Senior IAM Engineer, LDAP – SSO
Posted 7ds ago
Employment Information
Job Description
Senior Engineer managing IAM LDAP & SSO systems for CVS Health. Supporting various technologies while ensuring directory services performance and integrity.
Responsibilities:
- Supporting various LDAP systems- Radiant Logic, Ping Directory, IBM Tivoli Directory Server and Ping SSO systems - PingFederate, PingRisk, PingOne, Ping Access, PingDavinci.
- Work with other engineers and be responsible for the overall direction of the current and future state of LDAP/Authentication systems, access solutions, and LDAP directory server infrastructure.
- Install, administer, and maintain LDAP Directory Services - RadiantOne FID - VDS and ICS servers, Ping Directory, ODSEE Directory and Proxy servers, IBM Tivoli directory server.
- Be part of 24x7 on-call weekly rotation schedule for LDAP directory services support.
- Migrate LDAP client applications from ODSEE to RadiantOne FID and Ping Directory.
- Configure the required service accounts, ACIs, troubleshoot the migration/integration with the application teams.
- Understanding of Client - Server communication concepts, SSL Cryptography, Load Balancers.
- Perform periodic LDAP log analysis for proactive incident prevention and improved systems performance.
- Work closely with User provisioning team for LDAP directory data management.
- Correlate user identities from different LDAP directories and merge them into a single directory and migrate the client applications over to a single directory.
- Work with server infrastructure and network teams to build and troubleshoot Virtual machines, Load balancers for LDAP servers.
- Work in a team environment and communicate well to all levels of management.
- Proficient understanding of HTTP networking, including request and response headers, and network communication protocols and transaction workflows.
- Should have extensive experience in troubleshooting SAML/OIDC/webagent/proxy related authentication issues.
- Install, administer, and maintain Siteminder (policy server/agents/SPS)/ Ping access, Ping policy servers.
- Be part of 24x7 on-call weekly rotation schedule for SSO.
- Understanding of Client - Server communication concepts, SSL Cryptography, Load Balancers.
- Should have extensive experience with Linux and windows platforms.
- Perform periodic Siteminder/Ping log analysis for proactive incident prevention and improved systems performance.
Requirements:
- 7+ years’ experience with Identity Access Management
- 5+ years’ experience with PingFederate, Radiant Logic, and/or other LDAP technologies
- 3+ years’ experience with Shell, Perl, Bash, or Python scripting.
- 3+ years’ experience with JAVA, JNDI API, .Net and other programming languages to help troubleshoot LDAP client application connection issues.
- Experience with logging tools like Splunk
- Experience with monitoring tools like AppDynamics.
Benefits:
- Affordable medical plan options
- 401(k) plan (including matching company contributions)
- Employee stock purchase plan
- No-cost programs for all colleagues including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching.
- Paid time off
- Flexible work schedules
- Family leave
- Dependent care resources
- Colleague assistance programs
- Tuition assistance
- Retiree medical access
- Many other benefits depending on eligibility.


















