Staff IAM Engineer (SSO, LDAP)

  • Posted 4 hours ago | Updated 4 hours ago

Overview

Remote
USD 130,295.00 - 260,590.00 per year
Full Time

Skills

Health Care
ICS
Tivoli
ODSEE
Migration
Provisioning
Data Management
Virtual Machines
HTTP
Computer Networking
Network
Workflow
SAML
OIDC
Proxies
Authentication
Servers
SSO
Client/server
Communication
SSL
Cryptography
Linux
Microsoft Windows
Siteminder
Log Analysis
Identity Management
Shell
Perl
Bash
Python
Scripting
Java
JNDI
API
.NET
Programming Languages
LDAP
Splunk
AppDynamics
Management
Finance
Coaching

Job Details

At CVS Health, we're building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care.

As the nation's leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues - caring for people where, when and how they choose in a way that is uniquely more connected, more convenient and more compassionate. And we do it all with heart, each and every day.

Position Summary

As a Senior LDAP & SSO engineer, you will be supporting various LDAP systems- Radiant Logic, Ping Directory, IBM Tivoli Directory Server and Ping SSO systems - PingFederate, PingRIsk, PingOne, Ping Access, PingDavinci.

Key Responsibilities:
  • Work with other engineers and be responsible for the overall direction of the current and future state of LDAP/Authentication systems, access solutions, and LDAP directory server infrastructure.
  • Install, administer, and maintain LDAP Directory Services - RadiantOne FID - VDS and ICS servers, Ping Directory, ODSEE Directory and Proxy servers, IBM Tivoli directory server.
  • Be part of 24x7 on-call weekly rotation schedule for LDAP directory services support. Rotates once every 3-4 weeks.
  • Migrate LDAP client applications from ODSEE to RadiantOne FID and Ping Directory. Configure the required service accounts, ACIs, troubleshoot the migration/integration with the application teams.
  • Understanding of Client - Server communication concepts, SSL Cryptography, Load Balancers
  • Perform periodic LDAP log analysis for proactive incident prevention and improved systems performance.
  • Work closely with User provisioning team for LDAP directory data management.
  • Correlate user identities from different LDAP directories and merge them into a single directory and migrate the client applications over to a single directory.
  • Work with server infrastructure and network teams to build and troubleshoot Virtual machines, Load balancers for LDAP servers.
  • Work in a team environment and communicate well to all levels of management.
  • Proficient understanding of HTTP networking, including request and response headers, and network communication protocols and transaction workflows.
  • Should have extensive experience in troubleshooting SAML/OIDC/webagent/proxy related authentication issues.
  • Install, administer, and maintain Siteminder (policy server/agents/SPS)/ Ping access, Ping policy servers.
  • Be part of 24x7 on-call weekly rotation schedule for SSO. Rotates once every 3-4 weeks.
  • Understanding of Client - Server communication concepts, SSL Cryptography, Load Balancers
  • Should have extensive experience with Linux and windows platforms.
  • Perform periodic Siteminder/Ping log analysis for proactive incident prevention and improved systems performance.

Required Qualifications
  • 7+ years' experience with Identity Access Management
  • 5+ years' experience with PingFederate, Radiant Logic, and/or other LDAP technologies
  • 3+ years' experience with Shell, Perl, Bash, or Python scripting.
  • 3+ years' experience with JAVA, JNDI API, .Net and other programming languages to help troubleshoot LDAP client application connection issues.

Preferred Qualifications
  • Experience with logging tools like Splunk
  • Experience with monitoring tools like AppDynamics.

Education
  • Bachelor's degree or equivalent experience (High School Diploma and 4 years relevant experience)

Pay Range

The typical pay range for this role is:

$130,295.00 - $260,590.00

This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company's equity award program.

Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.

Great benefits for great people

We take pride in our comprehensive and competitive mix of pay and benefits - investing in the physical, emotional and financial wellness of our colleagues and their families to help them be the healthiest they can be. In addition to our competitive wages, our great benefits include:
  • Affordable medical plan options, a 401(k) plan (including matching company contributions), and an employee stock purchase plan.
  • No-cost programs for all colleagues including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching.
  • Benefit solutions that address the different needs and preferences of our colleagues including paid time off, flexible work schedules, family leave, dependent care resources, colleague assistance programs, tuition assistance, retiree medical access and many other benefits depending on eligibility.

For more information, visit ;br>
We anticipate the application window for this opening will close on: 05/07/2025

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.