OPEN JOB: Senior Identity Services Engineer LOCATION:New York City ***This role is mostly remote. BUT May require occasional onsite presence; therefore should live within a commutable distance of Manhattan. SALARY: $97000 to $145000 FULLTIME FULL BENEFITS
CLIENT: LARGE PRESTIGIOUS NYC HOSPITAL
SUMMARY:
Operates and maintains the Information Security teams portfolio of access management an federation products.
Responsible for application integration implementation of access control systems data analytics report generation incident investigation/remediation server administration and team mentorship.
Performs extensive operational and strategic level duties with the ability to serve in an architectural capacity providing the appropriate information and planning required for new technology and policy deployments.
ESSENTIAL JOB DUTIES:
Design implement and support enterprise SSO solutions (e.g. PingFederate Azure AD Okta)
Maintain and enhance access management platforms and federation infrastructure
Lead application integrations into existing SSO frameworks using SAML OAuth2 and OIDC
Implement and support RoleBased Access Control (RBAC) and modern authentication methods
Support and improve authentication strategies across the organization
Collaborate with information security app owners and infrastructure teams to deliver secure identity solutions
Troubleshoot complex authentication and federation issues across multiple environments
Participate in IAM roadmap planning and contribute to architectural decisions
Provide mentorship and technical guidance to IAM engineers
Support governance efforts related to authentication authorization and access control standards
REQUIRED QUALIFICATIONS:
5 years of Identity & Access Management experience with a strong focus on SSO and federation
Deep technical knowledge of:
PingFederate Azure AD Okta ADFS
Federation protocols including SAML OIDC and OAuth2
LDAP Active Directory SCIM
Proficiency in scripting and development with PowerShell Python and Java
Experience working with REST APIs for IAM services; familiarity with Postman or similar tools
Familiarity with OGNL expression language for customizing PingFederate policies
Frontend UX design and customization using HTML CSS and JavaScript
Basic Linux administration skills for maintaining and managing IAM infrastructure
Working knowledge of certificates and PKI (X.509 certificate chains signing encryption keystore management)
Strong troubleshooting and debugging skills across application identity and network layers
Understanding of modern identity concepts such as Zero Trust adaptive authentication (riskbased device/user signals) and conditional access
PREFERRED QUALIFICATIONS
Handson experience with the Ping Identity platform particularly:
PingFederate PingOne PingID PingDirectory
Experience with MFA and Passwordless/FIDO2/WebAuthn authentication strategies
Experience building and configuring enterprise SSO applications in Azure AD / Entra ID
Exposure to IAM orchestration platforms such as PingOne DaVinci or similar tools
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.