
IAM Software Engineer
Posted Aug 26

Posted Aug 26
This is a fully remote position, open to applicants in United States.
β’ Design, develop, and integrate RESTful APIs that facilitate identity workflows and partner application authentication.
β’ Implement OAuth 2.0, OpenID Connect (OIDC), PKCE, and secure token management practices.
β’ Construct secure API authentication and authorization services utilizing JWT, access tokens, and refresh tokens.
β’ Integrate backend services with the Okta Identity Engine (OIE), Okta Embedded SDK, and Department of Defense (DoD) enterprise IAM solutions.
β’ Execute identity service integrations with authoritative identity repositories and enterprise data sources.
β’ Create secure backend web services using Java, Spring Boot, .NET, or comparable technologies.
β’ Support API gateway configurations, microservices architecture, and service orchestration practices.
β’ Implement JSON/XML data exchange models and API contracts for partner application usage.
β’ Apply enterprise integration patterns and asynchronous messaging through queues, events, and service buses.
β’ Design authentication workflow orchestration and session management services.
β’ Develop backend services that support mobile authentication for native iOS and Android applications.
β’ Employ advanced API security practices, including OWASP API Security Top 10, mTLS, and certificate-based authentication.
β’ Implement secure database integration and data access methodologies.
β’ Create reusable identity services that support multiple partner applications.
β’ Implement API Gateway integrations.
β’ Establish enterprise audit logging and operational telemetry.
β’ Contribute to CI/CD pipelines, automated builds, and DevSecOps processes.
β’ Conduct unit, integration, and API testing.
β’ Engage in Agile development, Git-based version control, and secure configuration management.
β’ Integrate enterprise ICAM/CIAM platforms within cloud or hybrid environments.
β’ Ensure identity solutions adhere to NIST SP 800-63 Digital Identity Guidelines and Zero Trust Architecture principles.
β’ Support DoD cybersecurity requirements, including RMF and STIG compliance.
β’ 5 years of experience with a BS/BA; 3 years with an MS/MA; 0 years with a PhD; 9 years with a high school diploma.
β’ Must be able to obtain and maintain a Public Trust clearance.
β’ U.S. Citizenship is required.
β’ Proven experience in designing, developing, and integrating RESTful APIs.
β’ Strong understanding of OAuth 2.0, OpenID Connect (OIDC), PKCE, and token management.
β’ Experience in implementing secure API authentication and authorization using JWT, access tokens, and refresh tokens.
β’ Familiarity with integrating the Okta Identity Engine (OIE) and enterprise IAM services.
β’ Experience in integrating identity services with authoritative identity repositories.
β’ Background in secure backend development utilizing Java, Spring Boot, .NET, or similar frameworks.
β’ Exposure to API gateways, microservices, and backend orchestration.
β’ Proficiency in JSON/XML and API contract development.
β’ Experience with enterprise integration patterns and asynchronous messaging.
β’ Understanding of authentication workflow orchestration and session management.
β’ Experience in building backend services that support native mobile authentication.
β’ Knowledge of API security best practices, including OWASP API Security Top 10, mTLS, and certificate authentication.
β’ Experience with databases and secure data access methodologies.
β’ Familiarity with CI/CD pipelines and DevSecOps environments.
β’ Hands-on experience with unit, integration, and API testing tools such as Postman and Swagger/OpenAPI.
β’ Experience in supporting enterprise ICAM/CIAM solutions in cloud or hybrid architectures.
β’ Knowledge of NIST SP 800-63 and Zero Trust Architecture.
β’ Experience in supporting RMF and STIG cybersecurity compliance.
β’ Preferred: Experience integrating backend services with Okta Identity Engine Embedded SDK.
β’ Preferred: Experience supporting large-scale Federal ICAM/CIAM programs.
β’ Preferred: Knowledge of DoD identity services, CAC/PIV, derived credentials, or enterprise credentialing.
β’ Preferred: Experience with event-driven architectures or high-security distributed systems.
β’ Preferred: Familiarity with DoD Zero Trust initiatives and identity modernization.
β’ Potential eligibility for overtime.
β’ Potential eligibility for shift differential.
β’ Potential eligibility for discretionary bonus.
Arista Networks
Coforma
Platform.sh
Arista Networks
Get handpicked remote jobs straight to your inbox weekly.