> Markdown version of [/jobs/ext/2849693-descriptionsr-identity-and-access-management-engineer-for-american-science-cloud](https://www.wearedevelopers.com/jobs/ext/2849693-descriptionsr-identity-and-access-management-engineer-for-american-science-cloud). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # DescriptionSr Identity and Access Management Engineer for American Science Cloud - **Company:** American Superconductor Corporation - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Unix, Software as a Service, Cloud Computing, Code Review, Computer Networks, Multi-Factor Authentication, Github, Identity and Access Management, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), Nagios, Network Protocols, OAuth, OpenID, Ping (Networking Utility), Role-Based Access Control, Cloud Services, Prometheus, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, Workflow Management Systems, Grafana, Multi-Cloud, Gitlab, Build Management, Information Technology, Api Design - **Published:** September 11, 2026 - **Apply:** https://www.thejobnetwork.com/job/a889da07-e9c4-4da0-be9b-ca50956fb260/senior-iam-engineer ## About the Role Basic Qualifications:Bachelor's Degree in computer science or closely related field and a minimum of 5 years of experience as an Identity and Access Management engineer. An equivalent combination of education and experience may be considered.Preferred Qualifications: * Extensive experience in Identity and Access Management supporting SSO, OAuth, MFA, and API development * Excellent interpersonal/communication skills, and the ability to work as part of a team. * Proven track record leading and driving the delivery of large, complex IAM projects * Strong experience with the Ping suite of IAM products, bonus points for Ping Government Identity Cloud experience * Extensive experience with web authentication implementation such as SAML, OAuth, API-token, REST, etc…. * Experience in directory services and directory structure, specifically using LDAP and/or PingDirectory * Experience implementing RBAC and ABAC in complex enterprise environments * Strong experience in identity federation design and implementation using standards like OIDC and SAML to manage user identities across disparate systems * Experience with Automation and scripting (Python, etc…) for IAM tasks * Working knowledge of cloud application architecture patterns and a thorough grasp of common products and managed services for at least one Cloud Service Provider (e.g. AWS) * Working knowledge of Unix system fundamentals and common network protocols. * Solid understanding of cloud computing networking concepts. * Ability to proactively identify performance issues, problems, and areas for improvement. * Ability to identify requirements and to define, plan, and implement requisite solutions. * An understanding of code review and familiarity with tools like GitHub and GitLab * Experience using tools such as Nagios, Grafana and Prometheus to monitor systems, metrics, and create dashboards. Special Requirement:This position requires the ability to obtain and maintain a federal public trust clearance from the U.S. government. As such, this position is a Workplace Substance Abuse program (WSAP) testing designed position which requires passing a pre-placement drug test and participation in an ongoing random drug testing program in which employees are subject to being randomly selected for testing. The occupant of this position will also be subject to an ongoing requirement to report to any drug-related arrest or conviction or receipt of a positive drug test result. ## Description Job DescriptionSr Identity and Access Management Engineer for American Science Cloud (AmSC) Experience level: Senior Work location: remote Must be eligible for a federal security clearance (US Citizen)Project Overview: American Science Cloud - A Platform for Transformative ScienceAmSC is a secure, federated, and science-optimized cloud environment that integrates the DOE's world-leading computing and experimental facilities, data resources, and high-performance networksThe AmSC platform enables DOE scientists to create, access, and integrate world-class AI-ready datasets, run scalable model training on leadership-class systems, perform distributed simulations, control instruments, and move data efficiently across sites.The project is a multi-Lab and Public-Private Partnership endeavor, working in tandem with the Models Consortium (ModCon) who will deploy transformative AI models and services to the platform. Key DOE capabilities, such as the Frontier (ORNL), Aurora (ANL), Perlmutter (NERSC, at LBL), Energy Services Network (ESnet, at LBL), and the High Performance Data Facility (HPDF, at JLab) will be directly integrated, allowing multi-site workflows. The Team:As an Identity and Access Management Engineer you will work within the L2 Infrastructure Services group of AmSC to support identity management solution architecture, deployment and administration on our multi-cloud central hub infrastructure. The AmSC identity infrastructure supports teams from many different DOE labs and locations deploying a variety of AI and HPC services both on prem and in cloud environments.Your primary responsibilities will be to design and build an Identity Management platform and federation hub that promote collaboration within the AmSC, enabling researches to seamlessly leverage AmSC infrastructure and services for their projects. You will be one of the first full-time AmSC staff members, and this presents a unique opportunity to build something new and exciting.Major, * Lead the architecture, development and implementation of an Identity and Access Management platform using the Ping suite of products * Contribute to workflow design, API development, and collaborate with application developers and owners to establish robust integrations * Plan, execute and document application onboarding of a diverse and growing application set * Collaborate with IAM personnel from other organizations to design, build and administer a federation hub, allowing users to access resources at any participating facility * Build out and enable ABAC, RBAC, least privilege access and other common IAM standards * Deploy, configure and support identity and access management services such as single sign on (SSO), OAuth, MFA, zero trust, etc…. * Lead incident response, providing advanced troubleshooting and building out of monitoring and alerting systems * Define and implement define KPIs, processes and drive continuous improvement. * Participate in on-call rotation providing 24-hour, 7-day support and off-hours maintenance windows. * Coordinate with vendors to resolve hardware and software problems. * Deliver AmSC's mission by aligning behaviors, priorities, and interactions with our core values of Impact, Integrity, Teamwork, Safety, and Service. Promote diversity, equity, inclusion, and accessibility by fostering a respectful workplace - in how we treat one another, work together, and measure success. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)