# Senior ICAM Engineer, Full Time, Remote

**Company:** [Technologist, Inc.](http://jobs.workable.com/companies/5tTYQVAjXVwdxnFjHtpRdB.md)
**Location:** Remote, United States
**Workplace:** on site
**Employment type:** Full-time
**Department:** Active Business

[Apply for this job](http://jobs.workable.com/view/5586443d-660b-4b58-a542-1b0a3354e8f9)

## Description

Mount Airey Group (MAG), a wholly owned subsidiary of Technologist Inc., is seeking a Senior Identity, Credential and Access Management (ICAM) Engineer to join our team. This is a full-time telework opportunity offering a competitive salary coupled with a stellar benefits package effective your first day of employment.

The Senior ICAM Engineer is responsible for the engineering, implementation, automation, administration, and operational support of enterprise Identity, Credential, and Access Management (ICAM) services. This role designs and implements secure identity solutions supporting authentication, authorization, identity lifecycle management, and Zero Trust initiatives. The engineer develops automation using PowerShell and the Okta REST APIs to improve operational efficiency, reduce manual administration, and support enterprise identity operations across cloud and on-premises environments. The engineer will also evaluate and adopt emerging automation technologies, including Python, to enhance future automation capabilities.

**Primary Responsibilities**

-   Administer, configure, and maintain enterprise Okta Identity Cloud environments supporting workforce identity and access management.
-   Design, implement, and troubleshoot Single Sign-On (SSO) integrations using SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC).
-   Configure and maintain authentication policies, adaptive Multi-Factor Authentication (MFA), phishing-resistant authentication, and application sign-on policies.
-   Develop and maintain user lifecycle automation, including provisioning, deprovisioning, profile mappings, attribute transformations, group rules, and application assignments.
-   Design, configure, and support inbound and outbound identity federation with internal and external Identity Providers (IdPs).
-   Develop and maintain custom user profile attributes, application profile mappings, and identity schemas to support business and partner requirements.
-   Integrate enterprise applications with Okta while ensuring compliance with organizational security policies and Federal ICAM standards.
-   Troubleshoot complex authentication, federation, provisioning, authorization, and identity synchronization issues across cloud and on-premises environments.
-   Develop and maintain PowerShell automation utilizing the Okta REST APIs to perform administrative functions, user lifecycle management, reporting, and large-scale user profile updates.
-   Design and execute automated batch processes for creating, modifying, and updating user identities while ensuring data integrity, consistency, and auditability.
-   Develop reusable automation scripts and tools that improve operational efficiency and reduce manual administrative effort.
-   Integrate enterprise systems using REST APIs to automate identity management workflows and improve data consistency across identity repositories.
-   Evaluate and develop future automation capabilities using Python to support API integrations, reporting, and enterprise automation initiatives.
-   Support Public Key Infrastructure (PKI), PIV/CAC authentication, certificate-based authentication, and smart card integrations.
-   Develop technical architecture documentation, implementation guides, standard operating procedures, workflow diagrams, and engineering documentation.
-   Participate in Zero Trust initiatives by implementing modern identity-centric security controls and authentication mechanisms.
-   Analyze identity-related security events and assist with audit, compliance, and forensic investigations.
-   Collaborate with cybersecurity, infrastructure, networking, and application teams to implement secure identity solutions.
-   Perform testing, change management, production deployments, and Tier III engineering support for enterprise identity services.
-   Research, evaluate, and recommend new identity technologies and automation solutions that improve security, reliability, and operational efficiency.

**Technical Requirements:**

-   Okta Identity Cloud
-   Microsoft Entra ID
-   Ping Identity
-   PowerShell
-   Okta REST APIs
-   REST APIs
-   JSON
-   Identity Lifecycle Management
-   SAML 2.0
-   OAuth 2.0
-   OpenID Connect (OIDC)
-   Multi-Factor Authentication
-   Identity Federation
-   Active Directory
-   LDAP
-   PKI
-   PIV/CAC Authentication
-   Zero Trust Architecture
-   Technical Documentation
-   Enterprise Identity Troubleshooting

**Expected Experience:**

-   Experience implementing and supporting:

-   Single Sign-On (SAML 2.0, OAuth 2.0, OpenID Connect)
-   Multi-Factor Authentication (MFA)
-   Identity Federation
-   User Lifecycle Management
-   Active Directory and LDAP
-   REST API integrations

-   Experience developing automation using PowerShell.
-   Experience consuming and integrating REST APIs.
-   Experience working with JSON and API payloads.

## Requirements

-   Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or related field, or equivalent professional experience.
-   Minimum of 2 (two) years of daily hands-on experience administering and engineering solutions using Okta Identity Cloud, including application integrations, identity lifecycle management, automation, and REST API development.

**OR**

-   Minimum of 3 (three) years of hands-on experience administering an enterprise Identity and Access Management platform such as Microsoft Entra ID, Ping Identity, ForgeRock, or a comparable IAM solution.
-   Ability to obtain Secret level clearance.
-   Ability to travel to Washington, DC for important meetings.

## Benefits

-   Health Care Plan (Medical, Dental & Vision)
-   Retirement Plan (401k, with employer match)
-   Paid Time Off (Vacation, Sick & Federal Holidays)
-   Short Term & Long Term Disability
-   Training & Development
