Auf einen Blick
- Aufgaben: Bewerte und dokumentiere die Sicherheitsprotokollierung der Omada Identity Platform.
- Unternehmen: NextLink Group, ein innovatives Unternehmen im Bereich Identitätsmanagement.
- Vorteile: Flexibles Arbeiten, wettbewerbsfähiges Gehalt und Entwicklungsmöglichkeiten.
- Weitere Informationen: Dynamisches Team mit vielen Möglichkeiten zur beruflichen Weiterentwicklung.
- Warum dieser Job: Gestalte die Sicherheitsarchitektur und mache einen echten Unterschied in der Cybersecurity.
- Qualifikationen: Erfahrung mit Omada und Sicherheitsprotokollierung erforderlich.
Das prognostizierte Gehalt liegt zwischen 59400 - 72600 € pro Jahr.
Next Link Group is seeking an experienced
Omada Identity Platform Security Consultant to independently assess, analyze, and document the logging and monitoring capabilities of the Omada Identity Platform.
The primary objective of the engagement is to determine how security-relevant audit information generated by Omada can be made available for centralized security monitoring processes and aligned with applicable organizational logging and monitoring requirements.
The consultant will perform a structured assessment of existing Omada audit and security logging capabilities, identify security-relevant events, evaluate potential log export and integration mechanisms, identify monitoring gaps, and develop an
Omada-specific logging and monitoring concept .
This engagement is structured as a self-contained work package with clearly defined deliverables .
The scope focuses on assessment, architecture/concept development, and technical documentation.
Operational implementation and ongoing operational activities are excluded.
Key Responsibilities
- 1. Omada Audit & Security Logging Assessment
- Analyze available audit, security, administrative, authentication, and operational log sources within the Omada Identity Platform.
- Identify the types of events and audit information generated by the platform.
- Assess the availability, completeness, and security relevance of available events.
- Determine which events are suitable for centralized security monitoring and detection use cases.
- Document relevant log sources, event categories, event attributes, and associated limitations.
- 2. Security Event Analysis
- Identify and classify security-relevant events, including areas such as:
- Authentication and access-related events
- Failed or suspicious authentication activities
- Administrative and privileged activities
- Changes to identities, accounts, roles, and entitlements
- Role and access assignment changes
- Access request and approval activities
- Provisioning and de-provisioning activities
- Failed provisioning or synchronization events
- Configuration and policy changes
- Privileged or sensitive changes within the Omada platform
- Security-related system or integration events
- Relevant audit activities that may support incident investigation and forensic analysis
The final event catalogue will be based on events actually available within the applicable Omada environment and product configuration.
- 3. Logging & Monitoring Concept
- Develop an
Omada-specific logging and monitoring concept covering
- Relevant Omada log sources
- Security-relevant event categories
- Recommended events for centralized monitoring
- Event prioritization and severity considerations
- Monitoring and detection use cases
- Required event information and contextual fields
- Auditability and traceability requirements
- Log availability and retention considerations
- Identification of gaps between available logging and security-monitoring requirements
- Recommendations for addressing identified gaps
- 4. Log Export & Integration Assessment
Evaluate technically feasible mechanisms for providing Omada security and audit logs to centralized monitoring platforms.
The assessment should cover, where applicable
- Native Omada logging/export capabilities
- APIs and supported interfaces
- File-based log collection
- Database or audit-data interfaces
- Connector or integration mechanisms
- Potential SIEM/SOC integration approaches
- Log format and event structure
- Data normalization requirements
- Event filtering and security relevance
- Reliability and completeness of log transfer
- Security and access considerations associated with log collection
- Technical dependencies and constraints
The objective is to provide an integration assessment and recommendation , rather than perform the production integration.
Deliverables
The consultant will be responsible for producing the following professional documentation artifacts:
1. Omada Audit Log Inventory & Assessment
A structured inventory containing
- Available log sources
- Audit-log categories
- Relevant event types
- Event information/attributes
- Security relevance
- Monitoring suitability
- Availability and accessibility
- Known limitations or gaps
- 2. Omada Logging & Monitoring Concept
A comprehensive concept defining
- Logging objectives
- Relevant security events
- Security monitoring requirements
- Event prioritization
- Monitoring recommendations
- Proposed approach for centralized security monitoring
- 3. Security Event Catalogue
Structured documentation of security-relevant events and log types, including recommendations regarding which events should be forwarded to centralized security monitoring.
4. Technical Integration Assessment
Assessment of the available methods for extracting and/or providing Omada audit information to centralized security-monitoring infrastructure, including technical dependencies, limitations, and recommended integration approach.
5. Gap Analysis & Recommendations
Identification of differences between
- Required security-monitoring capabilities
- Available Omada logging capabilities
- Events currently available for monitoring
- Events/information required for effective security monitoring
Each identified gap should include an appropriate recommendation or proposed remediation approach.
