ASSYST is seeking an Oracle Cloud Architect who under the guidance direction and supervision of the Cloud Manager and others as assigned the Contractor will design and implement OCI IAM and Microsoft Entrabased SSO solutions for both cloud and onpremises Oracle applications. The ideal candidate will be an expert in Identity and Access Management (IAM) Single SignOn (SSO) and secure DMZ architectures. Responsibilities also include documenting the complete security architecture and DMZ access patterns to ensure robust scalable and secure user access for internal and external stakeholders.
Responsibilities:Design configure and deploy OCI IAM Identity Providers and federations.
Integrate OCI IAM with Microsoft Entra ID to establish SAML/OIDCbased SSO for:
- Oracle EBusiness Suite
- PeopleSoft
- Oracle Analytics Server 2024
Implement bidirectional federation to:
- Allow Entra users to authenticate into OCIprotected applications.
- Allow OCI identities to access Entraprotected resources.
Integrate onpremises Oracle applications with OCI IAM and Entra using:
- OCI IDCS
- Azure AD Application Proxy
- Custom federation proxies
Deploy and configure secure reverseproxy or WAF layers for external SSO endpoints using:
- OCI Web Application Firewall
- Application Gateway
- Azure AD Application Proxy
- Oracle Access Manager
Document the OCI IAM security architecture including:
- Trust models
- Identity lifecycles
- Userattribute mapping
- Certificate management
- Define and implement a hardened DMZ architecture to broker access between external users internal users and onpremises Oracle services.
Configure OCI Networking components including:
- VCNs
- Subnets
- Security Lists
- Network Security Groups
- Transit Gateways
Develop runbooks standard operating procedures (SOPs) and security baselines for:
- IAM administration
- Patching
- Certificate rotation
Conduct security reviews threat modeling and periodic penetration testing in collaboration with the Security Operations team.
Collaborate with application teams network engineers and security auditors to align on access requirements and compliance standards.
Provide training sessions and handoff documentation for operations and support teams.
Requirements:- Minimum of 15 years of experience in the Oracle stack with at least 8 years in enterprise IAM.
- Proven track record implementing SAML 2.0 / OIDC SSO integrations with onpremises Oracle stacks (EBS PeopleSoft OAS).
- Handson experience in designing and operating secure DMZ/network architectures for hybrid cloud/onprem environments.
Technical Skills:- OCI Core Services: IAM Networking (VCN NSG TGW) Compute Load Balancing WAF.
- Azure Core Services: Entra ID Virtual Network Application Gateway Azure AD Application Proxy.
- Federation Technologies: SAML 2.0 OIDC OAuth2 JWT LDAP/AD integration.
- OnPremises Oracle Stack: EBS 12.2.7 PeopleSoft OAS 2024.
- Reverse Proxy / API Gateway: Oracle Access Manager OCI API Gateway Azure AD App Proxy.
Certifications:- Oracle Certified Master (OCM) or Oracle Certified Professional (OCP) in Cloud IAM or Security.
ASSYST is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race color religion sex age disability military status national origin or any other characteristic protected under federal state or applicable local law.