Lead IAM Consultant
Gurus Infotech, Inc.
United States
2 months ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
9 years minimum
Working hours
Regular working hours
Job source
Tech stack
Audit Trail
Cloud Computing
Configuration Management
Data Cleansing
Data Transformation
Identity and Access Management
Kerberos (Protocol)
Lightweight Directory Access Protocols (LDAP)
SAP ERP
OAuth
OpenID
Oracle (Applications)
+17 more
Ping (Networking Utility)
Azure Active Directory
Runbook
Salesforce.Com
Security Assertion Markup Language (SAML)
SAP (Applications)
Single Sign-On
Workday Financials
Okta
SAP Integration Solutions
Snowflake
Boomi
Test Scripts
SAPBasis
Pingfederate
Integration Frameworks
Workday
Job description
- Conduct a complete inventory of the existing Oracle LDAP / Oracle Internet Directory (OID) environment user objects, groups, organisational unit structure, schemas, attributes, and all SAP-bound service accounts
- Document all SAP ECC identity integrations LDAP connector configuration, SNC, SSO bindings, role-to-group mappings, and directory-dependent service accounts that must be migrated or decommissioned
- Map current identity flows end to end: provisioning sources, attribute synchronisation rules, access policies, and group-to-role mappings feeding SAP authorisations
- Perform a detailed fit-gap analysis between the Oracle LDAP/OID topology and PingOne covering user attributes, group structures, MFA policies, federation protocols, and SCIM provisioning readiness
- Design the target-state identity architecture on PingOne: IdP setup, SAML 2.0 / OIDC federation, SCIM provisioning to Salesforce Revenue Cloud, Workday Financials, Snowflake, and Boomi, and adaptive MFA policy configuration
- Build and own the Oracle LDAP to PingOne migration runbook directory export, identity data cleansing and transformation, PingOne import, parallel-run validation, cutover sequence, and rollback plan
- Execute and validate mock migration cycles test directory exports, validate user and group mappings in PingOne, and confirm access to all target platforms before cutover
- Coordinate with the CAS CISO and security team to ensure the PingOne configuration meets CAS security policy, compliance requirements, and access governance standards
- Work with the Boomi integration team to ensure identity event flows provisioning, deprovisioning, and attribute sync are correctly handled across the integrated platform landscape
- Support UAT for identity and access scenarios validate SSO, MFA, and provisioning across Salesforce, Workday, Snowflake, and Boomi in the new PingOne-led environment
- Deliver the Oracle LDAP decommission sign-off checklist confirm all users, groups, and service accounts are migrated, all SAP integrations re-pointed, and the legacy directory is safe to switch off
- Produce all Phase 0 and migration deliverables: As-Is Identity Architecture Document, Fit-Gap Register, PingOne Integration Blueprint, Migration Runbook, and Decommission Readiness Checklist
Requirements
- 9+ years of hands-on experience with Oracle LDAP / Oracle Internet Directory (OID) directory administration, schema management, OU design, and attribute configuration
- Proven experience migrating from Oracle LDAP/OID to PingOne or a comparable cloud identity provider such as PingFederate, Okta, or Azure AD including directory export, data transformation, and cutover execution
- Solid understanding of SAP ECC identity integration LDAP connector, SNC, SAP SSO 2.0, and Kerberos; able to identify and document all directory dependencies within an SAP environment
- Hands-on PingOne or PingFederate configuration experience SSO, SAML 2.0, OAuth 2.0 / OIDC, SCIM provisioning, adaptive MFA, and access policy management
- Experience configuring SCIM-based provisioning and SAML/OIDC federation for enterprise SaaS platforms including Salesforce, Workday, and Snowflake
- Ability to produce clear identity migration artefacts directory inventory reports, attribute mapping matrices, migration runbooks, test scripts, and cutover plans
- Familiarity with Boomi or equivalent integration platforms as they relate to identity event flows provisioning triggers, deprovisioning, and attribute synchronisation
- Strong understanding of identity security principles least privilege, MFA enforcement, access governance, and audit logging requirements
- Good communication skills with the ability to work alongside a CAS CISO, security team, and multiple third-party delivery partners
- Ping Identity certification or equivalent cloud identity certification preferred; experience in a regulated or research-sector environment is an advantage
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
IK
Igor Khokhriakov
24 days ago
AJ
Austin Joy
What Are The Top Skills Required For Azure Developers?
over 4 years ago
MH
Michael Hunger
Everything a Developer Needs to Know About MCP with Neo4j
about 1 year ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago
EM
Eli McGarvie
The Best X (Twitter) Accounts for Developers
almost 3 years ago
DC
Daniel Cranney
Stephan Gillich - Bringing AI Everywhere
almost 2 years ago