
Staff Identity Engineer β Radiant One
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Canada, +1 more country.
β’ Design, implement, and optimize Identity Fabric environments, encompassing replication topology, ACIs, high-availability setups, and performance optimization for enterprise-scale applications.
β’ Create identity provisioning workflows and develop bespoke connectors, including custom integrations that extend beyond standard configurations.
β’ Lead initiatives for directory consolidation, migration, and hybrid identity, which involve multi-forest Active Directory and Azure AD/Entra integration.
β’ Act as the technical escalation point for production challenges related to directory replication, provisioning failures, and identity correlation conflicts.
β’ Conduct root cause analyses and implement sustainable solutions.
β’ Collaborate with IAM governance, security architecture, and application teams to ensure directory and provisioning capabilities are in sync with the overarching identity strategy.
β’ Establish technical guidelines and best practices for directory and provisioning engineering.
β’ Provide mentorship to senior and mid-level engineers.
β’ Develop Python and PowerShell automation tools to minimize manual operational tasks and enhance reliability.
β’ Document architectural decisions, design considerations, and operational runbooks.
β’ Assess and influence roadmap decisions concerning the directory and provisioning technology stack.
β’ Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent professional experience.
β’ Over 8 years of practical experience in enterprise Identity and Access Management, specifically in identity provisioning and directory services.
β’ Direct production experience with Radiant Logic RadiantOne, including virtual directory design and identity correlation/aggregation.
β’ Direct production experience with Ping Directory or PingDirectoryProxy, focusing on replication and performance tuning.
β’ Extensive knowledge of LDAP/LDAPS fundamentals, including schema design, referrals, and resolving replication conflicts.
β’ Experience in designing and building provisioning workflows and connectors, including SCIM, JIT, and custom connector development.
β’ Proficiency in scripting languages such as JavaScript, Python, and PowerShell for automation, tooling, and provisioning tasks.
β’ Capability to make informed architectural trade-offs and guide technical direction for fellow engineers.
β’ Ability to thrive in a remote-first team environment.
β’ Familiarity with SailPoint IdentityIQ or other Identity Governance and Administration (IGA) platforms and collaboration with governance teams.
β’ Experience with hybrid identity architectures, Azure AD/Entra ID, and multi-forest Active Directory environments.
β’ Understanding of Privileged Access Management (PAM) boundaries, service account lifecycle, and privileged directory access.
β’ Experience leading directory consolidation or large-scale migration initiatives.
β’ Previous experience mentoring engineers or informally guiding technical direction within a team.
β’ Medical, dental, and vision insurance.
β’ 401(k) plan.
β’ Paid leave.
β’ Tuition reimbursement.
β’ A variety of additional discounts and perks.
β’ Eligibility for bonuses.
Mercor
RTX
Expel
Qualus
Get handpicked remote jobs straight to your inbox weekly.