Lead IAM service support and strategy, designing secure systems and architectures that mitigate cyber risks while collaborating with various stakeholders.
Company Description
NBCUniversal is one of the world's leading media and entertainment companies. We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our global theme park destinations, consumer products, and experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, NBC Sports, Telemundo, NBC Local Stations, Bravo, and Peacock, our premium ad-supported streaming service. We produce and distribute premier filmed entertainment and programming through our powerhouse film and television studios, including Universal Pictures, DreamWorks Animation, and Focus Features, and the four global television studios under the Universal Studio Group banner, and operate industry-leading theme parks and experiences around the world through Universal Destinations & Experiences, including Universal Orlando Resort, home to Universal Epic Universe, and Universal Studios Hollywood. NBCUniversal is a subsidiary of Comcast Corporation. Visit www.nbcuniversal.com for more information.
Our impact is rooted in improving the communities where our employees, customers, and audiences live and work. We have a rich tradition of giving back and ensuring our employees have the opportunity to serve their communities. We champion an inclusive culture and strive to attract and develop a talented workforce to create and deliver a wide range of content reflecting our world.
Job Description
Join the NBCUniversal Operations and Technology (O&T) team and help drive strategy for the growing Identity and Access Management (IAM) service portfolio. The O&T IAM Architecture team is responsible for creating strategic solutions and setting the identity roadmap that supports the NBCUniversal enterprise and lines of business. This role is responsible for IAM service support and strategy. You'll be responsible for evaluating and developing on-prem and cloud-based IAM services with the goal of reducing cyber risk where our personas, devices, and applications consume identity. Successful candidates will couple an advanced technical mindset with a balanced solution approach, while applying knowledge, flexibility, and strong communication skills.
Responsibilities
Qualifications
Basic Requirements:
Desired Characteristics:
Additional Requirements:
Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee's residence.This position is eligible for company sponsored benefits, including medical, dental and vision insurance, 401(k), paid leave, tuition reimbursement, and a variety of other discounts and perks. Learn more about the benefits offered by NBCUniversal by visiting the Benefits page of the Careers website. Salary range: $110,000 - $135,000 . We are accepting applications for this position on an ongoing basis.
Additional Information
As part of our selection process, external candidates may be required to attend an in-person interview with an NBCUniversal employee at one of our locations prior to a hiring decision. NBCUniversal's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law.
If you are a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access nbcunicareers.com as a result of your disability. You can request reasonable accommodations by emailing [email protected].
For LA County and City Residents Only: NBCUniversal will consider for employment qualified applicants with criminal histories, or arrest or conviction records, in a manner consistent with relevant legal requirements, including the City of Los Angeles' Fair Chance Initiative For Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable.
NBCUniversal is one of the world's leading media and entertainment companies. We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our global theme park destinations, consumer products, and experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, NBC Sports, Telemundo, NBC Local Stations, Bravo, and Peacock, our premium ad-supported streaming service. We produce and distribute premier filmed entertainment and programming through our powerhouse film and television studios, including Universal Pictures, DreamWorks Animation, and Focus Features, and the four global television studios under the Universal Studio Group banner, and operate industry-leading theme parks and experiences around the world through Universal Destinations & Experiences, including Universal Orlando Resort, home to Universal Epic Universe, and Universal Studios Hollywood. NBCUniversal is a subsidiary of Comcast Corporation. Visit www.nbcuniversal.com for more information.
Our impact is rooted in improving the communities where our employees, customers, and audiences live and work. We have a rich tradition of giving back and ensuring our employees have the opportunity to serve their communities. We champion an inclusive culture and strive to attract and develop a talented workforce to create and deliver a wide range of content reflecting our world.
Job Description
Join the NBCUniversal Operations and Technology (O&T) team and help drive strategy for the growing Identity and Access Management (IAM) service portfolio. The O&T IAM Architecture team is responsible for creating strategic solutions and setting the identity roadmap that supports the NBCUniversal enterprise and lines of business. This role is responsible for IAM service support and strategy. You'll be responsible for evaluating and developing on-prem and cloud-based IAM services with the goal of reducing cyber risk where our personas, devices, and applications consume identity. Successful candidates will couple an advanced technical mindset with a balanced solution approach, while applying knowledge, flexibility, and strong communication skills.
Responsibilities
- Serve on a distributed security and technology team responsible for establishing IAM solutions.
- Lead the design and implementation of IAM capabilities including SSO, directory services, Zero Trust access, MFA, PAM, automation, and behavior-analytics systems.
