Program Description: Customer requires enterprise architecture, assessment, modernization, integration, and project management support for IT Enterprise and large-scale programs.
The initiative will evaluate whether current enterprise services can securely and reliably support large-scale development, testing, performance, scalability, failover, and production operations. The work includes assessments of enterprise technology capabilities, including the ServiceNow platform, enterprise network architecture, Microsoft Intune mobility environment, and the integration of enterprise applications with external vendor mobile devices and supporting systems.
Position Description: The Identity and Directory Management Services (IDMS) Subject Matter Expert (SME) will provide technical and functional expertise for assessing, designing, configuring, integrating, securing, and supporting enterprise identity and directory services. The SME will evaluate identity lifecycle processes, directory architecture, authentication and federation services, access controls, automation, integrations, monitoring, and operational practices.
The SME will support the planning and integration of enterprise applications, SaaS platforms, external service providers, cloud services, APIs, and partner systems to ensure identity, authentication, authorization, provisioning, governance, auditing, monitoring, and lifecycle management requirements are incorporated into solution designs and implementation plans. The SME will support the governance and lifecycle management of identities, credentials, entitlements, privileged accounts, service accounts, application identities, certificates, secrets, tokens, and access rights across enterprise systems, cloud services, SaaS platforms, and external provider integrations.
The IDMS SME will collaborate with cybersecurity, infrastructure, cloud, application, service management, and operations teams to resolve complex identity issues, strengthen Zero Trust alignment, improve governance and automation, and support reliable access across enterprise environments.
Responsibilities
- Assess and optimize enterprise identity and directory architectures, configurations, operating procedures, governance, and security controls.
- Administer and troubleshoot Active Directory, Microsoft Entra ID, Okta, directory synchronization, domain services, Group Policy, DNS dependencies, and hybrid identity services.
- Design and support identity lifecycle processes for provisioning, modification, access review, account disablement, deprovisioning, and non-human or service accounts.
- Implement and maintain authentication and federation capabilities, including single sign-on, multi-factor authentication, Conditional Access, SAML, OAuth 2.0, OpenID Connect, LDAP, and related protocols.
- Configure role-based and attribute-based access controls, delegated administration, privileged access, least-privilege policies, and separation-of-duties controls.
- Integrate identity services with enterprise applications, cloud environments, endpoint platforms, APIs, security tools, and IT service management solutions.
- Automate identity administration, synchronization, reporting, and remediation using scripting, workflows, infrastructure-as-code, and supported platform tools.
- Monitor identity service health, authentication events, access anomalies, audit logs, capacity, performance, availability, and security posture.
- Identify architecture gaps, vulnerabilities, technical debt, scalability risks, and manual processes, then develop prioritized remediation recommendations.
- Document architectures, configurations, procedures, findings, and technical decisions, and support workshops, testing, incident resolution, and knowledge transfer.
- Assess and support onboarding of enterprise applications, SaaS providers, cloud services, vendor-hosted solutions, partner systems, APIs, and externally managed platforms to ensure identity integration, federation, access governance, provisioning, authentication, authorization, auditability, monitoring, and operational support requirements are properly defined and implemented.
- Collaborate with enterprise architects, application teams, vendors, cybersecurity personnel, service management teams, and project teams to review solution designs and ensure identity services are incorporated into system architectures, implementation roadmaps, operational procedures, and support models.
- Evaluate application authentication models, federation requirements, identity dependencies, entitlement structures, access control requirements, API security requirements, and lifecycle management requirements for new and existing enterprise solutions.
- Design, implement, and improve identity, credential, and access lifecycle management processes governing onboarding, role changes, access modifications, periodic recertification, privileged access, credential rotation, and deprovisioning activities.
- Manage identity governance requirements associated with user identities, service accounts, application identities, API credentials, machine identities, certificates, tokens, secrets, and privileged accounts throughout their lifecycle.
- Establish controls and governance processes for credential issuance, usage, storage, rotation, expiration, revocation, recovery, auditing, and retirement across enterprise environments.
- Evaluate identity and credential management requirements for enterprise applications, SaaS providers, vendor-hosted solutions, cloud platforms, APIs, external partners, and integrated systems.
Requirements
- At least 12 years of relevant experience in identity and access management, directory services, cybersecurity, systems engineering, or related technical disciplines.
- Bachelor's degree in information technology, computer science, engineering, cybersecurity, or a related field.
- Demonstrated experience designing, administering, assessing, or modernizing enterprise identity and directory management environments.
- Advanced knowledge of Microsoft Active Directory, Microsoft Entra ID, domain services, forests and trusts, Group Policy, directory synchronization, and hybrid identity.