6. Final Technical Documentation
A consolidated final document containing
- Executive summary
- Current-state assessment
- Log-source inventory
- Security-event catalogue
- Logging and monitoring concept
- Integration assessment
- Gap analysis
- Assumptions and dependencies
- Technical limitations
- Identified risks
- Recommendations
- Proposed next steps for subsequent implementation
Requirements
Required Skills & Experience
Essential
- Strong experience with
- Omada Identity Platform / Omada Identity
- Strong understanding of
- Identity Governance and Administration (IGA/IAM)
- Experience analyzing application and security audit logs
- Good understanding of security logging and monitoring principles
- Experience with centralized security monitoring and
- SIEM concepts
- Understanding of identity-related security events and detection use cases
- Experience assessing application integration with security-monitoring platforms
- Ability to analyze technical log formats, events, interfaces, and APIs
- Experience developing structured technical and security documentation
- Strong analytical and stakeholder communication skills
- Ability to work independently and deliver a defined technical work package
- Highly Desirable
Experience with one or more of the following would be advantageous
- Microsoft Sentinel
- Splunk or comparable SIEM platforms
- SOC monitoring processes
- Identity threat detection and monitoring
- Privileged access monitoring
- Security audit and compliance requirements
- Log-management architecture
- REST/API-based security integrations
- Syslog or equivalent event-forwarding mechanisms
- Identity lifecycle and provisioning processes
- Security monitoring for business-critical applications
- Required Skills & Experience
Essential
- Strong experience with
- Omada Identity Platform / Omada Identity
- Strong understanding of
- Identity Governance and Administration (IGA/IAM)
- Experience analyzing application and security audit logs
- Good understanding of security logging and monitoring principles
- Experience with centralized security monitoring and
- SIEM concepts
- Understanding of identity-related security events and detection use cases
- Experience assessing application integration with security-monitoring platforms
- Ability to analyze technical log formats, events, interfaces, and APIs
- Experience developing structured technical and security documentation
- Strong analytical and stakeholder communication skills
- Ability to work independently and deliver a defined technical work package
- Highly Desirable
Experience with one or more of the following would be advantageous
- Microsoft Sentinel
- Splunk or comparable SIEM platforms
- SOC monitoring processes
- Identity threat detection and monitoring
- Privileged access monitoring
- Security audit and compliance requirements
- Log-management architecture
- REST/API-based security integrations
- Syslog or equivalent event-forwarding mechanisms
- Identity lifecycle and provisioning processes
- Security monitoring for business-critical applications
- Expected Consultant Profile
- The ideal consultant combines
Omada/IGA expertise with cybersecurity logging and SIEM knowledge .
This is not purely an Omada administration role and not purely a SOC/SIEM role. The consultant should be capable of bridging:
Omada / IGA → Audit & Security Events → Logging Architecture → SIEM/SOC Monitoring
The consultant must also be comfortable independently investigating platform capabilities and translating technical findings into clearly structured security requirements and recommendations.
- Scope Boundaries
- In Scope
- Analysis and assessment
- Technical workshops/interviews where required
- Omada logging capability assessment
- Audit-event analysis
- Security-event identification
- Logging and monitoring concept development
- Integration-option assessment
- Security-monitoring gap analysis
- Risk and limitation documentation
- Technical recommendations
- Final documentation
- Explicitly Out of Scope
The following activities are not part of this engagement
- Production implementation
- SIEM connector implementation
- Production configuration changes
- Deployment of monitoring rules
- Operational acceptance/testing
- Production rollout
- Ongoing SOC monitoring
- Incident response operations
- Ongoing application support
- Subsequent operational activities
Recommendations and implementation guidance may be documented, but execution of the implementation remains outside the scope of the engagement .
Engagement Success Criteria
The work package will be considered successful when
- Available Omada audit and security log sources have been systematically documented.
- Security-relevant Omada events have been identified and classified.
- The suitability of those events for centralized monitoring has been assessed.
- A practical Omada-specific logging and monitoring concept has been established.
- Technically feasible log-export and integration approaches have been assessed.
- Monitoring gaps, limitations, assumptions, and risks have been documented.
- Clear technical recommendations have been provided to support a subsequent implementation phase.
IAM Developer – Omada Arbeitgeber: Next-Link
Next-Link bietet eine dynamische und unterstützende Arbeitsumgebung, in der Innovation und Zusammenarbeit gefördert werden. Als Remote Data Catalog & Governance Architect haben Sie die Möglichkeit, an spannenden Projekten zu arbeiten, die einen direkten Einfluss auf die Datenstrategie des Unternehmens haben. Wir legen großen Wert auf die berufliche Weiterentwicklung unserer Mitarbeiter und bieten zahlreiche Schulungs- und Aufstiegsmöglichkeiten, um Ihre Karriere voranzutreiben.
