GPS - IAM Engineer
Listed on 2026-03-12
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing, IT Support
The opportunity
You’ll have responsibilities withinthe
Identity and Access Management (IAM) teamthat supports various applications incloudplatformservices acrossthe Government and Public Sector (GPS) business unit.
You’ll support the end-to-end aspects of services including but not limited to service engineering, break/fix support, service roadmaps and standards, vendor management.
You’ll also have responsibilities to include ensuring stability for application platforms and/or services under their responsibility including resolution of incidents and problems, maintenance and support, application platform change control, and automation of processes and procedures. Working closely with other teams within EY, you’ll drive technology standards and consistency across IT Services.
- Maintaining ongoing knowledge and support of Azure infrastructure and aligned applications such as:
- Azure Cloud hosted services, Bastion, Keyvault, Recovery Services Vault, Storage accounts
- Azure Role Based Access Control (RBAC)
- Power Automate, App Service Plan, Function Apps, Application Insights
- Azure networking;
Vnets, network security groups (NSG), private and public endpoints, Azure Private DNS - Microsoft Entra Domain Services (MEDS)
- Access reviews, reporting and Audit compliance
- Deploying MEDS on Azure VM’s and install replica Domain Controllers or Forests in an Azure virtual network
- Maintain ongoing knowledge and support of servers and networks aligned to the Active Directory environments including but not limited to:
- Single Sign-On (SSO) configuration and remediation
- Native Microsoft tools including but not limited to ADSI, ADUC, DNS, Domains and Trusts,
- DISA STIG remediation with Group Policy Objects (GPO)
- Public Key Infrastructure (PKI)
- Creating and configuring Microsoft Entra Domain Services (IAAS & PAAS) for authenticating applications in Azure Cloud
- Application Registrations; OAuth/OpenID, API Permissions, Client /Secrets, JWT Tokens/Claims, JSON, App Roles
- API Gateways, Enterprise Databases, SSO and Access Management systems, identity federation protocols (SAML), OIDC, OAuth2 and LDAP/LDAPS
- Enterprise Applications; SAML, SCIM Provisioning
- Managing data stored in Entra Graph and Powershell.
- Multi Factor Authentication (MFA) such as Entra integration into the authentication, authorization, and single sign-on process for applications and systems
- Account, Group, and entitlement management with SailPoint Identity Security Cloud (ISC) or Identity
IQ (IIQ) - Integrating SailPoint ISC or IIQ and other Identity Infrastructure with Entra
- Design and configuration of Entra Conditional Access using Zero Trust principles
- The role may also require the periodic allocation of additional time on the job to support multiple demands and escalating issues or to accommodate teams or staff in other time zones
- Core understanding of Entra t deployment and Active Directory management
- Understanding of aligning Microsoft Entra / Azure services with security governance frameworks and guidelines such as CMMC, Fedramp, and NIST SP 800.53, 800.63, and 800.171
- Understanding of application registration and Key Management using the Entra portal
- Understanding of Entra Roles, Units and emergency accounts to enable policies at a granular level for access administration
- Strong organizational skills, self-motivated and able to work to tight deadlines
- Strong analytical and problem-solving skills
- Effective teaming and knowledge sharing skills
- Advanced skills in planning, designing and troubleshooting complex cloud environments
- Solid understanding of Cloud environment and security best practices
- Good understanding of ITIL
- Exceptional ability to document processes, procedures and security designs clearly and accurately for distribution to internal teams and customers
- Understanding of other technologies required to run a secure enterprise level infrastructure
- Demonstrated experience in dealing with external vendors and suppliers in the security industry
- Cloud Infrastructure Security enthusiast
- Self-motivated with an aptitude to learn quickly
- Ability to deal with ambiguity
- Have a global mind-set for working with different cultures and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).