- Craft resilient and scalable identity strategies that align with cybersecurity policies and governance structure
- Collaborate with stakeholders to define IAM requirements and design comprehensive solutions for business needs
- Develop highly scalable identity service architectures serving enterprise, customer access, and external partner requirements
- Produce technical solutions that meet NBCU's business objectives and drive compliance with NBCU's information security goals
- Partner with technology and security teams across NBCU to provide technical expertise, design guidance, and drive best practices
- Create and deliver effective presentations that inform NBCUniversal Senior Leadership teams to drive business relevant information security decisions
- Lead product evaluations and new technology adoptions
- Maintain strong vendor relationships that drive partnership with NBCU
- Create technical documentation with architecture diagrams, configuration guides and operational practices
- Make recommendations to improve automation efficiency, security practices and end user experience
- Execute tactical requests along with supporting strategic vision for rigorous and scalable IAM control
Qualifications
Basic Requirements:
- 5+ years' experience in an identity architecture role
- 5+ years' experience designing solutions in IAM technical role(s) for large enterprise
- Bachelor's degree or higher in computer science, information security, or a non-computer-related field, or equivalent work experience
- Strong communication and interpersonal skills; including negotiation, facilitation, and consensus building skills; Ability to influence, persuade, and manage polarities without direct control
- Significant experience designing initial infrastructure, administering IAM systems, access controls, security and risk management, and governance fundamentals
- Strong understanding of RBAC, identity policies, identity lifecycle automation and reporting, password policies, separation of duties, user provisioning, and approval workflows
- Experience working with modern and legacy enterprise authentication services (OpenID Connect (OIDC), OAuth2, SAML, Kerberos) and platforms (preferably Active Directory, Entra ID, AWS)
- Experience with Single-Sign-On, Multi-Factor Authentication (MFA), Passwordless Technologies, Privileged Access Management (PAM), and Public Key Infrastructure (PKI)
- Familiarity with one or more regulatory requirements and laws such as, but not limited to, PCI DSS, FFIEC, SOX, HIPAA, GDPR and GLBA. Additionally, experience in one or more: ISO 17799, ITIL, NIST
- Understanding of cloud computing architecture, technical design and implementations, including IaaS, PaaS and SaaS models
- High degree of flexibility and ability to work with employees at all levels of the organization with diverse backgrounds
- Makes wise, data-informed decisions, finds and owns problems to closure
- Ability to balance the long-term big picture and short-term implications of tactical decisions
- Possesses an innovative technical mindset with a focus on architecture, strategy, and design
- Strong desire to drive change
Desired Characteristics:
- Experience architecting and delivering large-scale Enterprise IAM service instances
- Experience with enterprise directory architecture, including significant knowledge of Active Directory and Entra ID
- Experience developing and delivering Zero Trust architectural designs
- Experience with Venafi / Netwrix / CyberArk
- Experience with Google Cloud Platform (GCP) and Amazon Web Services (AWS)
- Experience with large-scale ID Verification solutions for Enterprise and Consumer Identity solutions
- A current cybersecurity professional certification such as CISSP, CCSP, GSEC, or GISP
- Preferably one or more Azure certifications, such as AZ-900, AI-900, AZ-500, SC-300, or AZ-305
- Knowledge of integrating AI agents with identity providers and applying governance to their access and lifecycle management.
- Apply AI-driven analytics to strengthen identity governance, enable intelligent access decisions, detect anomalous behavior, and optimize end-to-end IAM workflows
Additional Requirements:
Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee's residence.This position is eligible for company sponsored benefits, including medical, dental and vision insurance, 401(k), paid leave, tuition reimbursement, and a variety of other discounts and perks. Learn more about the benefits offered by NBCUniversal by visiting the Benefits page of the Careers website. Salary range: $110,000 - $135,000 . We are accepting applications for this position on an ongoing basis.
Additional Information
As part of our selection process, external candidates may be required to attend an in-person interview with an NBCUniversal employee at one of our locations prior to a hiring decision. NBCUniversal's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law.
If you are a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access nbcunicareers.com as a result of your disability. You can request reasonable accommodations by emailing [email protected].
For LA County and City Residents Only: NBCUniversal will consider for employment qualified applicants with criminal histories, or arrest or conviction records, in a manner consistent with relevant legal requirements, including the City of Los Angeles' Fair Chance Initiative For Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable.
Top Skills
Active Directory
Automation
AWS
Azure
Entra Id
Google Cloud Platform
Iam
Kerberos
Mfa
Oauth2
Openid Connect
Pam
SAML
Sso
Similar Jobs at NBCUniversal
AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
The Lead Technical GRC Analyst will manage NBCUniversal's security governance framework, while supporting IT cyber governance processes, conducting technical assessments, and collaborating with stakeholders to ensure effective security measures.
Top Skills:
Active DirectoryArcherAzure AdCisIso 27001M365Microsoft Defender For CloudNistOnetrustServicenow GrcSlack
AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
This role involves leading the design and implementation of SAP SuccessFactors solutions, managing technical teams, and establishing governance standards to align technology strategy with business goals.
Top Skills:
APIsBusiness Application StudioBw/4HanaFieldglassIntegration SuiteJava ConnectorsRestful Abap ProgrammingSacSap BtpSap BwSap Successfactors
AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
The Sr. Business Analyst will execute HR strategies focusing on Recruiting and Onboarding solutions, collaborating with teams and configuring applications like SuccessFactors.
Top Skills:
ClickboardingSap BtpSap HcmSmartrecruitersSuccessfactors
What you need to know about the Seattle Tech Scene
Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.
Key Facts About Seattle Tech
- Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Amazon, Microsoft, Meta, Google
- Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
- Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Madrona, Fuse, Tola, Maveron
- Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute
.png)
.png)