← Все вакансии/Senior/jobgether
SeniorRemote

Senior IBM Security Verify Access Engineer

J
jobgether
Уровень
Senior
Формат
Remote
О роли

Описание вакансии

About the company

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Contractor: Senior IBM Security Verify Access (ISVA/ISAM) Engineer based in India.

Responsibilities
  • Design, install, configure, administer, migrate, upgrade, patch, and maintain enterprise ISVA/ISAM environments and virtual appliances.
  • Configure and support WebSEAL, Policy Server, Runtime Components, Federation Services, Advanced Access Control, authorization policies, reverse proxies, and related IAM components.
  • Architect and operate clustered, highly available, and disaster-recovery-ready environments, including backups, snapshots, restores, rollback plans, runbooks, and production cutovers.
  • Troubleshoot complex authentication, authorization, SSO, federation, certificate, appliance, reverse-proxy, and access-policy issues in production environments.
  • Design and implement enterprise SSO integrations using SAML 2.0, OAuth 2.0, OIDC, and JWT, including IdP/SP configurations, metadata, certificates, endpoints, bindings, signatures, and encryption.
  • Analyze and resolve issues involving SAML assertions, OAuth/OIDC tokens, authorization codes, refresh tokens, PKCE, claims, scopes, redirect URIs, ACS URLs, and token validation.
  • Develop, enhance, and troubleshoot ISVA/ISAM mapping rules using JavaScript for attribute transformation, claims processing, token customization, session handling, and custom authentication logic.
  • Integrate mapping rules with LDAP attributes, HTTP headers, REST APIs, and external decision points while debugging runtime behavior across federation protocols.
  • Administer and troubleshoot IBM Security Directory Server, including schema management, indexing, replication, backup, restore, performance tuning, HA, and SSL/TLS configuration.
  • Support directory migrations and integrations with IAM platforms while resolving LDAP bind, search, replication, schema, and performance issues.
  • Manage certificates, PKI, TLS, Linux/Unix environments, load balancers, DNS, networking, logging, monitoring, and production incident response.
  • Use shell scripting, Python, JavaScript, REST APIs, and log-analysis techniques to automate support activities and improve operational efficiency.
  • Lead technical discussions with application, infrastructure, networking, security, and vendor teams and contribute to IAM migration, modernization, consolidation, and upgrade initiatives.
  • Produce and maintain architecture diagrams, technical design documents, SOPs, implementation plans, rollback procedures, runbooks, and knowledge-transfer materials.
Requirements
  • 10+ years of experience in Identity and Access Management, with extensive hands-on experience administering IBM Security Verify Access (ISVA) and/or IBM Security Access Manager (ISAM).
  • Strong expertise with ISVA/ISAM installation, configuration, migration, upgrades, WebSEAL, Policy Server, Advanced Access Control, Federation Services, reverse proxies, and appliance operations.
  • Deep knowledge of SAML 2.0, OAuth 2.0, OpenID Connect, JWT, federation metadata, certificates, trust configuration, token claims, and authentication flows.
  • Hands-on experience developing and modifying ISVA/ISAM mapping rules using JavaScript, including SAML, OAuth, OIDC, attribute transformation, and custom authentication logic.
  • Strong experience with IBM Security Directory Server, LDAP schema, replication, indexing, performance tuning, SSL/TLS, and directory administration.
  • Solid understanding of PKI, TLS, Linux/Unix, load balancing, DNS, networking fundamentals, logging, monitoring, and production incident management.
  • Experience with shell scripting, Python, JavaScript, REST APIs, log analysis, and support automation.
  • Strong ability to trace and troubleshoot end-to-end request flows, authentication traces, policy decisions, junction behavior, HTTP headers, cookies, sessions, and access-control issues.
  • Demonstrated ability to diagnose complex federation problems such as metadata mismatches, assertion validation errors, signature or encryption failures, redirect URI issues, clock skew, and certificate trust failures.
  • Excellent analytical and problem-solving skills, particularly when handling high-severity production incidents.
  • Strong written and verbal communication skills, with the ability to clearly document root causes, technical decisions, implementation plans, and stakeholder updates.
  • Ability to collaborate effectively with distributed technical teams and lead discussions across application, infrastructure, networking, security, and vendor functions.
  • Preferred: Experience with IBM Verify SaaS, IBM Security Identity Manager, IBM Security Verify Governance, IBM Security Directory Integrator, Azure AD/Microsoft Entra ID, AWS Cognito, Kubernetes, or OpenShift.
  • Preferred: Experience lead
Стек и навыки

С чем работаем