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so IAM Developer – Omada erhalten könntest
✨Netzwerken in der IT-Community
In der IT-Consulting-Welt sollten wir regelmäßig auf Veranstaltungen wie Tech-Meetups oder Konferenzen gehen. Hier können wir nicht nur unser Netzwerk erweitern, sondern auch direkt mit potenziellen Arbeitgebern ins Gespräch kommen und unser Interesse an einer Vollzeitstelle zeigen.
✨Online-Foren und Gruppen nutzen
Sich in Online-Foren und Communities wie Stack Overflow oder LinkedIn-Gruppen umzusehen, kann uns helfen, Insider-Tipps zu erhalten und Informationen über offene Stellen in der IT-Beratung zu sammeln. Vergiss nicht, aktiv zu werden und Fragen zu stellen oder dein Wissen zu teilen – das erhöht unsere Sichtbarkeit!
✨Direkt bei Next-Link bewerben
Viele Unternehmen, wie Next-Link, stemmen ihre Vollzeitstellen bevorzugt über ihre eigenen Karriere-Webseiten. Also, lass uns regelmäßig auf deren Seite vorbeischauen und uns direkt bewerben, statt nur die üblichen Jobportale zu nutzen.
✨Überzeugende Projekte zeigen
Wir sollten unser Portfolio oder relevante Projekte gut sichtbar machen, egal ob das auf Github, persönlich oder auf LinkedIn ist. Bei IT-Consulting-Stellen kommt es oft auf praktische Erfahrungen an, also lass uns zeigen, was wir können!
Wir glauben, dass du diese Fähigkeiten brauchst, um IAM Developer – Omada mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Zeige deine technischen Skills!:In der IT-Beratung zählen deine technischen Kenntnisse und Fähigkeiten. Achte darauf, relevante Programmiersprachen, Tools und Systeme in deinem Lebenslauf aufzulisten. Zeig auch, wenn du Zertifikate hast, die deine Kompetenz unterstützen – das könnte dir einen echten Vorteil verschaffen!
Verstehe die Branche!:Unterstreiche in deinem Anschreiben, dass du ein gutes Verständnis für aktuelle Trends und Herausforderungen in der IT-Branche hast. Zeig, dass du nicht nur die technischen Aspekte beherrschst, sondern auch die Bedürfnisse der Kunden erkennen und lösen kannst!
Deine Projekte zählen!:Falls du bereits an IT-Projekten gearbeitet hast, verlinke diese oder beschreibe sie in deinem Lebenslauf. Praktische Erfahrungen – sei es in Form von Praktika oder privaten Projekten – sind besonders wertvoll in der IT-Beratung. Zeige uns, was du kannst!
Individuelle Bewerbung ist der Schlüssel!:Jede Bewerbung sollte individuell auf Next-Link und die ausgeschriebene Position IAM Developer – Omada zugeschnitten sein. Teile uns mit, warum gerade du eine gute Wahl für unser Team bist. Das zeigt dein Engagement und deine Motivation, die über eine Standardbewerbung hinausgeht.
Wie man sich auf ein Vorstellungsgespräch bei Next-Link vorbereitet
✨Technische Vorbereitung ist alles!
Da du dich auf eine Vollzeitstelle in der IT-Beratung bewirbst, solltest du dir wirklich einen Überblick über die wichtigsten Tools und Technologien verschaffen, die in der Branche verwendet werden. Sei bereit, technische Fragen zu beantworten, die sich auf Software-Architektur oder Systemintegration beziehen könnten.
✨Praxisbeispiele parat haben
In der IT-Beratung ist es wichtig, konkrete Beispiele aus deiner bisherigen Erfahrung zu bringen. Überlege dir Projekte, bei denen du erfolgreich einen Kunden beraten hast oder Herausforderungen gelöst hast. Das zeigt, dass du nicht nur theoretisches Wissen hast, sondern auch in der Praxis erfolgreich sein kannst.
✨Soft Skills betonen
Ein großer Teil der IT-Beratung ist die Kommunikation mit Kunden und das Verständnis ihrer Bedürfnisse. Bereite dich darauf vor, über deine zwischenmenschlichen Fähigkeiten zu sprechen, wie du mit herausfordernden Kunden umgehst oder wie du in Teams arbeitest. Das wird den Interviewern zeigen, dass du mehr als nur technisches Wissen mitbringst!
✨Fragen zum Unternehmen vorbereiten
Schau dir spezifisch die Projekte von Next-Link an und überlege dir, welche Fragen du dazu stellen möchtest. Zeig Interesse an den aktuellen Herausforderungen, vor denen das Unternehmen steht, und wie du dazu beitragen könntest. Das hebt dich von anderen Bewerbern ab und zeigt, dass du wirklich motiviert bist.