Job Description:
The IAM-AAD Engineer will be responsible for day to day management of Identity and Access Management (IAM) and Active Directory solutions. The ideal candidate will work closely with cross-functional teams to ensure secure and efficient access controls. Additionally, the IAM-AAD Engineer will be involved in troubleshooting, maintaining, and enhancing existing IAM and AD/AAD systems to meet the organization's Identity and AD requirements.
Key Responsibilities:
- Design, build and implement workflows and enhancements for the enterprise identity and access management platform.
- Act as the subject matter expert for identity management business processes (identity lifecycle, user access reviews, application matrices etc).
- Plan, design, implement and administer Active Directory and related systems.
- Serve as an escalation point for troubleshooting and issue resolution with regards to multi forest Active Directory.
- Implement, monitor, and maintain AD design.
- Work with other teams in AD Integration for a multiple forest Active Directory infrastructure.
- Troubleshoot and resolve workflow and/or system issues.
- Responsible for BAU support, monitoring, upgrades, patching and configuration.
- Documentation and Knowledge Sharing: Maintain comprehensive documentation of cloud configurations, processes, and procedures.
- Share knowledge and best practices with team members and contribute to a culture of continuous learning.
Qualifications/Requirements:
- Bachelor's Degree in Computer Science, Information Technology, or a related field.
- Proficiency in cloud platforms such as AWS, Azure.
- Certification in cloud platforms (Azure).
- 5+ year of professional work experience as Access Management Consultant/ Engineer and AAD Consultant/ Engineer.
- Ability to deliver Access Management project across all aspects (e.g., Analyse, Design, Develop/ Configure, Test, Deploy, Document).
- Understanding of Single Sign On principles (SAML, WS-Fed, OAuth2 and OIDC).
- Understanding of the Identity Federation, Password-less and MFA concepts.
- Good working experience of Azure AD.
- Scripting (PowerShell/Bash).
- Good understanding of directory functioning.
- Basic knowledge in cyber security (e.g. encryption, signature, PKI).
- Basic knowledge in network (e.g. routing, balancing, firewall.
- Background in both delivering and working with a major IAM vendors or service provider.
- Strong written and verbal communication skills.