Senior Security Analyst – Customer Identity & Access Management (CIAM)
Role summary
ServicePoint is seeking a Senior Security Analyst specializing in Customer Identity & Access Management (CIAM) for a 3-month contract-to-hire role in Arlington, TX. This onsite position focuses on securing, administering, and enhancing customer-facing identity platforms, including Ping Identity technologies, SSO, MFA, and managing the full customer identity lifecycle. The role also involves security administration of Active Directory, Privileged Access Management (PAM), vulnerability management, and incident response. The ideal candidate is a CIAM SME with strong technical expertise, ownership, and the ability to independently manage complex initiatives. Collaboration with various IT teams is essential, and participation in an on-call rotation is required.
Senior Security Analyst – Customer Identity & Access Management (CIAM)
Location: Arlington, TX (100% onsite)
Type: 3-Month Contract-to-Hire
Schedule: Monday–Friday, standard business hours
About the Role
ServicePoint is supporting a client seeking a Senior Security Analyst – Customer Identity & Access Management (CIAM). This senior-level cybersecurity role focuses on securing, administering, and enhancing customer-facing identity, authentication, and access management platforms.
As a CIAM subject matter expert (SME), you will lead initiatives supporting external users, applications, and digital services, while also contributing to broader security efforts including vulnerability management, network and email security, and Privileged Access Management (PAM).
The ideal candidate demonstrates deep technical expertise in enterprise identity systems, strong ownership, and the ability to independently manage complex security initiatives and investigations. This role requires close collaboration with Application Development, IT Operations, Infrastructure, Network, and Risk teams to deliver secure, scalable, and compliant identity solutions. Participation in an on-call rotation is required.
Key Responsibilities
Customer Identity & Access Management (Primary Focus)
Design, implement, and manage CIAM solutions for external users and digital platforms.
Administer and support Ping Identity technologies, including Ping Directory (on-prem), PingFederate (on-prem), and PingOne MFA (cloud-based).
Manage authentication services such as single sign-on (SSO), federation, and OAuth/OpenID Connect integrations.
Implement and maintain enterprise Multi-Factor Authentication (MFA) solutions.
Secure the full customer identity lifecycle, from registration through de-provisioning.
Investigate and remediate identity-related security incidents, including fraud and anomalous access.
Active Directory & Directory Services
Provide security-focused administration of Microsoft Active Directory.
Manage authentication mechanisms, group-based access, and privileged accounts.
Support account lifecycle management, access reviews, and identity security controls.
Partner with infrastructure teams on Active Directory hardening and best practices.
Assist in investigations involving credential compromise or misuse.
Privileged Access Management (PAM)
Oversee privileged access across identity platforms and administrative roles.
Enforce least-privilege and role-based access controls.
Monitor privileged activity and support incident response and forensic analysis.
Provide audit reporting and access control documentation.
Vulnerability Management & Security Operations
Support vulnerability management efforts across identity and authentication systems.
Analyze risks and coordinate remediation with cross-functional teams.
Act as a senior escalation point for complex identity and access issues.
Lead CIAM and identity security initiatives.
Mentor junior analysts and provide technical guidance.
Maintain documentation, standards, and procedures.
Participate in a rotating on-call schedule.
Network & Email Security
Support identity-related integrations for VPNs and secure access solutions.
Assist in investigations related to phishing, credential abuse, and account compromise.
Collaborate with Network and Messaging teams to strengthen access controls.
Job Type: Contract
Pay: $50.00 - $55.00 per hour
Expected hours: 40 per week
Work Location: In person