GPS - IAM Engineer - Supervising Associate
Listed on 2026-01-01
-
IT/Tech
Cybersecurity, Systems Engineer
The opportunity
You’ll have responsibilities within the Identity and Access Management (IAM) team that supports various applications including cloud platform services across the Government and Public Sector (GPS) business unit. You’ll support the end‑to‑end aspects of services including but not limited to service engineering, break/fix support, service roadmaps and standards, and vendor management. You’ll also have responsibilities to include ensuring stability for application platforms and/or services under their responsibility including resolution of incidents and problems, maintenance and support, application platform change control, and automation of processes and procedures.
Working closely with other teams within EY, you’ll drive technology standards and consistency across IT Services.
- Maintaining ongoing knowledge and support of Azure infrastructure and aligned applications such as Azure Cloud hosted services, Bastion, Keyvault, Recovery Services Vault, Storage accounts
- Azure Role Based Access Control (RBAC)
- Power Automate, App Service Plan, Function Apps, Application Insights
- Azure networking;
Vnets, network security groups (NSG), private and public endpoints, Azure Private DNS - Microsoft Entra Domain Services (MEDS)
- Access reviews, reporting and audit compliance
- Deploying MEDS on Azure VMs and install replica Domain Controllers or Forests in an Azure virtual network
- Maintain ongoing knowledge and support of servers and networks aligned to the Active Directory environments including but not limited to Single Sign‑On (SSO) configuration and remediation
- Native Microsoft tools including but not limited to ADSI, ADUC, DNS, Domains and Trusts
- DISA STIG remediation with Group Policy Objects (GPO)
- Public Key Infrastructure (PKI)
- Creating and configuring Microsoft Entra Domain Services (IAAS & PAAS) for authenticating applications in Azure Cloud
- Entra services management including application proxy, licensing, Azure PIM
- Application Registrations; OAuth/OpenID, API Permissions, Client /Secrets, JWT Tokens/Claims, JSON, App Roles
- API Gateways, Enterprise Databases, SSO and Access Management systems, identity federation protocols (SAML), OIDC, OAuth2 and LDAP/LDAPS
- Enterprise Applications; SAML, SCIM provisioning
- Managing data stored in Entra Graph and Power Shell
- Multi‑Factor Authentication (MFA) such as Entra integration into the authentication, authorization, and single‑sign‑on process for applications and systems
- Account, Group, and entitlement management with SailPoint Identity Security Cloud (ISC) or Identity
IQ (IIQ) - Integrating SailPoint ISC or IIQ and other Identity Infrastructure with Entra
- Design and configuration of Entra Conditional Access using Zero Trust principles
- Entra collaboration; B2B, Entra External
- The role may also require the periodic allocation of additional time on the job to support multiple demands and escalating issues or to accommodate teams or staff in other time zones
- Core understanding of Entra t deployment and Active Directory management
- Understanding of aligning Microsoft Entra / Azure services with security governance frameworks and guidelines such as CMMC, Fedramp, and NIST SP 800.53, 800.63, and 800.171
- Understanding of application registration and Key Management using the Entra portal
- Understanding of Entra Roles, Units and emergency accounts to enable policies at a granular level for access administration
- Strong organizational skills, self‑motivated and able to work to tight deadlines
- Strong analytical and problem‑solving skills
- Effective teaming and knowledge sharing skills
- Advanced skills in planning, designing and troubleshooting complex cloud environments
- Solid understanding of cloud environment and security best practices
- Good understanding of ITIL
- Exceptional ability to document processes, procedures and security designs clearly and accurately for distribution to internal teams and customers
- Understanding of other technologies required to run a secure enterprise level infrastructure
- Demonstrated experience in dealing with external vendors and suppliers in the security industry
- Cloud Infrastructure Security enthusiast
- Self‑m…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).