platforms, including Microsoft Entra ID, Active Directory, and LDAP.
3. Working knowledge of federation protocols and standards, including SAML 2.0, OpenID Connect, OAuth 2.0, and SCIM.
4. Working knowledge of privileged access management concepts and platforms, including vaulting, session management, and just-in-time elevation.
5. Working knowledge of identity governance and administration practices, including role mining, entitlement management, segregation of duties, and access certification.
6. Working knowledge of multifactor authentication technologies, including phishing-resistant methods such as FIDO2 and passkeys.
7. Working knowledge of audit and regulatory expectations for access control, including HIPAA, PCI-DSS, GLBA, and NIST SP 800-171 requirements.
8. Familiarity with higher education identity practices, including InCommon, Shibboleth, eduPerson, and student information system integration.
Skills:
1. Complex Problem Solving – Proficient skills in identifying complex problems and reviewing related information to develop and evaluate options and implement solutions.
2. Automation and Scripting – Proficient skills in scripting and automation using PowerShell, Python, or comparable languages, and in working with application programming interfaces.
3. Systems Integration – Proficient skills in connecting identity platforms to authoritative and consuming systems reliably and repeatably.
4. Data Analysis – Proficient skills in analyzing entitlement, account, and authentication data to identify risk and reconcile discrepancies.
5. Documentation – Proficient skills in producing architecture, procedural, and end-user documentation.
Abilities:
1. Ability to assume ownership of a distributed function and consolidate it into a governed, documented service.
2. Ability to balance access control rigor against the operational needs of academic, clinical, and research communities.
3. Ability to coordinate change across departments that share responsibility for identity data and systems.
4. Ability to handle privileged credentials and sensitive access data with discretion and integrity.
5. Ability to plan and execute access changes affecting large populations with minimal disruption.
Physical Requirements and Working Environment:
1. Speech Recognition - Must be able to identify and understand the speech of another person.
2. Speech Clarity - Must be able to speak clearly so others can understand you.
3. Near Vision - Must be able to see details at close range (within a few feet of the observer).
4. Travel - Must be able to travel on a daily and/or overnight basis.
5. May be required to work nights or weekends.
6. May be exposed to short, intermittent, and/or prolonged periods of sitting and/or standing in performance of job duties.
7. May be required to accomplish job duties using various types of equipment/supplies, to include but not limited to pens, pencils, and computer keyboards.
Required Certifications/Licensures:
Required Education: Bachelor’s degree.
Major (if required:
Required Experience: Minimum four (4) to six (6) years’ experience in information technology including identity and access management engineering or administration.
Experience with directory services, single sign-on and federation, and automated provisioning.
Preferred Qualifications:
1. Experience in higher education, including InCommon federation, Shibboleth, and student information system identity integration.
2. Experience implementing an identity governance and administration or privileged access management platform.
3. Experience automating joiner, mover, and leaver processes at enterprise scale.
4. Experience supporting access control audit and attestation requirements in a regulated environment.
5. Experience with Workday, Banner, or comparable authoritative systems of record.
Is this a safety sensitive position? No
Background Screening Required? Yes
Pre-Employment Conditions:
Sensitivity Disclaimer: Nova Southeastern University is in full compliance with the Americans with Disabilities Act (ADA) and does not discriminate with regard to applicants or employees with disabilities and will make reasonable accommodation when necessary.
NSU is an Equal Opportunity Employer and considers applicants for all positions without regard to race, color, religion, creed, gender, national origin, age, disability, marital or veteran status or any other legally protected status.
We use cookies.
Some are necessary to operate the website and its functions. Others help personalize, improve content and services to show you the most relevant job opportunities. With the decision "Accept essential only" we will respect your privacy and will not set cookies that aren't necessary for the operation of the site.