Overview
Location(s)
Dallas, Texas, Jacksonville, Florida, P&C-Butterfield Road-Downers Grove-IL-AAC
Details
Kemper is one of the nation’s leading specialized insurers. Our success is a direct reflection of the talented and diverse people who make a positive difference in the lives of our customers every day. We believe a high-performing culture, valuable opportunities for personal development and professional challenge, and a healthy work-life balance can be highly motivating and productive. Kemper’s products and services are making a real difference to our customers, who have unique and evolving needs. By joining our team, you are helping to provide an experience to our stakeholders that delivers on our promises.
Kemper is seeking an Identity Security & Non-Human Identity Analyst to work at our office in Illinois. The analyst builds and operates security controls for non-human identities, including service accounts, workload identities, bots, service principals, secrets, keys, tokens, and certificates. The role requires deep cloud/DevOps and identity lifecycle knowledge, hands-on secrets/credential engineering, automation, and risk-based governance.
Position Responsibilities
Discover and classify service accounts, application identities, bots, API keys, tokens, certificates, workload identities, and other machine identities.
Establish authoritative inventory, ownership, criticality, lifecycle status, and reconciliation across cloud, directories, CMDB, secrets platforms, and applications.
Engineer secure secrets, key, token, and certificate creation, storage, rotation, expiration, revocation, and monitoring processes.
Partner with cloud and DevOps teams on workload identity, managed identities, service principals, Kubernetes identities, CI/CD credentials, and infrastructure-as-code controls.
Identify stale, orphaned, embedded, overprivileged, or unmanaged credentials and drive risk-based remediation.
Implement least privilege, ownership certification, usage analytics, exception management, and governance for machine identities.
Build APIs, scripts, onboarding patterns, automated rotation, dashboards, and service metrics to scale the capability.
Position Qualifications
5+ years of IAM, cloud security, DevOps/DevSecOps, infrastructure security, or related experience
Substantial hands-on work experience with non-human identities, secrets, keys, certificates, or workload identity.
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Cloud Computing, or a related discipline, or equivalent relevant professional experience.
Hands-on experience managing secrets, keys, certificates, service accounts, service principals, or workload identities.
Experience with secrets managers, vaults, certificate lifecycle technologies, or comparable credential-management platforms.
Strong knowledge of non-human identity risk, least privilege, credential lifecycle, embedded-secret risk, ownership, recertification, and compensating controls.
Strong understanding of cloud IAM, DevOps, CI/CD, Kubernetes/container identities, APIs, and infrastructure-as-code patterns.
Understanding of cloud and DevOps attack paths involving secrets, tokens, service principals, and workload identities.
Scripting/API and automation capability.
Ability to reconcile identity data across directories, cloud services, CMDB, secrets platforms, and applications
Ability to translate technical machine-identity exposure into business and control risk.
Strong cross-functional collaboration with cloud, DevOps, application, infrastructure, and IAM teams.
Systems thinking and ability to solve ownership/data-quality problems at scale.
Independent capability ownership.
Clear standards and technical documentation.
Pragmatic influence in engineering workflows.
Preferred Qualifications
Cloud security/architecture certification in AWS, Azure, or GCP.
Vendor certification for the organization's secrets-management or vault platform.
Kubernetes, DevOps, or infrastructure-as-code experience.
CISSP, CISM, or comparable security credential.
Experience designing machine-identity governance at enterprise scale.
This position works in the Kemper office in Illinois.
The range for this position is $79,500 to $132,900. When determining candidate offers, we consider experience, skills, education, certifications, and geographic location among other factors. This job is also eligible for our Kemper benefits package (Medical, Dental, Vision, PTO, 401k, etc.)
Kemper is proud to be an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran, disability status or any other status protected by the laws or regulations in the locations where we operate. We are committed to supporting diversity and equality across our organization and we work diligently to maintain a workplace free from discrimination. Kemper does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Kemper and Kemper will not be obligated to pay a placement fee.
Kemper will never request personal information, such as your social security number or banking information, via text or email. Additionally, Kemper does not use external messaging applications like WireApp or Skype to communicate with candidates. If you receive such a message, delete it.