- Experience with identity lifecycle management, automated provisioning and deprovisioning, access requests, access reviews, account certification, and entitlement management.
- Strong knowledge of single sign-on, federation, multi-factor authentication, Conditional Access, passwordless authentication, and identity provider integrations.
- Hands-on knowledge of SAML 2.0, OAuth 2.0, OpenID Connect, LDAP/LDAPS, Kerberos, SCIM, certificates, and related identity protocols.
- Experience implementing role-based access control, attribute-based access control, least privilege, delegated administration, and separation of duties.
- Experience with privileged access management, service accounts, application identities, API credentials, secrets, and non-human identity governance.
- Knowledge of Zero Trust identity principles, authentication risk, identity monitoring, audit logging, vulnerability management, and incident response.
- Experience integrating identity services with enterprise applications, cloud platforms, Microsoft 365, endpoint management, security tools, and service management platforms.
- Experience using PowerShell or comparable scripting tools to automate identity administration, reporting, synchronization, and remediation.
- Ability to troubleshoot complex authentication, authorization, federation, replication, synchronization, and access issues across hybrid environments.
- Ability to conduct technical assessments, document current-state architectures, identify gaps and risks, and develop actionable future-state recommendations.
- Strong technical documentation and communication skills for technical teams, business stakeholders, and leadership.
- Experience integrating identity platforms with enterprise applications, SaaS providers, external vendor solutions, partner systems, APIs, cloud services, and hybrid environments.
- Experience evaluating application onboarding requirements, federation architectures, identity dependencies, authentication models, authorization models, and access governance requirements across enterprise environments.
- Experience working with application owners, solution architects, cybersecurity teams, external vendors, and operational support teams to implement identity and access management capabilities within complex enterprise ecosystems.
- Experience with identity, credential, and access lifecycle management processes, including onboarding, offboarding, role changes, access certification, entitlement management, credential governance, and privileged access controls.
- Experience managing service accounts, application identities, API credentials, machine identities, certificates, secrets, tokens, and non-human identity governance processes.
- Experience implementing controls for credential issuance, storage, vaulting, rotation, expiration, revocation, monitoring, and auditability.
Preferred Skills
- Microsoft certification related to identity and access administration, Azure, security, or enterprise architecture.
- Experience with identity governance and administration platforms such as Okta, SailPoint, Microsoft Entra ID Governance, or comparable technologies.
- Experience with privileged access management platforms such as CyberArk or comparable technologies.
- Knowledge of Active Directory Certificate Services, public key infrastructure, smart card or certificate-based authentication, and certificate lifecycle management.
- Experience with Active Directory modernization, forest or domain migration, Group Policy optimization, directory recovery, and disaster recovery planning.
- Experience deploying identity configurations through Terraform, CI/CD pipelines, or other infrastructure-as-code and automation practices.
- Familiarity with cloud identity architectures across Microsoft Azure, Amazon Web Services, Microsoft 365, and hybrid environments.
- Experience integrating identity platforms with ServiceNow, SIEM, monitoring, endpoint management, or security operations solutions.
- Familiarity with Zero Trust architecture, cybersecurity control frameworks, security benchmarks, privacy requirements, and audit support.
· Experience supporting large, distributed, highly available, or regulated enterprise identity environments.
- Experience supporting enterprise application onboarding, SaaS integration, vendor integration, B2B federation, external identity providers, business partner access, and cross-organizational identity trust relationships.
- Experience with enterprise credential management, secrets management, certificate lifecycle management, public key infrastructure (PKI), privileged access management (PAM), and machine identity governance platforms.
Soft Skills
- Analytical thinking: Identifies root causes, control weaknesses, dependencies, and risks across complex identity environments.
- Problem-solving: Develops practical solutions that balance security, usability, reliability, maintainability, and operational needs.
- Communication: Explains identity concepts, technical issues, risks, and recommendations clearly to varied audiences.
- Collaboration: Works effectively across cybersecurity, infrastructure, cloud, application, service management, and operations teams.
- Attention to detail: Maintains accuracy across access policies, directory configurations, identity data, testing, and documentation.
- Adaptability: Responds effectively to changing technologies, security threats, business requirements, and operational priorities.
- Ownership: Proactively drives identity issues, assessment findings, and remediation actions through resolution.
- Documentation discipline: Produces clear, accurate, and reusable architecture, configuration, procedure, and knowledge-transfer materials.
Benefits
SES provides a competitive salary and the following benefits:
- Medical
- Dental
- Vision
- AD&D
- STD
- LTD
- Company paid Life Insurance
- 401k with employer contribution
- Paid Time Off
- Pet Insurance