Pay Range:$83,200.00 - $124,800.00
Please email if you are a candidate seeking a reasonable accommodation for the application and/or interview process.
Why this job matters:Supports and administers enterprise identity platforms across Microsoft Entra ID, Azure, Okta, Active Directory, and Google Cloud Platform (GCP) environments. Works under the guidance of senior engineers and IT leadership to design, implement, secure, automate, and maintain identity services that enable secure access to enterprise applications, cloud resources, and business data. