Nexora Elite

2 jobs near Columbus, OH

Identity Management Engineer ( Associate Level)

Nexora Elite, LLC

Chicago, IL • Remote

$80K - $110K/yr

Full-time

Posted 8 days ago


Job description

POSITION SUMMARY

The Identity Management Engineer supports the design, implementation, migration, and daily operation of enterprise identity and access management capabilities. Working with senior engineers, application teams, cybersecurity, infrastructure, and compliance partners, this role helps onboard applications, modernize authentication, improve identity governance, and maintain reliable access throughout the identity lifecycle.

KEY RESPONSIBILITIES

·         Assist with onboarding enterprise and SaaS applications to Microsoft Entra ID, Ping Identity, Active Directory, and related identity platforms.

·         Configure and support SSO and federation using SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), and foundational SCIM provisioning patterns.

·         Support application IAM and identity-governance migrations, including discovery, requirements gathering, testing, documentation, cutover, and post-migration validation.

·         Help implement joiner, mover, and leaver processes; access requests; group and role assignments; and periodic access certifications.

·         Support modern authentication capabilities such as MFA, passwordless authentication, FIDO2 security keys, Windows Hello for Business, and passkeys.

·         Troubleshoot authentication, authorization, directory synchronization, provisioning, and account-lifecycle issues across cloud and on-premises environments.

·         Assist with Conditional Access policies, identity risk controls, service accounts, application identities, managed identities, and workload identity configurations under established standards.

·         Collect audit evidence, remediate control findings, and work with compliance teams to support access reviews and regulatory or internal assessments.

·         Maintain runbooks, configuration records, application integration diagrams, test evidence, and operational knowledge articles.

·         Participate in incident response, change management, release validation, and production support rotations as assigned.

REQUIRED QUALIFICATIONS

·         1-3 years of experience in IAM, directory services, cybersecurity, cloud engineering, systems administration, or application support.

·         Hands-on exposure to Microsoft Entra ID and Active Directory; experience with Ping Identity, Okta, SailPoint, Saviynt, CyberArk, or a comparable platform is beneficial.

·         Working knowledge of users, groups, enterprise applications, authentication methods, RBAC, and least-privilege principles.

·         Basic understanding of SAML, OAuth 2.0, OIDC, LDAP, Kerberos, SCIM, MFA, certificates, APIs, and modern passwordless authentication.

·         Ability to troubleshoot technical issues, follow change controls, document work clearly, and collaborate across application and compliance teams.

·         Bachelor's degree in cybersecurity, computer science, information systems, engineering, or a related field, or equivalent practical experience.

PREFERRED QUALIFICATIONS

·         Experience with PowerShell, Microsoft Graph, REST APIs, JSON, Python, or other automation tools.

·         Exposure to identity governance and administration (IGA), privileged access management (PAM), CI/CD, cloud platforms, or IT service-management tools.

·         Foundational certification such as Microsoft SC-300, Security+, Azure Fundamentals, or equivalent.