Job Description - Senior ICAM Engineer, Full Time, Remote
Description
Mount Airey Group (MAG), a wholly owned subsidiary of Technologist Inc., is seeking a Senior Identity, Credential and Access Management (ICAM) Engineer to join our team. This is a full-time telework opportunity offering a competitive salary coupled with a stellar benefits package effective your first day of employment.
The Senior ICAM Engineer is responsible for the engineering, implementation, automation, administration, and operational support of enterprise Identity, Credential, and Access Management (ICAM) services. This role designs and implements secure identity solutions supporting authentication, authorization, identity lifecycle management, and Zero Trust initiatives. The engineer develops automation using PowerShell and the Okta REST APIs to improve operational efficiency, reduce manual administration, and support enterprise identity operations across cloud and on-premises environments. The engineer will also evaluate and adopt emerging automation technologies, including Python, to enhance future automation capabilities.
Primary Responsibilities
Administer, configure, and maintain enterprise Okta Identity Cloud environments supporting workforce identity and access management.
Design, implement, and troubleshoot Single Sign-On (SSO) integrations using SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC).
Configure and maintain authentication policies, adaptive Multi-Factor Authentication (MFA), phishing-resistant authentication, and application sign-on policies.
Develop and maintain user lifecycle automation, including provisioning, deprovisioning, profile mappings, attribute transformations, group rules, and application assignments.
Design, configure, and support inbound and outbound identity federation with internal and external Identity Providers (IdPs).
Develop and maintain custom user profile attributes, application profile mappings, and identity schemas to support business and partner requirements.
Integrate enterprise applications with Okta while ensuring compliance with organizational security policies and Federal ICAM standards.
Troubleshoot complex authentication, federation, provisioning, authorization, and identity synchronization issues across cloud and on-premises environments.
Develop and maintain PowerShell automation utilizing the Okta REST APIs to perform administrative functions, user lifecycle management, reporting, and large-scale user profile updates.
Design and execute automated batch processes for creating, modifying, and updating user identities while ensuring data integrity, consistency, and auditability.
Develop reusable automation scripts and tools that improve operational efficiency and reduce manual administrative effort.
Integrate enterprise systems using REST APIs to automate identity management workflows and improve data consistency across identity repositories.
Evaluate and develop future automation capabilities using Python to support API integrations, reporting, and enterprise automation initiatives.
Support Public Key Infrastructure (PKI), PIV/CAC authentication, certificate-based authentication, and smart card integrations.
Develop technical architecture documentation, implementation guides, standard operating procedures, workflow diagrams, and engineering documentation.
Participate in Zero Trust initiatives by implementing modern identity-centric security controls and authentication mechanisms.
Analyze identity-related security events and assist with audit, compliance, and forensic investigations.
Collaborate with cybersecurity, infrastructure, networking, and application teams to implement secure identity solutions.
Perform testing, change management, production deployments, and Tier III engineering support for enterprise identity services.
Research, evaluate, and recommend new identity technologies and automation solutions that improve security, reliability, and operational efficiency.
Technical Requirements:
Okta Identity Cloud
Microsoft Entra ID
Ping Identity
PowerShell
Okta REST APIs
REST APIs
JSON
Identity Lifecycle Management
SAML 2.0
OAuth 2.0
OpenID Connect (OIDC)
Multi-Factor Authentication
Identity Federation
Active Directory
LDAP
PKI
PIV/CAC Authentication
Zero Trust Architecture
Technical Documentation
Enterprise Identity Troubleshooting
Expected Experience:
Experience implementing and supporting:
Single Sign-On (SAML 2.0, OAuth 2.0, OpenID Connect)
Multi-Factor Authentication (MFA)
Identity Federation
User Lifecycle Management
Active Directory and LDAP
REST API integrations
Experience developing automation using PowerShell.
Experience consuming and integrating REST APIs.
Experience working with JSON and API payloads.
Requirements
Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or related field, or equivalent professional experience.
Minimum of 2 (two) years of daily hands-on experience administering and engineering solutions using Okta Identity Cloud, including application integrations, identity lifecycle management, automation, and REST API development.
OR
Minimum of 3 (three) years of hands-on experience administering an enterprise Identity and Access Management platform such as Microsoft Entra ID, Ping Identity, ForgeRock, or a comparable IAM solution.
Ability to obtain Secret level clearance.
Ability to travel to Washington, DC for important meetings.
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the US.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the US, connecting you to thousands of jobs fast!
Find the best jobs in the US, apply in 1 click and get a job today!