
Identity Management Engineer – Architect
Posted 19 hours ago

Posted 19 hours ago
This is a fully remote position, open to applicants in United States.
• Design, develop, and manage enterprise IAM / ICAM architectures that support on-premises, cloud, SaaS, and hybrid environments.
• Engineer and sustain directory services, including Active Directory and Microsoft Entra ID.
• Create and automate processes for user provisioning, deprovisioning, role assignment, access modifications, and identity lifecycle management.
• Integrate enterprise applications utilizing SAML, OpenID Connect (OIDC), OAuth, and SCIM protocols.
• Establish and uphold Privileged Access Management controls for administrative, elevated, and high-risk accounts.
• Design and manage Identity Governance and Administration capabilities through SailPoint or other approved enterprise identity governance platforms.
• Integrate and oversee AWS IAM Identity Center along with related AWS identity and access management features.
• Implement smart-card authentication (PIV/CAC), certificate-based authentication, and other sanctioned strong-authentication methods.
• Enforce phishing-resistant multi-factor authentication for privileged and mission-critical access.
• Ensure alignment of identity architectures, authentication methods, credential lifecycle processes, and access controls with FICAM requirements and pertinent government identity standards.
• Develop and enforce least-privilege, role-based, and policy-driven access controls.
• Automate identity management processes using scripting, APIs, infrastructure as code, and workflow technologies.
• Integrate PAM, IGA, directory services, cloud identity, and authentication platforms.
• Execute monitoring, logging, auditing, and alerting for authentication events, privileged activities, identity lifecycle changes, and access policy violations.
• Conduct access reviews, entitlement assessments, privileged account evaluations, and identity governance activities.
• Collaborate with application, cloud, cybersecurity, platform, and DevSecOps teams to onboard applications and services into enterprise identity platforms.
• Troubleshoot issues related to authentication, federation, provisioning, directory synchronization, authorization, and access management.
• Maintain documentation of identity architecture, integration standards, operational procedures, access control models, and governance processes.
• Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical field.
• Proven experience in designing, engineering, or administering enterprise IAM / ICAM solutions.
• Strong expertise in Active Directory and cloud-based directory services like Microsoft Entra ID.
• Practical experience with SAML, OIDC, OAuth, and SCIM.
• Experience in implementing or operating Privileged Access Management platforms and privileged identity workflows.
• Familiarity with Identity Governance and Administration, preferably using SailPoint IdentityIQ or SailPoint Identity Security Cloud.
• Experience with AWS IAM, AWS IAM Identity Center, and cloud identity integration.
• Comprehensive understanding of authentication, authorization, RBAC, ABAC, least privilege, and identity lifecycle management.
• Experience with PIV/CAC, certificate-based authentication, and phishing-resistant multi-factor authentication.
• Knowledge of FICAM, federal identity standards, and authentication requirements applicable to government environments.
• Solid understanding of Zero Trust architecture.
• Experience in automating identity workflows using APIs, scripting languages, PowerShell, Python, Terraform, or similar automation technologies.
• Proficiency in integrating identity platforms with SaaS applications, cloud services, enterprise applications, and hybrid infrastructures.
• Experience with centralized logging, identity monitoring, audit reporting, access reviews, and compliance evidence collection.
• Experience supporting government, defense, GovCloud, or other regulated environments is preferred.
• Strong skills in architecture, troubleshooting, documentation, governance, and cross-functional collaboration.
• Preferred certifications include: AWS Certified Security – Specialty; Microsoft Certified: Identity and Access Administrator Associate (SC-300); Microsoft Certified: Cybersecurity Architect Expert (SC-100); CISSP; SailPoint IdentityIQ / Identity Security Cloud certification; CyberArk Defender or CyberArk Sentry.
• Competitive salary paid bi-monthly.
• Comprehensive medical coverage.
• Full coverage of medical premiums by True Zero.
• Company-wide incentives for new business initiatives.
• Contribution Incentives (e.g., white papers, blog posts, internal webinars, etc.).
• Starting with 3 weeks of PTO plus 11 Paid Holidays each year.
• 401k Program with a 100% company match on the first 4% contributed.
• Monthly reimbursement for Cell Phone and Home Internet expenses.
• Paternity and Maternity Leave.
• Investment in training and certifications to enhance and expand your technical skills.
Illumination Works
Agility Technologies Inc
Salesforce
Get handpicked remote jobs straight to your inbox weekly.