Senior Identity & Access Management Engineer (IT...

CUNY
New York, NY, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Part-time / full-time
Experience level
Expert
Compensation
$124,471.0
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Application Integration Architecture Cloud Computing Security CompTIA Security+ Cyber Security Multi-Factor Authentication Federated Identity Management Identity and Access Management IT Management Python (Programming Language) Lightweight Directory Access Protocols (LDAP) OAuth Oracle (Applications)
+5 more
Openid Connect Security Assertion Markup Language (SAML) Single Sign-On SQL Databases Information Technology

Job description

This position encompasses professional and responsible technical consultative and/or administrative work. Under administrative direction of a university IT manager, with broad latitude of independent action or decision, serves as subject matter expert on IT security, identity, and access infrastructure; provides IT security architectural guidance; designs security solutions; conducts IT risk assessments and recommended mitigating solutions.

There are three (3) Assignment Levels within this classification. All personnel perform related work. Assignment Levels 2 and 3 may supervise staff. This specification describes typical assignments; related duties may be assigned as needed.

To view the complete job description, go tohttp://www.cuny.edu/about/administration/offices/hr/classified-civil-service/ccsjobs/and view the Job Description for IT Security Specialist., The Office of Computing and Information Services (CIS) at the City University of New York (CUNY) supports the IT and telecommunications needs of CUNY’s 26 colleges. CIS supports enterprise IT and applications, identifies and develops new technologies that advance the University’s core mission, operates and maintains the University’s network, the enterprise Data Center, and the CUNY Service Desk. Additionally, CIS manages the processes that safeguard the University’s IT assets and maintains the security posture by operating the CUNY Security Operations Center (SOC), develops disaster recovery plans for business continuity, and supports the CUNYfirst Enterprise Resource Planning (ERP) solution that integrates student administration, financial management, and human resources operations across CUNY’s 26 colleges. Lastly, CIS provides strategic and operational IT leadership to all CUNY campuses.

Reporting to the Manager of Oracle Access Management (OAM), the Senior Identity Access Management (IAM) Engineer serves as the senior technical resource responsible for the design, implementation, administration, and security of enterprise Identity & Access Management (IAM) services supporting the University’s authentication and authorization infrastructure. This position provides advanced support for Single Sign-On (SSO), Multi-Factor Authentication (MFA), federated identity services, directory services, RADIUS authentication, and identity lifecycle management. The Senior IAM Engineer develops automation solutions, operational reporting, and security controls to protect University systems while ensuring reliable and secure access to institutional resources.

In addition to the General Duties, other key duties include, but are limited to the following:

  • Administers and supports enterprise IAM platforms, authentication services, and access management solutions.

  • Designs, implements, and maintains Single Sign-On integrations utilizing SAML, OAuth, OpenID Connect, and related federation technologies.

  • Supports Multi-Factor Authentication (MFA), RADIUS, Eduroam, and related authentication infrastructure.

  • Develops Python automation and SQL-based reporting to improve operational efficiency, auditing, and security monitoring.

  • Manages LDAP directory services, identity synchronization, provisioning, and identity lifecycle processes.

  • Performs advanced troubleshooting of authentication, authorization, directory, network, and application integration issues.

  • Conducts security reviews of authentication configurations and access controls to ensure compliance with university security standards.

  • Participates in incident response, root cause analysis, and remediation activities involving identity and access management services.

  • Collaborates with Information Security, Infrastructure Services, Networking, Application Support, and campus stakeholders to implement secure authentication solutions.

  • Develops and maintains technical documentation, operational procedures, and security standards related to IAM services.

  • Provides technical leadership and guidance for IAM-related projects and initiatives.

Requirements

1.** A baccalaureate degree in computer science, engineering or a related field from an accredited college or university and five (5) years of satisfactory full-time experience providing IT security architectural guidance, designing security solutions, and/or conducting IT risk assessments and recommended mitigating solutions; **or

2.** A baccalaureate degree from an accredited college or university and six (6) years of satisfactory full-time experience as described in “1” above; **or

3.** A high school diploma or its educational equivalent and ten (10) years of satisfactory full-time experience as described in “1” above; **or

4. Education and/or experience which is equivalent to “1,” “2” or “3” above. The following may substitute for some of the required experience required in “1,” “2” or “3” above, as follows:

College education (undergraduate credits) may substitute for up to four (4) years of the required experience in “3” above on the following basis:

D. 120 or more semester credits substitute for 4 years of experience.

Graduate credits in information technology, computer science or a related field may substitute for up to two (2) years of experience in “1” or “2” above on the following basis:

B. 30 or more graduate credits substitute for 2 years of required experience.

Each of the following certifications may substitute for one (1) year of the required experience in “1,” “2” or “3” above:

G. Certified Cloud Security Professional (CCSP) issued by ISC2.

However, all candidates must have a high school diploma or its educational equivalent and at least three (3) years of experience as described in “1” above.

Assignment Level II or III** **:

Level II: After meeting the Qualification Requirements above, an additional two (2) years of satisfactory full-time experience providing IT security architectural guidance, designing security solutions, and/or conducting IT risk assessments and recommended mitigating solutions is required for Level II.

Level III: After meeting the Qualification Requirements above and the Level II requirements, an additional two (2) years of satisfactory full-time experience providing IT security architectural guidance, designing security solutions, and/or conducting IT risk assessments and recommended mitigating solutions is required for Level III (for a total of 4 years of experience above the Qualification Requirements).

English Language Proficiency : Demonstrated English language proficiency, including ability to speak, read, write, and understand English well enough to meet minimally acceptable performance standards set for job duties.

Motor Vehicle Driver License : A Motor Vehicle Driver license, valid in New York State, may be required for some, but not all positions.

Note: CUNY considers full-time work to be at least 35 hours per week. Part-time experience of at least 20 hours per week may be prorated by half and credited instead of,but not in addition to, full-time experience during the same period (e.g., two months of related work experience at 20-34 hours per week equates to one month of full-time related work experience.) Part-time experience of fewer than 20 hours per week cannot be credited at all., + Oracle Access Management (OAM) or Oracle IAM products.

  • MFA platforms and identity governance solutions.

  • Familiarity with higher education identity management environments.

  • Experience supporting:

  • Eduroam and enterprise RADIUS services.

  • Production infrastructure, monitoring platforms, and incident response processes.

  • Security certifications such as CISSP, Security+, GIAC, or identity-related certifications.

  • Exceptional stakeholder engagement, executive presence, and communication skills.

Benefits & conditions

Level 3 Incumbent Minimum: $124,471, CUNY offers a comprehensive benefits package to employees and eligible dependents based on job title and classification. Employees are also offered pension and Tax-Deferred Savings Plans. Part-time employees must meet a weekly or semester work hour criteria to be eligible for health benefits. Health benefits are also extended to retirees who meet the eligibility criteria.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:14 min

Evolution of distributed SQL database architectures

Wei Hu Wei Hu · World Congress 2024

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · World Congress 2025

1:19 min

Securing roles upon finishing a computer science degree

Karol Rogowski · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all