Identity Provider Operations Engineer
About the role
Maintaining secure, resilient, and highly available authentication and access management systems is critical to supporting enterprise users and protecting mission systems from unauthorized access.
Responsibilities
- Support the ongoing operations, maintenance, sustainment, and troubleshooting of enterprise IAM and federation services in support of Zero Trust initiatives and mission-critical environments.
- Work closely with cybersecurity teams, system administrators, network engineers, and mission stakeholders to support daily IAM operations, resolve authentication and federation issues, maintain access management services, and ensure compliance with organizational security policies and standards.
- Monitor identity systems, troubleshoot SSO and federation issues, maintain MFA and password-less authentication capabilities, support user lifecycle management processes, apply patches and configuration updates, and assist with operational automation and service improvement initiatives.
- Sustain enterprise-class identity platforms that enable secure access to critical systems and applications while minimizing operational disruptions.
Requirements
- Experience administering, supporting, and maintaining identity platforms such as PingFederate, Okta, or Entra ID in an enterprise operations environment.
- Experience supporting and troubleshooting authentication and federation protocols including SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC).
- Experience troubleshooting SAML, OAuth, and OIDC integrations, token exchanges, assertion mismatches, and federation connectivity issues.
- Experience using scripting or automation languages such as Java, JavaScript, Python, PowerShell, or Groovy to support operational tasks, automation, and maintenance activities, and with system monitoring, operational documentation, patching, and maintenance procedures for IAM services.
- Experience working with RESTful APIs to support identity platform integrations, operational automation, and user lifecycle management processes.
- Experience supporting integrations and synchronization with Active Directory (AD) or LDAP environments.
- Knowledge of Zero Trust architectures and operational support of multifactor authentication (MFA) and password-less authentication solutions.
Qualifications
- Top Secret clearance.
- HS diploma or GED.
Skills
- Strong verbal and written communication skills.
Benefits
Salary range: $86,800.00 to $198,000.00 (annualized USD).
Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits.
Other benefits include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care.
Candidate AI Usage Policy: The use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.
Work Model: Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
Commitment to Non-Discrimination: All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.