Job title: Authentication & Access Management Sr. Engineer/Architect
Location: Fully Remote (EST or CST time)
Longterm Contract
Must Haves
10+ years of experience
IAM Experience
IAM product experience
LDAP & active directory integration experience
Authentication & Access Management Sr. Engineer/Architect
The identity & Access Management (IAM) team is looking for an Authentication & Access Management Sr. Engineer/Architect to implement the next-generation Identity solution for enterprise users.
Technical Requirements
- Overall 10+ years of hands-on working experience in the Identity and Access Management area at the enterprise level.
- The person must be able to understand and gather business requirements, translate them to technical requirements and design the solution to meet the tactical and strategic approaches.
- The person must be able to produce architectural patterns and solution design documents.
- A hands-on technical experience is required to conduct the POC and solution design in a development environment.
- Must have the ability to lead the discussion with various folks including business, engineering, and operation teams.
- The person must be an expert in Authentication & Access Management area and related technology.
Authentication space (7+ years):
Multi-factor authentication (MFA) including password less MFA
Security knowledge of various technology & protocols - FIDO, PKI, Mobile MFA, OTP, FIDO key, Biometric authentication, behavior & risk-based authentication
Implementation experience with web, device (laptop, etc.), infrastructure, and API authentication use cases.
Mobile security knowledge is a plus.
Access Management space (7+ years):
Identity Federation & Single Sign-On (SSO)
Expert knowledge of implementing SAML, OpenID Connect (OIDC), and OAuth 2.0
Security knowledge about session management
Identity gateway (proxy) and similar implementation knowledge
Continuous access control
Integration with cloud and on-premises systems including Azure AD, GCP, Salesforce, etc.
- Should have REST API and JSON working experience.
- Must have LDAP and Active Directory integration experience.
- Should have some development experience in building POC and prototypes.
- Working knowledge of some of the IAM products is required.
PingIdentity, Okta, HYPR, Axiad, ForgeRock, SiteMinder, TransmitSecurity, Azure AD, etc.
Centrify/Delinea, BeyondTrust, CyberARK, etc.
- Azure and GCP cloud experience are a plus.
- Zero trust implementation experience is a big plus.
Preferred
- The expertise in Privileged Access Management area
- Privileged Access Management for admin and privileged accounts
- Just in time and time based access control
- Access control solution for Linux, Windows servers, Kubernetes/docker, databases, Clouds and other PAM use cases.
- CISSP certification
- Development experience in any of the technologies, Java, Powershell, etc.