岗位描述
概要
安永信息安全团队正在招募新成员,以支持中国区的身份与访问管理(IAM)服务,满足该领域日益增长的业务及监管需求。如果您正在寻找一个能够展示您的 IAM 技能、经验以及解决复杂问题能力的职位,这是一个涉足 IAM 领域并与跨职能团队合作以满足内外部的 IAM 安全要求的绝佳机会。
关于此机会
身份与访问管理是安全性、数字化、云迁移、远程办公和运营效率的基础。这对 IAM 工程和团队提出了越来越高的要求。此外,来自法律法规和内部业务对 IAM 的需求不断增加,也对中国区的 IAM 能力提出了挑战。因此,我们正在扩大团队规模,该职位将成为中国区 IAM 团队的一员。
我们的业务刚刚启动一项雄心勃勃的增长战略,安永信息安全团队希望在中国的大连、上海、北京或重庆招聘人员来支持这一增长。
该职位将与中国区的客户参与团队以及全球的技术专家紧密合作,支持数字化赋能服务,结合领先技术与安永广泛的行业特定经验及专业服务知识。
主要职责
• 设计、维护和支持 Microsoft Entra ID、IDaaS(身份即服务)以及本地 Active Directory 服务。
• 实施和管理单点登录 (SSO)、多因素认证 (MFA)、条件访问、身份联合以及自动化配置。
• 能够使用 SAML、OAuth 2.0、OpenID Connect 和 SCIM 等协议集成应用程序。
• 维护 Active Directory 与 Entra ID 之间的混合身份同步。
• 支持 AD 工程设计,包括组策略、DNS、复制、委派、服务账户和安全加固。
• 使用 PowerShell、Microsoft Graph API 和其他平台 API 自动化 IAM 操作。
• 排查身份生命周期、认证、授权、同步和应用程序访问领域的问题。
• 实施最小权限原则和特权访问控制。
• 维护 IAM 文档、操作流程、监控和恢复能力。
• 支持安全审查、审计、IAM 项目以及与身份相关的事件响应。
• 参与轮值On-call待命。
技能和特质
在多个 IAM 领域拥有广泛的主题专业知识,如身份治理与管理、认证、授权、目录服务、客户端 IAM 服务、云 IAM 服务、公钥基础设施 (PKI)、数字证书生命周期管理、企业加密和密钥管理,以及特权身份管理。
深入了解 IAM 相关协议,如 SAML、SCIM、OpenID 和 OAuth。
深入了解联合身份验证和 SSO 概念及技术,特别是基于 ADFS 或类似身份产品集的解决方案。
深入了解 Microsoft Azure,特别是 Entra ID、条件访问、Azure MFA、Entra ID PIM 以及连接 Azure 与企业基础设施(本地)的架构设计。
拥有 CyberArk 或其他特权访问管理 (PAM) 解决方案的可证明经验。
理解云计算、技术设计和实施,包括基础设施即服务 (IaaS)、平台即服务 (PaaS) 和软件即服务 (SaaS) 交付模型。
深入了解目录技术(例如:Active Directory、AD LDS、Azure AD、LDAP 等)。
任职资格(必须具备)
计算机科学、信息系统、网络安全或相关领域的学士和/或硕士学位。
7 年以上 IT 技术领域实践经验。
3 年以上信息安全 - 身份与访问管理经验(详见技能部分)。
出色的解决问题能力,具有高度的求知欲。
拥有在关键、高可用性生产系统上工作的经验。
具有使用 AI 辅助开发工具以及构建 AI 代理或自动化工作流的实践经验。
能够将 AI 代理安全地与企业系统和 API 集成。
能够与地域分散的跨职能团队协作。
任职资格(理想具备)
优先考虑在以下一个或多个领域拥有额外安全工作经验和知识的候选人:
持有安全行业认证,包括但不限于 CISSP、SSCP、CISM、SANS GSEC、ECSA、ECSP 和 Security+。
优秀的客户服务和沟通(口头/书面)技巧。
强大的批判性思维和分析能力,以及“跳出框框”思考的能力。
能够在最少监督下独立工作或与团队合作。
强烈的团队合作精神,善于达成共识。
The opportunity
Identity and access management is foundational to security, digitalization, cloud migration, remote work and operational efficiency. This places growing demands on IAM engineering and teams. Moreover, the increasing requirements for the IAM coming from Law/regulations and internal business requirements, also questioning the IAM capabilities in China. Therefore, we are expanding the team, and this position will be member of the China IAM team.
