Haystack
← Back to Jobs
Operations & Project Management
IS

Business Analyst - IAM, InfoSec

iSpace, IncBeverly Hills, CA🇺🇸United StatesPosted Sep 24, 2026

Why This Role Stands Out

This hybrid Business Analyst role offers an exciting opportunity to drive critical transitions in identity and access management, allowing you to hone your analytical and problem-solving skills within a dynamic InfoSec environment. You'll thrive here if you're a proactive, self-starter eager to take ownership and make a significant impact on security infrastructure. Apply now to contribute to iSpace, Inc.'s innovative projects and gain valuable experience.

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Beverly Hills, CA, United States
Posted
22 hours ago
AgileBusiness AnalysisConfluenceJira

Job Description

Title: Business Analyst/QA Analyst – IAM (InfoSec)
Location: Los Angeles Based
Duration: 3-6 Months (possible extension)
Hybrid – Onsite as needed
The Hybrid BA/QA Analyst will play a pivotal role in transitioning legacy applications and services to a new authentication method. This position is designed for a self‐starter who thrives in environments with evolving requirements, incomplete documentation, and cross‐team dependencies. The analyst will independently uncover gaps, drive clarity, and ensure authentication workflows are fully understood, documented, and validated through rigorous testing.
This role suits someone who naturally takes ownership, anticipates issues before they surface, and pushes the project forward without waiting for direction.
Key Responsibilities
Business Analysis

  • Independently investigate and document current‐state authentication flows across applications, APIs, and user journeys—even when documentation is sparse.
  • Proactively elicit requirements from stakeholders and identify missing or ambiguous details.
  • Translate legacy identity behaviors into clear, actionable requirements for the new authentication method.
  • Create and maintain detailed artifacts: process flows, data mappings, acceptance criteria, and transition plans.
  • Drive alignment with engineering and security teams by initiating discussions, clarifying assumptions, and resolving open questions.


Quality Assurance

  • Develop comprehensive test plans without waiting for fully defined requirements; fill gaps through analysis and stakeholder engagement.
  • Execute manual and automated tests for login, MFA, token handling, session management, and error states.
  • Validate API authentication behavior, including token issuance, expiration, refresh, and claims.
  • Log defects with clear reproduction steps and independently follow up to ensure resolution.
  • Lead UAT cycles by coordinating test activities, preparing test scripts, and guiding business testers.


Cross‐Functional Collaboration

  • Act as the proactive liaison between product owners, developers, security architects, and operations teams.
  • Surface risks early, propose mitigation strategies, and communicate impacts clearly.
  • Initiate and lead discussions to resolve blockers rather than waiting for direction.
  • Support cutover planning, smoke testing, and post‐deployment validation with minimal oversight.
  • Produce clear documentation for end users and support teams on new authentication workflows.


Required Qualifications

  • 5+ years of experience as a Business Analyst, Quality Assurance Analyst, or hybrid role.
  • Demonstrated ability to work independently, manage priorities, and drive outcomes without constant guidance.
  • Strong understanding of authentication concepts: OAuth2, OIDC, SAML, JWT, MFA, SSO, identity providers (Azure AD, Okta, Ping, etc.).
  • Experience testing authentication flows across web apps, mobile apps, and APIs.
  • Ability to write clear requirements, acceptance criteria, and test cases.
  • Proficiency with tools such as Postman, Swagger/OpenAPI, Jira, Confluence, and test management platforms.


Preferred Qualifications

  • Experience with modernization or identity migration projects where ambiguity is common.
  • Familiarity with automation frameworks (e.g., Cypress, Selenium, Playwright).
  • Understanding of security best practices and compliance requirements.
  • Experience working in Agile environments.
  • Ability to interpret logs, token payloads, and authentication headers.


Success Profile
A successful candidate will be:

  • A self‐starter who takes initiative and drives clarity in ambiguous environments.
  • Comfortable diving into undocumented legacy authentication logic.
  • Skilled at translating incomplete requirements into precise, testable criteria.
  • Persistent in uncovering edge cases and failure modes.
  • Collaborative, communicative, and proactive in identifying risks.
  • Motivated by delivering secure, seamless authentication experiences.

Similar jobs