
Senior ISVA/ISAM Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in India.
• Design, install, configure, manage, migrate, upgrade, patch, and oversee the lifecycle of ISVA/ISAM/ISVIA virtual appliances.
• Configure and provide support for WebSEAL, Policy Server, Runtime Components, Federation Services, Advanced Access Control, authorization policies, and reverse proxy components.
• Design and manage clustered, highly available ISVA environments that are ready for disaster recovery.
• Oversee snapshots, backups, restores, runbooks, rollback plans, and production cutover activities.
• Diagnose complex issues related to authentication, authorization, SSO, federation, appliances, certificates, and access policies.
• Develop and implement enterprise SSO solutions utilizing SAML 2.0, OAuth 2.0, OIDC, and JWT.
• Configure IdP/SP integrations, federation partners, metadata, certificates, endpoints, bindings, signatures, and encryption settings.
• Create and troubleshoot claims, assertions, scopes, token attributes, subject identifiers, relay state, ACS URLs, and redirect URIs.
• Assess SAML assertions, OAuth/OIDC tokens, authorization code flows, refresh token behavior, PKCE, and token validation issues.
• Facilitate onboarding of SaaS and on-premises applications to enterprise SSO platforms and support federation migration initiatives.
• Develop, refine, and troubleshoot ISVA mapping rules using JavaScript.
• Execute attribute mapping, claims transformation, token customization, session handling, and policy-driven access flows.
• Integrate mapping rules with LDAP attributes, HTTP headers, REST APIs, and external decision points.
• Install, configure, manage, and troubleshoot IBM Security Directory Server.
• Provide support for schema management, indexing, replication, backup, restoration, tuning, and high availability configuration.
• Troubleshoot LDAP bind, search, replication, SSL/TLS, schema, and performance issues.
• Assist in directory migration and integration with IAM platforms.
• Lead technical discussions with application, infrastructure, network, security, and vendor teams.
• Produce documentation including runbooks, architecture notes, implementation plans, rollback plans, and knowledge transfer materials.
• Conduct end-to-end troubleshooting across ISVA/ISAM, WebSEAL, AAC, federation, mapping rules, IBM Security Directory Server, LDAP, certificates, DNS, and load balancers.
• Analyze request flows, authentication traces, policy decisions, junction behavior, HTTP headers, cookies, and session-related issues.
• Debug SAML/OAuth/OIDC issues including metadata mismatches, assertion validation, signature/encryption failures, redirect URI concerns, clock skew, and certificate trust failures.
• Over 10 years of IAM experience with extensive hands-on ISVA/ISAM administration.
• Practical experience with ISVA/ISAM installation, configuration, migration, upgrades, WebSEAL, Policy Server, AAC, Federation, reverse proxy, and appliance operations.
• Profound knowledge in SAML 2.0, OAuth 2.0, OpenID Connect, JWT, metadata, certificates, token claims, and trust configuration.
• Hands-on JavaScript experience in mapping rule development for SAML, OAuth, OIDC, attribute transformation, and custom authentication logic.
• Familiarity with IBM Security Directory Server, LDAP schema, replication, indexing, tuning, and SSL/TLS.
• Understanding of certificates, PKI, TLS, Linux/Unix, load balancers, DNS, networking fundamentals, logging, monitoring, and incident management in production.
• Experience with shell scripting, Python, JavaScript, REST APIs, log analysis, and automation support.
• Must be located in India and work during India Standard Time (IST) hours.
• Preferred but not required: IBM Verify (SaaS) experience.
• Preferred familiarity with IBM Security Identity Manager / IBM Security Verify Governance, IBM Security Directory Integrator, Azure AD / Microsoft Entra ID, AWS Cognito, Kubernetes, or OpenShift.
• Preferred experience leading IAM migration, modernization, consolidation, or platform upgrade projects.
• Preferred experience in creating architecture diagrams, technical design documents, SOPs, runbooks, and knowledge transfer materials.
• Paid hourly.
• Remote work arrangement.
• Contract opportunity.
Anduril Industries
Sargent & Lundy
Sargent & Lundy
Get handpicked remote jobs straight to your inbox weekly.