Haystack
← Back to Jobs
Other

W2 Role : IAM (Identity Access Management)

Wise Skulls Corp.Plano, TX🇺🇸United StatesPosted 4 Aug 2026

Quick Overview

Work Type
On Site
Level
Mid Senior

Job Description

There are 2 locations: Plano, TX OR Bethpage, NY (Hybrid)

 

JD

  • Need Customer Identity Engineers with experience migrating legacy customer-facing applications and custom identity databases to a centralized CIAM platform using Auth0 by Okta.
  • The Identity & Access Management Engineer will provide Identity and Access Management consulting and engineering services supporting customer identity platform configuration, integration, migration, and authentication modernization initiatives.

     

Responsibilities:

  • IDP Platform Administration & Configuration
  • Administer and configure the enterprise IDP tenant day-to-day: application integrations (OIDC, SAML), sign-on policies, MFA enrollment policies, network zones, and trusted origins.
  • Build and maintain Customer IDP schema — custom attributes, group rules, attribute mappings, and user profile transformations that support accurate identity data across all integrated systems.
  • Design and implement IDP Lifecycle Management configurations for automated provisioning and de-provisioning via SCIM 2.0 and Workflows, covering Joiner / Mover / Leaver events.
  • Develop and maintain workflows (no-code/low-code) and Event Hooks for automated identity orchestration, exception routing, and audit logging.
  • Manage IDP authorization servers: custom scopes, claims, access policies, and token lifetime configurations aligned to application security requirements.
  • Monitor platform health via system logs and integrated SIEM tooling; triage alerts, identify anomalies, and escalate or remediate per runbook.
  • Create and maintain platform operational documentation along with providing customer facing support teams tools, job aids and runbooks.
  • Authentication Modernization & Application Migration.
  • Execute the migration of applications from legacy authentication mechanisms to customer IDP SSO, working from migration playbooks defined by the IAM Manager and adapting them to eachapplication'' s specific stack and constraints.
  • Perform OIDC and SAML application registrations in IDP: configure redirect URIs, response types, grant types, initiated login URIs, and post-logout behavior.
  • Test end-to-end authentication and authorization flows in development, staging, and production environments; document results and coordinate with application teams to resolve gaps before go-live.
  • Support the enablement of passwordless and phishing-resistant authentication.
  • Maintain the migration tracker and contribute status updates for leadership reporting on the application portfolio onboarding roadmap.
  • Application Team Enablement & Technical Support
  • Serve as a first-line technical advisor for application development teams integrating with IDP —answering questions on SDK selection, token design, scope modeling, and session management in office hours and async channels.
  • Write and maintain integration guides, code samples, and reference implementations (JavaScript, Java, Python, or Go) to help application teams onboard with minimal friction.
  • Diagnose and resolve complex authentication failures, token validation errors, and SCIM provisioning issues by reviewing system logs, HAR files, and application-side logs.
  • Participate in architecture reviews for new application integrations, flagging identity anti-patterns and recommending standards-compliant alternatives.
  • Contribute to the IAM community of practice: share knowledge through documentation, recorded demos, and team enablement sessions.
  • Security, Compliance & Identity Operations
  • Implement and validate authentication policy controls: step-up MFA triggers, adaptive access rules, session expiration, and assurance-level requirements aligned to data sensitivity classifications.
  • Support access certification campaigns by producing accurate user-application access reports from IDP data and coordinating with application owners on remediation.
  • Contribute to audit evidence collection for SOX, SOC 2, PCI-DSS, and privacy-related IAM controls; maintain accurate configuration documentation as a control artifact.
  • Participate in IAM incident response: diagnose authentication outages, credential compromise events, or misconfiguration issues; execute runbook remediation steps and contribute to post-incident reviews.
  • Apply and track IDP configuration hygiene: unused apps, dormant users, overly permissive policies, and API token rotation — following the team''s security baseline standards.
  • Tooling, Automation & Continuous Improvement
  • Build and maintain automation scripts and Infrastructure-as-Code (IaC) configurations for repeatable configuration management using Terraform or equivalent.
  • Contribute to the IAM team''s CI/CD pipeline for configuration deployments: write tests for policy changes, peer-review pull requests, and promote changes through dev/stage/prod environments.
  • Identify operational toil and propose automation or tooling improvements to reduce manual work for the team and for application teams onboarding to IDP.
  • Evaluate new IDP features and Identity Engine capabilities; prepare proof-of-concept implementations and recommendations for the Manager to consider for roadmap inclusion.

 

Qualifications Required

  • 3+ years of experience in Identity and Access Management, IT security, or a closely related technical discipline with hands-on platform administration responsibilities.
  • Demonstrated, hands-on experience administering customer IDP’s in a production environment: application integrations, sign-on policies, MFA, Universal Directory, and Lifecycle Management.
  • Working knowledge of identity protocols and standards: OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and SCIM 2.0 — able to read and interpret protocol flows, tokens, and assertions.
  • Experience troubleshooting authentication and provisioning issues end-to-end using system logs, browser developer tools, and HAR file analysis.
  • Ability to read and write code in at least one modern language (JavaScript/Node.js, Python, Java, or Go) sufficient to build integrations, automation scripts, and code samples.
  • Comfortable working directly with application development teams in a consulting or enablement capacity — able to explain IAM concepts clearly to non-IAM engineers.
  • Familiarity with private cloud and cloud platforms (AWS, Azure, or Google Cloud Platform) and how identity integrates with cloud-native services (e.g., API Gateway authorizers, managed identity, cloud IAM roles).


Preferred

  • Certifications in customer identity platforms. (or willingness to obtain within 6 months of hire).
  • Experience with workflows for no-code/low-code identity orchestration.
  • Hands-on experience with FIDO2/WebAuthn or phishing resistant enrollments and policy configuration.
  • Experience managing IDP configuration as code using Terraform or similar IaC tools.
  • Familiarity with CIAM-specific patterns: progressive profiling, social login (Google, Apple, Facebook), consent and preference management, and customer-facing MFA enrollment UX.
  • Exposure to SIEM integration for identity telemetry, and experience writing alert logic or dashboards for IAM signals.
  • Understanding of Zero Trust principles and practical experience implementing device trust or continuous access evaluation policies.
  • Bachelor'' s degree in Computer Science, Information Systems, Cybersecurity, or a related field; equivalent experience considered.

Skills

Node.js
API Gateway
AWS
MFA
OAuth
SAML
SOC 2
SSO
Azure
Compliance
Continuous Improvement
Google Cloud
Java
JavaScript
Onboarding
Python
Technical Support
Terraform
Triage
Zero Trust

Similar jobs