Senior Access Management Engineer – Duo, MFA Specialist
Posted 2hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Access Management Engineer leading Cisco Duo MFA deployments, integrations, and migrations. Supporting Okta and Ping Identity projects for GuidePoint Security’s cybersecurity clients.
Responsibilities:
- Lead end-to-end Duo Security engagements from design through implementation and handoff
- Design and deploy Duo MFA, Authentication Proxy, SSO, Device Trust, Network Gateway, Admin API, Auth API, Trusted Endpoints, and Duo Desktop solutions
- Integrate Duo with VPN concentrators, remote access platforms, web applications, cloud platforms, Windows RDP, SSH, and legacy applications
- Plan and execute Duo-to-Duo and competitive MFA platform migrations
- Develop Python, PowerShell, and Bash automation scripts for bulk operations, reporting, lifecycle management, and integration testing
- Design phased MFA rollout strategies, pilot groups, communication plans, and exception workflows
- Conduct Duo security configuration reviews and identify policy, bypass, and device-trust risks
- Maintain technical documentation, architecture diagrams, runbooks, implementation guides, and knowledge-transfer materials
- Support Okta and Ping Identity projects under a lead architect, including SSO, MFA, lifecycle management, directory integrations, workflows, migrations, and testing
- Own technical delivery and client outcomes on Duo engagements
- Provide status updates, communicate blockers, delegate tasks, and mentor junior engineers
- Develop SOPs, delivery templates, and Duo best-practice frameworks
- Support presales discovery, scoping, requirements gathering, LOE estimates, SOW development, solution architectures, roadmaps, presentations, and demonstrations
Requirements:
- Bachelor’s degree in computer science, Information Security, or related field — or equivalent work experience
- 5+ years of experience in Identity and Access Management, with strong emphasis on MFA and access security
- Deep, hands-on experience with Cisco Duo Security
- Experience with Duo MFA policy design, deployment, and administration
- Experience with Duo Authentication Proxy, including RADIUS, LDAP, and Active Directory
- Experience with Duo SSO using SAML 2.0 and OIDC
- Experience integrating Duo across VPN, remote access, web applications, and infrastructure
- Experience with Duo Admin API and Auth API
- Experience with Duo Device Trust and Trusted Endpoints
- Working proficiency with Okta or Ping Identity
- Strong understanding of SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), and RADIUS
- Proficiency with Python, PowerShell, or Bash
- Experience integrating MFA with VPN, Citrix, RD Gateway/NPS, and cloud platforms
- Familiarity with Active Directory, LDAP, and enterprise directory services
- Experience with Intune, Jamf, or Workspace ONE for device trust
- Strong understanding of Zero Trust, least-privilege access, and identity security best practices
- Ability to own technical delivery, manage client expectations, and work independently with minimal oversight
- Willingness to embrace emerging technologies, including AI tools
- Sedentary work and substantial wrist, hand, and/or finger movement for at least 8 hours daily
- Close visual acuity for computer terminal viewing and/or extensive reading for at least 8 hours daily
Benefits:
- Remote workforce primarily (U.S. based only)
- Some travel may be required for certain positions
- Group Medical Insurance options, including Zero Deductible PPO and High Deductible Health Plan with HSA
- GuidePoint pays 90% of employee PPO premiums and 70% of family PPO premiums
- GuidePoint pays 100% of employee HDHP premiums and 75% of family HDHP premiums
- HSA contributions of $850 annually for employees and $1,750 annually for families
- Group Dental Insurance; GuidePoint pays 100% of employee premiums and 75% of family premiums
- 12 corporate holidays
- Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option
- Latest vendor training available
- Unlimited PTO benefit
- Regular feedback and coaching
- Opportunities for career growth and future leadership, Architect, or security-discipline roles









