Title: IAM (Identity Access Management)
Location: Plano, TX OR Bethpage, NY (Hybrid)
Duration: 6+ months
Implementation Partner: Infosys
End Client: To be disclosed
JD
- Need Customer Identity Engineers with experience migrating legacy customer-facing applications and custom identity databases to a centralized CIAM platform using Auth0 by Okta.
- The Identity & Access Management Engineer will provide Identity and Access Management consulting and engineering services supporting customer identity platform configuration, integration, migration, and authentication modernization initiatives.
Responsibilities:
- IDP Platform Administration & Configuration
- Administer and configure the enterprise IDP tenant day-to-day: application integrations (OIDC, SAML), sign-on policies, MFA enrollment policies, network zones, and trusted origins.
- Build and maintain Customer IDP schema - custom attributes, group rules, attribute mappings, and user profile transformations that support accurate identity data across all integrated systems.
- Design and implement IDP Lifecycle Management configurations for automated provisioning and de-provisioning via SCIM 2.0 and Workflows, covering Joiner / Mover / Leaver events.
- Develop and maintain workflows (no-code/low-code) and Event Hooks for automated identity orchestration, exception routing, and audit logging.
- Manage IDP authorization servers: custom scopes, claims, access policies, and token lifetime configurations aligned to application security requirements.
- Monitor platform health via system logs and integrated SIEM tooling; triage alerts, identify anomalies, and escalate or remediate per runbook.
- Create and maintain platform operational documentation along with providing customer facing support teams tools, job aids and runbooks.
- Authentication Modernization & Application Migration.
- Execute the migration of applications from legacy authentication mechanisms to customer IDP SSO, working from migration playbooks defined by the IAM Manager and adapting them to eachapplication' s specific stack and constraints.
- Perform OIDC and SAML application registrations in IDP: configure redirect URIs, response types, grant types, initiated login URIs, and post-logout behavior.
- Test end-to-end authentication and authorization flows in development, staging, and production environments; document results and coordinate with application teams to resolve gaps before go-live.
- Support the enablement of passwordless and phishing-resistant authentication.
- Maintain the migration tracker and contribute status updates for leadership reporting on the application portfolio onboarding roadmap.
- Application Team Enablement & Technical Support
- Serve as a first-line technical advisor for application development teams integrating with IDP -answering questions on SDK selection, token design, scope modeling, and session management in office hours and async channels.
- Write and maintain integration guides, code samples, and reference implementations (JavaScript, Java, Python, or Go) to help application teams onboard with minimal friction.
- Diagnose and resolve complex authentication failures, token validation errors, and SCIM provisioning issues by reviewing system logs, HAR files, and application-side logs.
- Participate in architecture reviews for new application integrations, flagging identity anti-patterns and recommending standards-compliant alternatives.
- Contribute to the IAM community of practice: share knowledge through documentation, recorded demos, and team enablement sessions.
- Security, Compliance & Identity Operations
- Implement and validate authentication policy controls: step-up MFA triggers, adaptive access rules, session expiration, and assurance-level requirements aligned to data sensitivity classifications.
- Support access certification campaigns by producing accurate user-application access reports from IDP data and coordinating with application owners on remediation.
- Contribute to audit evidence collection for SOX, SOC 2, PCI-DSS, and privacy-related IAM controls; maintain accurate configuration documentation as a control artifact.
- Participate in IAM incident response: diagnose authentication outages, credential compromise events, or misconfiguration issues; execute runbook remediation steps and contribute to post-incident reviews.
- Apply and track IDP configuration hygiene: unused apps, dormant users, overly permissive policies, and API token rotation - following the team's security baseline standards.
- Tooling, Automation & Continuous Improvement
- Build and maintain automation scripts and Infrastructure-as-Code (IaC) configurations for repeatable configuration management using Terraform or equivalent.
- Contribute to the IAM team's CI/CD pipeline for configuration deployments: write tests for policy changes, peer-review pull requests, and promote changes through dev/stage/prod environments.
- Identify operational toil and propose automation or tooling improvements to reduce manual work for the team and for application teams onboarding to IDP.
- Evaluate new IDP features and Identity Engine capabilities; prepare proof-of-concept implementations and recommendations for the Manager to consider for roadmap inclusion.
Qualifications Required
- 3+ years of experience in Identity and Access Management, IT security, or a closely related technical discipline with hands-on platform administration responsibilities.
- Demonstrated, hands-on experience administering customer IDP's in a production environment: application integrations, sign-on policies, MFA, Universal Directory, and Lifecycle Management.
- Working knowledge of identity protocols and standards: OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and SCIM 2.0 - able to read and interpret protocol flows, tokens, and assertions.
- Experience troubleshooting authentication and provisioning issues end-to-end using system logs, browser developer tools, and HAR file analysis.
- Ability to read and write code in at least one modern language (JavaScript/Node.js, Python, Java, or Go) sufficient to build integrations, automation scripts, and code samples.
- Comfortable working directly with application development teams in a consulting or enablement capacity - able to explain IAM concepts clearly to non-IAM engineers.
- Familiarity with private cloud and cloud platforms (AWS, Azure, or GCP) and how identity integrates with cloud-native services (e.g., API Gateway authorizers, managed identity, cloud IAM roles).
Preferred
- Certifications in customer identity platforms. (or willingness to obtain within 6 months of hire).
- Experience with workflows for no-code/low-code identity orchestration.
- Hands-on experience with FIDO2/WebAuthn or phishing resistant enrollments and policy configuration.
- Experience managing IDP configuration as code using Terraform or similar IaC tools.
- Familiarity with CIAM-specific patterns: progressive profiling, social login (Google, Apple, Facebook), consent and preference management, and customer-facing MFA enrollment UX.
- Exposure to SIEM integration for identity telemetry, and experience writing alert logic or dashboards for IAM signals.
- Understanding of Zero Trust principles and practical experience implementing device trust or continuous access evaluation policies.
- Bachelor' s degree in Computer Science, Information Systems, Cybersecurity, or a related field; equivalent experience considered.