NextLink Group is seeking an experienced Omada Identity Platform Security Consultant to independently assess, analyze, and document the logging and monitoring capabilities of the Omada Identity Platform.
The primary objective of the engagement is to determine how security-relevant audit information generated by Omada can be made available for centralized security monitoring processes and aligned with applicable organizational logging and monitoring requirements.
The consultant will perform a structured assessment of existing Omada audit and security logging capabilities, identify security-relevant events, evaluate potential log export and integration mechanisms, identify monitoring gaps, and develop an Omada-specific logging and monitoring concept.
This engagement is structured as a self-contained work package with clearly defined deliverables. The scope focuses on assessment, architecture/concept development, and technical documentation. Operational implementation and ongoing operational activities are excluded.
Key Responsibilities
1. Omada Audit & Security Logging Assessment
- Analyze available audit, security, administrative, authentication, and operational log sources within the Omada Identity Platform.
- Identify the types of events and audit information generated by the platform.
- Assess the availability, completeness, and security relevance of available events.
- Determine which events are suitable for centralized security monitoring and detection use cases.
- Document relevant log sources, event categories, event attributes, and associated limitations.
2. Security Event Analysis
Identify and classify security-relevant events, including areas such as:
- Authentication and access-related events
- Failed or suspicious authentication activities
- Administrative and privileged activities
- Changes to identities, accounts, roles, and entitlements
- Role and access assignment changes
- Access request and approval activities
- Provisioning and de-provisioning activities
- Failed provisioning or synchronization events
- Configuration and policy changes
- Privileged or sensitive changes within the Omada platform
- Security-related system or integration events
- Relevant audit activities that may support incident investigation and forensic analysis
The final event catalogue will be based on events actually available within the applicable Omada environment and product configuration.
3. Logging & Monitoring Concept
Develop an Omada-specific logging and monitoring concept covering:
- Relevant Omada log sources
- Security-relevant event categories
- Recommended events for centralized monitoring
- Event prioritization and severity considerations
- Monitoring and detection use cases
- Required event information and contextual fields
- Auditability and traceability requirements
- Log availability and retention considerations
- Identification of gaps between available logging and security-monitoring requirements
- Recommendations for addressing identified gaps
4. Log Export & Integration Assessment
Evaluate technically feasible mechanisms for providing Omada security and audit logs to centralized monitoring platforms.
The assessment should cover, where applicable:
- Native Omada logging/export capabilities
- APIs and supported interfaces
- File-based log collection
- Database or audit-data interfaces
- Connector or integration mechanisms
- Potential SIEM/SOC integration approaches
- Log format and event structure
- Data normalization requirements
- Event filtering and security relevance
- Reliability and completeness of log transfer
- Security and access considerations associated with log collection
- Technical dependencies and constraints
The objective is to provide an integration assessment and recommendation, rather than perform the production integration.
Deliverables
The consultant will be responsible for producing the following professional documentation artifacts:
1. Omada Audit Log Inventory & Assessment
A structured inventory containing:
- Available log sources
- Audit-log categories
- Relevant event types
- Event information/attributes
- Security relevance
- Monitoring suitability
- Availability and accessibility
- Known limitations or gaps
2. Omada Logging & Monitoring Concept
A comprehensive concept defining:
- Logging objectives
- Relevant security events
- Security monitoring requirements
- Event prioritization
- Monitoring recommendations
- Proposed approach for centralized security monitoring
3. Security Event Catalogue
Structured documentation of security-relevant events and log types, including recommendations regarding which events should be forwarded to centralized security monitoring.
4. Technical Integration Assessment
Assessment of the available methods for extracting and/or providing Omada audit information to centralized security-monitoring infrastructure, including technical dependencies, limitations, and recommended integration approach.
5. Gap Analysis & Recommendations
Identification of differences between:
- Required security-monitoring capabilities
- Available Omada logging capabilities
- Events currently available for monitoring
- Events/information required for effective security monitoring
Each identified gap should include an appropriate recommendation or proposed remediation approach.
