Remote candidates are fine
Interviews will be 2 rounds
The position can be remote within the US. Travel is not expected.
Top 5 Skill sets
1. Configuring authentication (OIDC, SAML, OAuth) for applications
2. Microsoft Entra conditional access policies
3. Experience with enabling MFA and SSO
4. Migration of applications between Identity Platforms/Providers
5. Developing automation/scripts to support onboarding of applications and users to Identity platforms
Nice to have skills or certifications:
1. Duo Experience, Microsoft Entra, Oracle Access Manager
2. Enable Microsoft Entra app proxy
3. CISSP or Azure Certifications
The Identity & Access Management (IAM) Security Engineer’s primary responsibility is to implement and support the
integration of authentication and authorization protocols and provide overall infrastructure support aligned with CDR
(Cybersecurity and Digital Risk) security principles and policies protecting data and reducing risk for the client Workforce.
The IAM Senior Engineer will be focused on the implementation and support of modern Enterprise (Workforce) IAM
systems. The Senior Engineer will work closely with cross-organizational development teams, architects, analysts, and
consumers of IAM authentication and authorization services. They serve as a key contact within IAM responsible for the
integration of secure identity solutions during the product lifecycle.
The IAM Security Engineer requires a deep understanding of identity and access management principles, protocols, and
best practices as well as experience implementing and managing IAM related automation, integrations, and orchestration.
This is a senior-level position that will execute the implementation of designs and requirements provided by IAM architects
and analysts and ensures that IAM capabilities and services are successfully integrated within systems across the
organization while also providing ongoing support and maintenance as needed for IAM processes and technology.
Design, integrate, and implement information systems security infrastructure. Assess potential systems and process vulnerabilities to determine security infrastructure requirements. Develop policies and procedures to prevent unauthorized access. Educate and communicate security requirements and procedures to users and new employees. Recommend and implement changes to enhance systems security and prevent unauthorized access. Research security trends, new methods, and techniques used in unauthorized access of data to preemptively eliminate the possibility of system breach. Provide guidance and direction on best practices for the protection of information. Ensure compliance with regulations and privacy laws. May oversee internal or external systems security (e.g., cloud services). Recognized as expert in field, knowledgeable of emerging trends and industry practices. Conducts the most complex and vital work critical to the organization. Works without supervision with complete latitude for independent judgment. May mentor less experienced peers and display leadership as needed. Network security, Security Controls, TCP/IP, Security Systems, CISSP, Check Point - Network security, Security Controls, TCP/IP, Security Systems, CISSP, Check PointCheck Point, Juniper, RSA, Blue Coat, Trend Micro, Websense, F5, Arbor Networks, Splunk, Client , Palo Alto, actiance, airtight, axway, cyberark, forescout, Hexis, infoblox, logrhythm, quarri, Sophos, tibco, varonis, zscaler, Client, tendmicro, rapid7, Fortinet, beyondtrust, aruba, firemon, gigamon, Kaspersky, safenet, XirrusQualifications:Knowledge of computer and network security techniques and methodologiesKnowledge of networking, security monitoring tools and security systems; including routers, switches, firewalls, IDS/IPS, authentication systems, anti-virus, content filtering, SEIM, log management, etc.Advanced security, system, and network troubleshooting skillsExcellent written and verbal skills with public speaking abilityReport writing skills using Microsoft Word, PowerPoint and ExcelExperience with vendor product lines such as Juniper, RSA, Cisco, Qualys, MalwareBytes, and SophosExperience working with automation tools such as Jenkins, Chef and PuppetExperience writing scripts in Python, Java or JavaScriptExperience working with multiple sites throughout a geographically dispersed areaMulti-datacenter experienceComputer forensics and malware analysisUnderstanding of Application Development, DevOps, Agile Methodology, MS Active DirectorySecurity Certifications (CISSP, CISA, GSEC, Security+)Bachelors degree or equivalent work experienceExperience with Microsoft and Linux based operating systems (Server and Workstation)Competency in Cyber Threat Management including content development using custom signatures, parsers, SNORT, REGEX, YARAExperience and knowledge of:- Network security- Security Controls (firewalls, IDS/IPS, authentication, etc.)- TCP/IP- Security Systems (routers, switches, firewalls, antivirus, content filtering, etc.)Optional Certifications:- CISSP certification- SANS/GIAC Certified Firewall Analyst (GCFW)- SANS/GIAC Enterprise Defender (GCED)
EEO:
“Mindlance is an Equal Opportunity Employer and does not discriminate in employment on the basis of – Minority/Gender/Disability/Religion/LGBTQI/Age/Veterans.”