Cloud Identity Security Analyst jobs in United States
cer-icon
Apply on Employer Site
company-logo

Southern Company · 2 days ago

Cloud Identity Security Analyst

Southern Company is a leading energy provider serving 9 million customers across the Southeast and beyond. They are seeking a Cloud Identity Security Analyst to assist in application integration, security hardening, and tenant management duties of the cloud identity team, primarily focusing on Microsoft Entra ID and Google Cloud Identity Platform.

EnergyNatural ResourcesNuclear
check
Growth Opportunities
badNo H1BnoteU.S. Citizen Onlynote

Responsibilities

Architecture, integration, lifecycle, and future planning for Microsoft Entra ID and Google Identity Platform identity providers
Creation and lifecycle of cloud-native identities such as Service Principals and App Registrations
Enforcing the principle of least privilege, especially in the area of AI integrations
Integration of applications using cloud-native identity protocols such as SAML, Oauth, or OpenID
Implementation of new security feature sets to address modern risks such as FIDO/Passkeys
Triage and escalation of cloud identity issues – with the technology and with individual business partners
Build automations where possible to facilitate repeat work or reporting within the cloud environments
Mentoring others in the area of IAM, cloud identity, and modern authentication principles and best practices
Serve as a trusted advisor to our stakeholders, by designing security solutions, for improved security and business enablement
Maintain various controls to meet regulatory requirements, including but not limited to Sarbanes-Oxley (SOX), FERC and NERC
Monitor, forecast, and prepare for new regulatory requirements or cloud technology changes
Aid in the development of standards and polices for the IAM program
Enhance processes to facilitate improved operational efficiencies, risk mitigation, and customer interactions
Lead and deliver cloud identity projects in scope, on time, and within budget
Provide expertise to assist in the development of Southern Company’s security architecture – identify areas of opportunity, research alternatives, and recommend solutions

Qualification

Microsoft Entra IDGoogle Cloud Identity PlatformSAMLOAuthIAM protocolsFIDOCloud application integrationAPIsCloud role-based accessInformation security frameworksRisk managementCommunication skillsMentoringSelf-starter

Required

Experience managing cloud-native identity providers, specifically Microsoft Entra ID and/or Google Cloud Identity Platform
Experience with cloud application integrations using SAML or OpenID
Experience with OAuth IDs (Service Principals), their configuration, lifecycle, and long-term risk management
An understanding of cloud role-based access controls and their unique differences from on-prem
Ability to leverage user dynamic risk, progressive authentication, self-service
Knowledge of modern authentication methods e.g. FIDO, Biometrics, Passwordless
Knowledge of cloud entitlement management and best practices
Must pass NERC CIP & Insider Threat Protection background checks
Technical knowledge with the following concepts: On-premises SSO, Active Directory, Privileged Account Management, PKI
A solid understanding of IAM related protocols and standards such as: SAML, OAuth/OIDC, SCIM, FIDO, RADIUS, LDAPS, Kerberos
Strong verbal communication and presentation skills
Competency in APIs (Rest, Graph) and/or JavaScript/Python/JSON/SQL
Experience prioritizing and executing with minimal direction or oversight
Industry certifications such as: CISSP, CCSP, CISA, GIAC, OSCP, CRISC, CCNP, etc
Experience with information security frameworks such as: COBIT, NIST, OWASP, etc
Familiarity with nation state, sophisticated criminal, and supply chain threats

Preferred

Technical knowledge with the following concepts: On-premises SSO, Active Directory, Privileged Account Management, PKI
A solid understanding of IAM related protocols and standards such as: SAML, OAuth/OIDC, SCIM, FIDO, RADIUS, LDAPS, Kerberos
Strong verbal communication and presentation skills
Competency in APIs (Rest, Graph) and/or JavaScript/Python/JSON/SQL
Experience prioritizing and executing with minimal direction or oversight
Industry certifications such as: CISSP, CCSP, CISA, GIAC, OSCP, CRISC, CCNP, etc
Experience with information security frameworks such as: COBIT, NIST, OWASP, etc
Familiarity with nation state, sophisticated criminal, and supply chain threats

Benefits

Competitive base salary
Annual incentive awards for eligible employees
Health, welfare and retirement benefits designed to support physical, financial, and emotional/social well-being
Incentive program

Company

Southern Company

company-logo
Southern Company headquartered in Birmingham, Alabama, is the shared services division of Southern Company.

Funding

Current Stage
Public Company
Total Funding
$6.16B
Key Investors
GRIP Program
2025-10-03Post Ipo Equity· $1.75B
2025-05-20Post Ipo Debt· $1.45B
2024-10-21Grant· $160M

Leadership Team

leader-logo
Thomas Fanning
President and CEO
leader-logo
David Poroch
Chief Financial Officer
linkedin
Company data provided by crunchbase