Our business has just embarked on an ambitious growth strategy and EY Information Security team is looking to hire a resource, based in Dalian, Shanghai, Beijing, Chongqing, China to support that growth.
Working closely with our client engagement teams in China and with our technologists across the world, supports digitally enabled services that take advantage of leading technologies in concert with EY’s broad industry-specific experience and professional services knowledge.
Key responsibilities
• Engineer, maintain, and support Microsoft Entra ID, IDaaS, and on-premises Active Directory services.
• Implement and manage SSO, MFA, Conditional Access, identity federation, and automated provisioning.
• Integrate applications using SAML, OAuth 2.0, OpenID Connect, and SCIM.
• Maintain hybrid identity synchronization between Active Directory and Entra ID.
• Support AD engineering, including Group Policy, DNS, replication, delegation, service accounts, and security hardening.
• Automate IAM operations using PowerShell, Microsoft Graph API, and other platform APIs.
• Troubleshoot identity lifecycle, authentication, authorization, synchronization, and application-access issues.
• Implement least privilege and privileged access controls.
• Maintain IAM documentation, operational procedures, monitoring, and recovery capabilities.
• Support security reviews, audits, IAM projects, and identity-related incident response.
• Participating in support scheduled on-call rotation
Skills and attributes for success
• Broad subject-matter expertise in multiple IAM domains such as identity governance and administration, authentication, authorization, directory services, client IAM services, cloud IAM services, public key infrastructure, digital certificate lifecycle management, enterprise encryption and key management, and privileged identity management.
• In-depth experience with IAM related protocols such as SAML, SCIM, OpenID and OAuth.
• In-depth experience with Federation and SSO concepts and technologies particularly solutions based on ADFS, or similar identity product set.
• In-depth experience with Microsoft Azure, particularly Entra ID, Conditional Access, Azure MFA, Entra ID PIM and architecture designs connecting Azure to enterprise infrastructure (on-prem).
• Demonstrable experience of CyberArk or other Privileged Access Management solution experience
• Understanding of cloud computing, technical design and implementations, including Infrastructure as a Service (IaaS), Platform as a Service (PaaS) and Software as a Service (SaaS) delivery models.
• In-depth experience with directory technologies (e.g., active directory, AD LDS, Azure AD, LDAP, etc.).
Qualifications (Must Have)
• Bachelor's and/or master’s degree in computer science, Information Systems, Cybersecurity, or related field of study.
• 7+ years of practical experience in IT technical field.
• 3+ years of Information Security - Identity and Access Management experience as detailed in the skills section.
• Excellent problem-solving skills with a high degree of intellectual curiosity.
• Experience working on critical, highly available production systems.
• Practical experience using AI-assisted development tools and building AI agents or automated workflows.
• Ability to integrate AI agents securely with enterprise systems and APIs.
• Ability to work with geographically distributed and cross-functional teams.
Qualifications (Ideally)
Although not required, it is preferred that candidates possess additional working security experience and knowledge in one or more of the following areas:
• A security industry certification is required including but not limited to CISSP, SSCP, CISM, SANS GSEC, ECSA, ECSP, and Security+
• Excellent customer service and communication (oral / written) skills.
• Strong critical thinking and analytical skills and ability to think "out of the box".
• Able to work independently or with a team, under minimum supervision.
• Strong team player and consensus forming individual.