Mediabistro logo
job logo

Lead, Security Analyst - Database Identity & Access Management

Prudential Financial, Newark, NJ, United States


Security Analyst

Database Identity & Access Management

Are you interested in building capabilities that enable the organization with innovation, speed, agility, scalability, and efficiency? The Identity & Access Management team in Information Security Office (ISO) takes great pride in our culture where information security is built into our DNA! When you join our organization at Prudential, you'll unlock an exciting and impactful career

all while growing your skills and advancing your profession at one of the world's leading financial services institutions.
Your Team & Role
As a Security Analyst

Database Identity & Access Management, you will work within the Identity & Access Management (IAM) function of the Information Security Office to strengthen how database access is governed, measured, and enforced across the enterprise.
This role focuses on database privileged access and IAM control design, as well as data and process analysis required to operationalize identity standards in complex, real world environments.
You will partner closely with database infrastructure, cloud, and IAM engineering teams to communicate needed controls, assess controls and reduce database privileged access and related risks.
What You Will Work On
Analyze, articulate, assess and drive remediation of database identity & privileged access risks.
Interpret outputs from database security tools (e.g., Guardium/Wiz/Qualys) to assess adherence to standards, identify control gaps and to define remediation requirements
Partner with DBAs and infrastructure teams to validate controls effectiveness, adherence to standards and to triage remediation
Map relevant data flows supporting IAM lifecycle processes like access requests & reviews, joiner/mover/leaver.
Produce clear requirements, specifications, and process flows for new or improved IAM processes related to database access management
Work with IAM leadership to articulate target state control models
Prepare materials including detailed DFD's in collaboration with data and engineering teams to socialize designs, validate assumptions with stakeholders and drive alignment and buy in across teams
Act as a credible translator between technical teams and security standards related to databases
The Skills & Expertise You Bring
Bachelor of Computer Science or experience in database infrastructure & security.
Strong technical grounding in databases (including Cloud databases) or data platforms, gained through roles in database administration / database engineering / data platform operations / infrastructure engineering, or closely related disciplines, with hands on exposure to how privileged access works
Clear understanding of database privileged access risks, including superuser roles, predefined roles, shared and service accounts, break glass access, and the operational and security trade offs associated with each. You are comfortable discussing these risks credibly with DBAs and platform teams
Experience working with database security and monitoring tools such as Guardium / Wiz / Qualys, or similar platformsspecifically interpreting findings, alerts, and reports to assess control effectiveness and adherence to standards.
Familiarity with common identity and data integration patterns, such as SCIM based provisioning, REST APIs, event driven updates, and batch/ETL feeds, with the ability to reason about authoritative sources, data ownership, timing, and failure modesand to translate that understanding into clear requirements and data flow specifications for IAM and platform engineering teams.
Comfort working in ambiguity and driving alignment, including creating diagrams (DFDs, process flows), and requirements), to articulate and drive target state designs, and execution
Strong cross functional collaboration skills needed in order to work credibly with database engineers, DBAs, infrastructure and cloud teams, IAM engineering, and audit/risk stakeholdersacting as a translator between technical reality and security intent, facilitating alignment, and resolving ambiguity.