Lead Security Analyst – Customer Identity and Access Management (CIAM)
Location: Columbus, OH, US
Location Type: On-site
Job ID: 04IFO
Job Area: Information Technology
Employment type: Full-time
Description
At Bath & Body Works, everyone belongs. We are committed to creating a diverse, equitable and inclusive culture focused on delivering exceptional fragrances and experiences to our customers. We focus on recruiting, retaining, and advancing diverse talent where our associate population is as diverse as the communities we serve, live and work. In addition, we work to improve our communities and our planet in a way that will make us proud for years to come because we believe the world is a brighter, happier place when everyone has access to the things that make them happy.
We are seeking a highly skilled and motivated Cybersecurity CIAM Lead Analyst to lead the design, implementation, and management of our Customer Identity and Access Management (CIAM) strategy. This role will focus on safeguarding customer data, ensuring secure access to digital services, and improving the customer experience through seamless identity and authentication processes. As the CIAM Lead Analyst, you will work closely with cross-functional teams, including security, IT, compliance, and business units, to ensure that all customer identities are securely run and that our systems comply with industry standards and regulations. You will partner directly with product/platform teams to deliver the technology requirements to support the business objectives.
Responsibilities
CIAM Strategy and Implementation: Lead the development, implementation, and ongoing management of the organization’s CIAM platform and strategy. Ensure that CIAM policies align with both business objectives and security best practices.
- Access Management: Be responsible for the secure management of customer identities, including user registration, authentication, authorization, and account recovery processes. Implement multi-factor authentication (MFA), single sign-on (SSO), and other secure identity protocols to enhance the customer experience and security.
- Security and Compliance: Ensure the CIAM environment complies with relevant data protection regulations (e.g., GDPR, CCPA) and security frameworks (e.g., NIST, ISO 27001). Regularly audit the environment for vulnerabilities and address them promptly.
- User Experience Focus: Work to optimize the balance between security and user experience by recommending solutions for frictionless yet secure customer authentication and authorization. Evaluate and introduce innovative identity management solutions that enhance the user journey.
- Risk and Threat Management: Proactively monitor and assess potential security threats related to customer identity data and access control. Respond to and mitigate incidents that affect CIAM systems, including data breaches, credential stuffing, and other identity-related threats.
- Collaboration: Collaborate with IT, product development, marketing, and other teams to ensure seamless integration of CIAM systems with other enterprise applications and services. Provide technical guidance and support to internal teams on identity and access management best practices.
- Reporting and Documentation: Maintain accurate documentation of CIAM policies, configurations, and access controls. Provide regular reports to senior leadership on the status of the CIAM program, including key metrics, risk assessments, and incident response activities.
- Vendor Management: Maintain relationships with external CIAM solution providers and third-party vendors, ensuring that services are meeting performance, security, and compliance requirements.
- 5+ years of proven ability in cybersecurity, with a focus on identity and access management (IAM) or customer identity and access management (CIAM).
- Demonstrable experience leading the implementation and management of CIAM solutions and strategies.
- Strong understanding of IAM protocols such as SSO, MFA, OAuth, OpenID Connect, and SAML.
- Hands-on experience with leading CIAM platforms (e.g., Okta, Ping Identity, Microsoft Azure AD B2C, Auth0).
- Experience with identity governance, authentication, and authorization technologies.
- Knowledge of security protocols, encryption, and privacy standards.
- Familiarity with data protection laws and regulations (e.g., GDPR, CCPA).
- Knowledge of security frameworks and standards (e.g., NIST, ISO 27001).
- Experience with risk management, vulnerability assessments, and incident response.
- Good communication skills, with the ability to translate technical concepts to non-technical partners.
- Ability to collaborate effectively with cross-functional teams.
- Strong problem-solving and analytical skills, with attention to detail.
- Ability to influence across all levels and areas of the business (technical & non-technical).
- Education: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent work experience).
Core Competencies
- Lead with Curiosity & Humility
- Build High Performing Teams for Today & Tomorrow
- Influence & Inspire with Vision & Purpose
- Observe, Engage & Connect
- Strive to Achieve Operational Excellence
- Deliver Business Results
Benefits
Bath & Body Works associates are the heart of our business. That’s why we’re proud to offer benefits that empower you to Dream Bigger & Live Brighter. Benefits for eligible associates include:
- Robust medical, pharmacy, dental and vision coverage. Plus, access to our onsite wellness center and pharmacy located at the Columbus, OH home office.
- 401k with company match and Associate Stock Purchase program with discount
- No-cost mental health and wellbeing support through our Employee Assistance Program (EAP)
- Opportunity for paid time off, paid parental leave. Plus, access to family and lifestyle programs including an inclusive family building benefit, childcare discounts, and home, auto and pet insurance.
- Tuition reimbursement and scholarship opportunities for post-secondary education programs
- 40% merchandise discount and gratis that encourages you to come back to your senses!
Visit bbwbenefits.com for more details.
The above statements are intended to describe the general nature and level of work being performed by people assigned to this job. They are not intended to be an exhaustive list of all responsibilities, duties and skills required.
We will consider for employment all qualified applicants, including those with arrest records, conviction records, or other criminal histories, in a manner consistent with the requirements of any applicable state and local laws. Please see links: Los Angeles Fair Chance In Hiring Ordinance, Philadelphia Fair Chance Law, San Francisco Fair Chance Ordinance.
We are an equal opportunity and affirmative action employer. We do not make employment decisions based on an individual’s race, color, religion, gender, gender identity, national origin, citizenship, age, disability, sexual orientation, marital status, pregnancy, genetic information, protected veteran status or any other legally protected status, and we comply with all laws concerning nondiscriminatory employment practices. We are committed to providing reasonable accommodations for associates and job applicants with disabilities. Our management team is dedicated to ensuring fulfillment of this policy with respect to recruitment, hiring, placement, promotion, transfer, training, compensation, benefits, associate activities and general treatment during employment. We only hire individuals authorized for employment in the United States.
Application window will close when all role(s) are filled.