[Remote] Identity Provider Engineer
Auto ImportNote: The job is a remote job and is open to candidates in USA. Booz Allen Hamilton is seeking an Identity Provider Engineer to play a critical role in identity and access management. The role involves supporting large-scale IAM projects, analyzing identity lifecycles, and implementing enterprise-class solutions to secure user identities and manage access to valuable assets.
Responsibilities
- Support large-scale IAM projects for our clients
- Interface with stakeholders and engineering teams
- Analyze the identity lifecycle
- Articulate access requirements
- Define enterprise identity records
- Design, deploy, and support systems that verify appropriate user privileges
- Manage credentials for accessing clients’ assets
- Implement enterprise-class solutions for single sign-on and privileged access systems
- Resolve complex identity and federation issues
Skills
- Experience with Ping Federate, Okta, or Entra ID
- Experience with SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC)
- Experience developing custom SAML, OAuth, and OIDC integrations and troubleshooting protocol exchanges
- Experience with languages used for identity platform development and automation such as Java, JavaScript, Python, PowerShell, or Groovy
- Experience working with RESTful APIs to integrate identity providers with external applications and automate identity lifecycle processes
- Experience integrating and synchronizing with Active Directory (AD) or LDAP
- Knowledge of Zero Trust architectures and implementation of password-less authentication or multifactor authentication (MFA) within the IdP environment
- Ability to resolve complex identity and federation issues, including token validation errors, assertion mismatches, and connectivity problems
- Active TS/SCI clearance; willingness to take a polygraph exam
- HS diploma or GED
- Experience with Ping Identity Suite tools, including development using PingFederate, PingAccess, PingDirectory, or PingOne with custom workflows and scripting
- Experience building or enhancing automated user lifecycle management using System for Cross-domain Identity Management protocols
- Experience integrating identity provider code and configurations into DevOps and CI/CD pipelines for automated build and deployment workflows
- Knowledge of advanced Okta development features such as Okta Workflows, Custom Authorization Servers, Inline Hooks, and Okta APIs for enhanced platform customization
- Knowledge of compliance and regulatory standards such as NIST, FedRAMP, HIPAA, or other frameworks relevant to identity management solutions
- Knowledge of cloud identity platforms such as AWS Cognito, Azure AD B2C, or Google Cloud Identity
- Possession of excellent verbal and written communication skills
- TS/SCI clearance with a polygraph
- Bachelor's degree in Computer Science, Cybersecurity, or Information Technology
Benefits
- Health, life, disability, financial, and retirement benefits
- Paid leave
- Professional development
- Tuition assistance
- Work-life programs
- Dependent care
- Recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values
- Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs
- Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits
Company Overview