Yum!

Cyber Security Analyst II, IAM Engineer

Yum! United States · $118K–$148K/yr

Restaurants · 10,001+ employees

3 h ago
Remote Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Cyber Security Analyst II is responsible for the design, administration, and security of the enterprise Identity and Access Management environment. This role involves implementing modern authentication controls, managing privileged access, and driving identity-related security improvements across cloud and hybrid infrastructures.

What they look for

Microsoft Entra ID Azure Active Directory Identity and Access Management Privileged Access Management RBAC MFA Conditional Access Policies PowerShell Microsoft Graph NIST PCI-DSS CIS Controls Identity Lifecycle Management Cybersecurity Hybrid Identity Architectures Governance

Requirements

Candidates must have at least 5 years of experience in cybersecurity or systems engineering, with a minimum of 3 years specifically in Microsoft Entra ID administration. A bachelor's degree in a related field is required, and professional certifications such as CISSP or Microsoft identity-related credentials are preferred.

Benefits

Bonus eligibility

Full description

Position Summary

The Cyber Security Analyst II serves as a senior Identity and Access Management (IAM) engineer responsible for the design, administration, security, governance, and continuous improvement of Yum's Microsoft Entra ID (Azure Active Directory) environment. This role is responsible for securing enterprise identities, implementing modern authentication controls, managing privileged access, supporting compliance initiatives, and driving identity-related security improvements across cloud and hybrid infrastructures.

The successful candidate operates with limited supervision, independently resolves complex identity-security challenges, develops new processes and operational efficiencies, and acts as a trusted technical resource for other team members and stakeholders. This scope aligns with Level 8 expectations within the Yum Technology Job Leveling Framework.

Responsibilities

Key Responsibilities

Identity & Access Management

  • Engineer, administer, and support Microsoft Entra ID and hybrid Active Directory environments.
  • Design and maintain identity lifecycle management processes, including onboarding, transfers, and offboarding.
  • Administer role-based access controls (RBAC) and privileged access management solutions.
  • Manage and optimize:• Conditional Access Policies
  • Multifactor Authentication (MFA)
  • Passwordless Authentication
  • Identity Protection
  • Access Reviews
  • Entitlement Management
  • Privileged Identity Management (PIM)

Security Engineering

  • Implement security controls to protect enterprise identities and privileged accounts.
  • Investigate and remediate identity-related security findings and vulnerabilities.
  • Support remediation efforts resulting from penetration tests, audits, and security assessments.
  • Evaluate emerging Identity and Security technologies and recommend adoption strategies.

Governance, Risk & Compliance

  • Conduct compliance assessments and evidence gathering utilizing frameworks such as:• NIST
  • PCI-DSS
  • CIS Controls
  • Security Control Framework (CSF)
  • Lead periodic entitlement reviews and access certification processes.

Automation & Operational Excellence

  • Develop automation solutions using PowerShell and Microsoft Graph.
  • Streamline identity operations through process improvements and workflow automation.
  • Improve operational monitoring, logging, and alerting capabilities.
  • Create repeatable processes that increase security and reduce operational overhead.

Collaboration & Leadership

  • Serve as an Identity and Access Management subject matter expert.
  • Partner with Infrastructure, Cyber Security, Cloud Engineering, HR, and Application teams.
  • Mentor junior engineers and analysts.
  • Provide technical guidance during security reviews and project engagements.
  • Communicate technical risks and recommendations to management and business stakeholders.

Qualifications

Required Qualifications

Education

  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related discipline.
  • Equivalent work experience may be considered.

Experience

  • 5+ years of cybersecurity, systems engineering, or IAM experience.
  • 3+ years administering Microsoft Entra ID / Azure Active Directory.
  • Experience supporting hybrid identity architectures.
  • Experience with audit, compliance, and governance activities.
  • Experience supporting enterprise-scale Microsoft 365 environments.

Certifications (Preferred)

  • Microsoft Certified: Identity and Access Administrator Associate
  • Microsoft Certified: Azure Security Engineer Associate
  • Microsoft Certified: Cybersecurity Architect Expert
  • CISSP, Security+, or equivalent industry certifications

Salary Range: $117,800 to $147,600 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we’ll consider the successful candidate’s location, experience, and other job-related factors.