6. Final Technical Documentation
A consolidated final document containing:
- Executive summary
- Current-state assessment
- Log-source inventory
- Security-event catalogue
- Logging and monitoring concept
- Integration assessment
- Gap analysis
- Assumptions and dependencies
- Technical limitations
- Identified risks
- Recommendations
- Proposed next steps for subsequent implementation
Requirements
Required Skills & Experience
Essential
- Strong experience with Omada Identity Platform / Omada Identity
- Strong understanding of Identity Governance and Administration (IGA/IAM)
- Experience analyzing application and security audit logs
- Good understanding of security logging and monitoring principles
- Experience with centralized security monitoring and SIEM concepts
- Understanding of identity-related security events and detection use cases
- Experience assessing application integration with security-monitoring platforms
- Ability to analyze technical log formats, events, interfaces, and APIs
- Experience developing structured technical and security documentation
- Strong analytical and stakeholder communication skills
- Ability to work independently and deliver a defined technical work package
Highly Desirable
Experience with one or more of the following would be advantageous:
- Microsoft Sentinel
- Splunk or comparable SIEM platforms
- SOC monitoring processes
- Identity threat detection and monitoring
- Privileged access monitoring
- Security audit and compliance requirements
- Log-management architecture
- REST/API-based security integrations
- Syslog or equivalent event-forwarding mechanisms
- Identity lifecycle and provisioning processes
- Security monitoring for business-critical applications
Required Skills & Experience
Essential
- Strong experience with Omada Identity Platform / Omada Identity
- Strong understanding of Identity Governance and Administration (IGA/IAM)
- Experience analyzing application and security audit logs
- Good understanding of security logging and monitoring principles
- Experience with centralized security monitoring and SIEM concepts
- Understanding of identity-related security events and detection use cases
- Experience assessing application integration with security-monitoring platforms
- Ability to analyze technical log formats, events, interfaces, and APIs
- Experience developing structured technical and security documentation
- Strong analytical and stakeholder communication skills
- Ability to work independently and deliver a defined technical work package
Highly Desirable
Experience with one or more of the following would be advantageous:
- Microsoft Sentinel
- Splunk or comparable SIEM platforms
- SOC monitoring processes
- Identity threat detection and monitoring
- Privileged access monitoring
- Security audit and compliance requirements
- Log-management architecture
- REST/API-based security integrations
- Syslog or equivalent event-forwarding mechanisms
- Identity lifecycle and provisioning processes
- Security monitoring for business-critical applications
Expected Consultant Profile
The ideal consultant combines Omada/IGA expertise with cybersecurity logging and SIEM knowledge.
This is not purely an Omada administration role and not purely a SOC/SIEM role. The consultant should be capable of bridging:
Omada / IGA → Audit & Security Events → Logging Architecture → SIEM/SOC Monitoring
The consultant must also be comfortable independently investigating platform capabilities and translating technical findings into clearly structured security requirements and recommendations.
Scope Boundaries
In Scope
- Analysis and assessment
- Technical workshops/interviews where required
- Omada logging capability assessment
- Audit-event analysis
- Security-event identification
- Logging and monitoring concept development
- Integration-option assessment
- Security-monitoring gap analysis
- Risk and limitation documentation
- Technical recommendations
- Final documentation
Explicitly Out of Scope
The following activities are not part of this engagement:
- Production implementation
- SIEM connector implementation
- Production configuration changes
- Deployment of monitoring rules
- Operational acceptance/testing
- Production rollout
- Ongoing SOC monitoring
- Incident response operations
- Ongoing application support
- Subsequent operational activities
Recommendations and implementation guidance may be documented, but execution of the implementation remains outside the scope of the engagement.
Engagement Success Criteria
The work package will be considered successful when:
- Available Omada audit and security log sources have been systematically documented.
- Security-relevant Omada events have been identified and classified.
- The suitability of those events for centralized monitoring has been assessed.
- A practical Omada-specific logging and monitoring concept has been established.
- Technically feasible log-export and integration approaches have been assessed.
- Monitoring gaps, limitations, assumptions, and risks have been documented.
- Clear technical recommendations have been provided to support a subsequent implementation phase.