Directory Services Engineer, Customer Identity & Access Management in New York at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Directory Services Engineer, Customer Identity & Access Management based in the United States.
As a Directory Services Engineer, you will own and enhance an external identity directory platform and its supporting cloud infrastructure.
You will help ensure identity services remain secure, reliable, scalable, and performant for customer- and partner-facing applications.
The role combines identity engineering, cloud infrastructure, automation, architecture, and operational support.
You will design identity lifecycle processes and secure authentication and integration patterns across diverse applications and environments.
A major focus will be supporting the migration of directory services to a next-generation cloud environment.
You will work closely with security, networking, application, and compliance teams to solve complex challenges and drive continuous improvement.
This is a fully remote opportunity with meaningful technical ownership, although candidates must currently reside in Puerto Rico and may occasionally travel to the Santa Isabel site.
- Architect, implement, operate, and maintain the external identity directory platform and its associated AWS cloud infrastructure.
- Design secure and scalable identity solutions supporting B2B and B2C use cases, partner identities, and application integrations.
- Establish and maintain platform standards, technical roadmaps, operational documentation, and runbooks.
- Develop and maintain robust identity lifecycle processes covering registration, verification, profile management, credential recovery, deactivation, and account cleanup.
- Lead and execute the migration of external identity directory services from the existing cloud hosting environment to a next-generation cloud environment.
- Partner with application teams to onboard services, map attributes and claims, and implement secure integration patterns.
- Collaborate with security and compliance stakeholders to implement encryption, secure token handling, privacy controls, and applicable regulatory requirements.
- Monitor platform health, reliability, performance, and security, identifying opportunities for proactive improvement.
- Troubleshoot complex identity, application, network, and infrastructure issues and lead incident response activities and post-incident reviews.
- Support enterprise and cloud-native integrations while ensuring identity services remain resilient and scalable.
- Apply established technical work instructions and operational procedures to support consistent and compliant daily activities.
- Lead cross-functional initiatives and communicate technical risks, solutions, and priorities clearly to relevant stakeholders.
- University degree or equivalent relevant experience, with at least 5 years of prior relevant professional experience; alternatively, an advanced degree in a related field with at least 3 years of relevant experience.
- Professional experience in identity and directory services, infrastructure engineering, or a closely related technical discipline.
- Strong understanding of authentication and identity protocols, including SAML 2.0, OIDC, OAuth 2.0, LDAP, and reverse proxy technologies.
- Experience working with enterprise directory services platforms in production environments.
- Knowledge of network architecture, networking protocols, and enterprise firewall rules.
- Hands-on experience with cloud platforms such as AWS and/or Azure.
- Experience owning or supporting production identity systems is highly advantageous, particularly 2+ years of direct ownership.
- Hands-on experience with Ping Directory Services and/or PingFederate is strongly preferred.
- Practical experience provisioning, configuring, and maintaining infrastructure within AWS is highly desirable.
- Strong troubleshooting and analytical skills, with the ability to investigate complex issues across application, network, identity, and infrastructure layers.
- Excellent communication, technical documentation, and stakeholder management skills.
- Ability to work effectively across security, networking, application, infrastructure, and compliance teams.
- Comfortable taking ownership of complex technical initiatives and operating effectively in a remote environment.
- Professional proficiency in English, as written work instructions and operational guidance are provided in English.
- Candidates must be U.S. citizens or otherwise meet the applicable U.S. person/immigration status requirements for access to information under the relevant program or contract.
- Candidates must currently reside in Puerto Rico; the position is remote, with occasional travel to the Santa Isabel site as business needs require.
- Competitive compensation based on role, experience, and relevant qualifications.
- Comprehensive healthcare and wellness benefits.
- Retirement benefits and work/life support programs.
- Flexible work schedules and a remote-first working arrangement.
- Parental leave, including support for new fathers.
- Achievement and recognition programs.
- Educational assistance and opportunities for professional development.
- Child and adult backup care support.
- Opportunities to work on complex identity, cloud, cybersecurity, and enterprise technology initiatives.
- Remote work primarily from home, with occasional travel to the Santa Isabel, Puerto Rico site as required.