Identity and Access Management Engineer

Nova Southeastern University
United States
6 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Shift work
Job source

Tech stack

Active Directory Application Programming Interfaces (APIs) Data Analysis Multi-Factor Authentication Identity and Access Management Python (Programming Language) Lightweight Directory Access Protocols (LDAP) OAuth PCI Data Security Standards Windows PowerShell Role-Based Access Control Openid Connect
+12 more
Azure Active Directory Anti-Phishing Security Assertion Markup Language (SAML) Student Information Systems Session Management Single Sign-On Systems Integration Speech Recognition Enterprise Software Applications Information Technology Banner Advertisement Workday

Job description

Designs, implements, and supports the University’s identity and access management (IAM) systems and processes to ensure secure, efficient, and compliant access to institutional resources. Responsible for managing the identity lifecycle, authentication and authorization services, access provisioning, and security controls across academic, administrative, research, and clinical environments while supporting the University’s cybersecurity, compliance, and operational objectives., 1. Designs, engineers, and operates the identity lifecycle, including automated joiner, mover, and leaver processing driven by authoritative systems of record for students, faculty, staff, affiliates, and contractors.

  1. Responsible for single sign-on and federation services, including SAML and OpenID Connect integrations, application onboarding standards, InCommon and research federation participation, and attribute release governance.

  2. Oversees multifactor authentication governance, including enrollment standards, policy scope and exceptions, phishing-resistant authentication adoption, recovery and bypass workflows, and lifecycle of authentication methods.
  3. Designs and administers privileged access management, including privileged account discovery and inventory, vaulting, session management, just-in-time elevation, and elimination of standing administrative privilege.

  4. Designs and maintains role-based access control and entitlement models, including role definition, entitlement cataloging, segregation of duties analysis, and access request and approval workflow.

  5. Designs and operates periodic access certification and attestation campaigns for high-risk systems and privileged entitlements, and tracks revocations to completion.

  6. Administers and secures directory services and identity platforms, including Microsoft Entra ID, Active Directory, and LDAP, and maintains identity data quality, matching, and reconciliation across systems.

  7. Engineers automated provisioning and deprovisioning integrations, including SCIM and application programming interface-based connectors, to replace manual account administration.

  8. Establishes governance for service accounts, application identities, machine identities, and non-human credentials, including ownership, rotation, and least-privilege scoping.

  9. Manages identity for guest, affiliate, alumni, emeritus, and sponsored populations, including sponsorship, expiration, and reauthorization controls.

  10. Produces access control evidence for internal and external audits, regulatory examination, sponsor requirements, and cyber insurance underwriting.

  11. Partners with Information Technology Infrastructure, Enterprise Applications, Human Resources, the Registrar, and Research Administration to integrate identity services with authoritative and consuming systems.

  12. Monitors identity-related risk and telemetry, including anomalous authentication, privilege escalation, dormant and orphaned accounts, and excessive entitlement, and drives remediation.

  13. Develops and maintains identity architecture documentation, standards, procedures, and end-user guidance.

  14. Completes special projects as assigned.

  15. Performs other duties as assigned or required.

Requirements

  1. Comprehensive knowledge of identity and access management concepts, including authentication, authorization, federation, provisioning, and access governance.
  2. Comprehensive knowledge of directory services and identity platforms, including Microsoft Entra ID, Active Directory, and LDAP.
  3. Working knowledge of federation protocols and standards, including SAML 2.0, OpenID Connect, OAuth 2.0, and SCIM.
  4. Working knowledge of privileged access management concepts and platforms, including vaulting, session management, and just-in-time elevation.
  5. Working knowledge of identity governance and administration practices, including role mining, entitlement management, segregation of duties, and access certification.
  6. Working knowledge of multifactor authentication technologies, including phishing-resistant methods such as FIDO2 and passkeys.
  7. Working knowledge of audit and regulatory expectations for access control, including HIPAA, PCI-DSS, GLBA, and NIST SP 800-171 requirements.
  8. Familiarity with higher education identity practices, including InCommon, Shibboleth, eduPerson, and student information system integration.

Skills:

  1. Complex Problem Solving - Proficient skills in identifying complex problems and reviewing related information to develop and evaluate options and implement solutions.
  2. Automation and Scripting - Proficient skills in scripting and automation using PowerShell, Python, or comparable languages, and in working with application programming interfaces.
  3. Systems Integration - Proficient skills in connecting identity platforms to authoritative and consuming systems reliably and repeatably.
  4. Data Analysis - Proficient skills in analyzing entitlement, account, and authentication data to identify risk and reconcile discrepancies.
  5. Documentation - Proficient skills in producing architecture, procedural, and end-user documentation.

Abilities:

  1. Ability to assume ownership of a distributed function and consolidate it into a governed, documented service.
  2. Ability to balance access control rigor against the operational needs of academic, clinical, and research communities.
  3. Ability to coordinate change across departments that share responsibility for identity data and systems.
  4. Ability to handle privileged credentials and sensitive access data with discretion and integrity.
  5. Ability to plan and execute access changes affecting large populations with minimal disruption.

Physical Requirements and Working Environment:

  1. Speech Recognition - Must be able to identify and understand the speech of another person.
  2. Speech Clarity - Must be able to speak clearly so others can understand you.
  3. Near Vision - Must be able to see details at close range (within a few feet of the observer).
  4. Travel - Must be able to travel on a daily and/or overnight basis.
  5. May be required to work nights or weekends.
  6. May be exposed to short, intermittent, and/or prolonged periods of sitting and/or standing in performance of job duties.
  7. May be required to accomplish job duties using various types of equipment/supplies, to include but not limited to pens, pencils, and computer keyboards.

Required Certifications/Licensures:

Required Education: Bachelor’s degree.

Major (if required:

Required Experience: Minimum four (4) to six (6) years’ experience in information technology including identity and access management engineering or administration.

Experience with directory services, single sign-on and federation, and automated provisioning., 1. Experience in higher education, including InCommon federation, Shibboleth, and student information system identity integration.

  1. Experience implementing an identity governance and administration or privileged access management platform.
  2. Experience automating joiner, mover, and leaver processes at enterprise scale.
  3. Experience supporting access control audit and attestation requirements in a regulated environment.
  4. Experience with Workday, Banner, or comparable authoritative systems of record.

Is this a safety sensitive position? No

About the company

Nova Southeastern University (NSU) was founded in 1964, and is a not-for-profit, independent university with a reputation for academic excellence and innovation. Nova Southeastern University offers competitive salaries, a comprehensive benefits package including tuition waiver, retirement plan, excellent medical and dental plans and much more. NSU cares about the health and welfare of its students, faculty, staff, and campus visitors and is a tobacco-free university.

We appreciate your support in making NSU the preeminent place to live, work, study and grow. Thank you for your interest in a career with Nova Southeastern University.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

1:48 min

Automating exploratory data analysis within training pipelines

Dora Petrella · World Congress 2023

6:22 min

Eliminating HR bureaucracy and trusting employees

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:36 min

Performing exploratory data analysis to uncover underlying patterns

Julian Joseph · LIVE

5:06 min

Primary reasons for capability gaps in modern recruitment systems

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

Videos

See all

Related articles

See all