Job Description
Who We Are
Creative Artists Agency (CAA) is the leading entertainment and sports agency, with global expertise in filmed and live entertainment, digital media, publishing, sponsorship sales and endorsements, media finance, consumer investing, fashion, trademark licensing, and philanthropy. Distinguishedby its culture of collaboration and exceptional client service, CAA’s diverse workforce identifies, innovates, and amplifies opportunities for the people and organizations that shape culture and inspire the world. Thetrailblazer of the agency business, CAA was the first to build a sports business, create an investment bank, launch a venture fund, found technology start-up companies, establish a philanthropic arm, build a business in China, and form a brand marketing services division, among other innovations. Named Most Valuable Sports Agency by Forbes for eight consecutive years, CAA represents more than 2,000 of the world’s top athletes in football, baseball, basketball, hockey, soccer, in addition to coaches, on-air broadcasters, and sports personalities and works in the areas of broadcast rights, corporate marketing initiatives, social impact, and sports properties for sales and sponsorship opportunities. Foundedin 1975, CAA is headquartered in Los Angeles, and has offices in New York, Nashville, Memphis, Chicago, Miami, London, Munich, Geneva, Stockholm, Shanghai, and Beijing, among other locations globally.
Summary
This is a hands-on security position working within the Information Security group and with the internal IT department at large.We are looking for candidates whohave apassionforcyber security,identitymanagement,andthreatresponse. Youwill provide domainexpertiseto design and develop the capabilities of the identity and accessmanagementplatform and the automation of application deployment pipelines to the platform.
The Role
In this role, you will be an essential partner and technical specialist for identity and access platform development and provide thought leadership on overall security and authentication acrossvarious workflows.Youwill be a key part of ourefforts toenablethebusinessneedsinahighly collaborative organization. The environment is fast-paced and commonly on the leading edge of technology, including early adoption of various cloud servicesalong withthe challenges of integrating those services into our security practice.
Responsibilities
Provide design, evaluation, analysis, testing, debugging and implementation of identity and access management programs to support the company’s strategy
Maintain configuration, updates, and overall administration of the identity access management platform
Have a deep understanding of user lifecycle management; including provisioning/de-provisioning, access requests, userentitlementsand audit & validations
Maintain standards for access management across the company and department
Collaborate with HRIS, IT service owners, and service desk to troubleshoot and fulfill identity related workflows
Knowledge of identity governance workflows with the concepts of attestation and auditing.
Integrate new applications into the identity access management platform throughRESTful APIs, JDBC, flat file, or built-in connectors and configureaggregation, provisioning, and entitlements
Automate identity workflowsand processes for lifecycle management, auditing, reporting,governanceand self-service
Provide andmaintaina RESTful identity API to downstream services
Play an active role in CAA’s security incident response efforts, working toidentifyand mitigate information security threats
Required Capabilities
Aminimum of4years in Information Technology, ideally with a focus oninformation security
Aminimum of2years’ experience inidentity and access managementorCyberSecurity
ABachelor’s or Master’sDegree in a relevant field of work
Experience scripting in at least one of the following languages: PowerShell, Python, JavaScript
Experience with thedeploymentand support ofZero Trust Identityarchitecture andinfastructure
Astrong understanding of the fundamental operations of servers, operating systems, networks,firewalls,cloud applications,and infrastructure
Experience in automation and integrationwith SaaS applications
Understandingof OAuth, SAMLandOpenIDframeworks
Experience in lifecycle management and provisioning andde-provisioning
Knowledge ofdifferentMFA and compensating controlsfor identity
Knowledge ofprivilegeidentity management,privilegedaccess management,and concepts ofjust in timeprovisioning, just enough access, and principal of least privilege
Desired Capabilities
Setupand integratedSingle Sign-Onwith various SaaS vendors
Account set-up and access management
Using and coding againstREST APIs
Knowledge and experience of SCIM provisioning and integration
Worked closely with human resources and help desk support staff
Experience supportingand followingidentity framework orIDaaS
An understanding of the NIST framework and using a continuous improvement loop
Desired Skills
Azure AD, Active Directory, AD Connect, Azure Automation, Power Automate, SAML, OpenID, WS-Fed, SSO, SCIM, OAuth, Programming (java, python), PowerShell, RESTful APIs, MSSQL, OGNL,GraphQL, Workday, SailPoint, Okta, Ping Federate,PingID, Splunk, RBAC
Location
This role is based in our Nashville office.
Compensation
The annual base salary for this position is in the range of $122,000 - $153,000 in Nashville. This position is also eligible for benefits and a discretionary bonus. Ultimately, the salary may vary based upon, but not limited to, relevant experience, time in the role, business sector, and geographic location, among other criteria. Please talk with a CAA Recruiter to learn more.
Environment
CAA has aservice orientedcollaborative environment where we help ourcolleaguesthen focus on our own work.
Creative Artists Agency, LLC (the “Company”) is committed to a policy of Equal Employment Opportunity and will not discriminate on the basis of race (inclusive of traits historically associated with race, including hair texture and protective hairstyles), color, religion, creed, gender or sex (including pregnancy, childbirth, breastfeeding or related medical conditions), national origin, ancestry, age, physical disability, mental disability, medical condition, genetic information, family and medical care leave status, military or veteran status, marital status, family status, sexual orientation, gender identity, gender expression, political affiliation, an employee’s or their dependent’s reproductive health decision making (e.g., the decision to use or access a particular drug, device or medical service), or any other characteristic protected by applicable law.The absence of a permanent address is not a bar to employment. The Company does not discriminate against individuals based on housing status, including the absence of a fixed address.The Company also complies with the Americans with Disabilities Act and applicable state and local laws with regard to providing reasonable accommodation for qualified individuals with disabilities.CAA does not accept unsolicited resumes from third-party recruiters unless they were contractually engaged by CAA to provide candidates for a specified opening. Any such employment agency, person or entity that submits an unsolicited resume does so with the acknowledgement and agreement that CAA will have the right to hire that applicant at its discretion without any fee owed to the submitting employment agency, person or entity.
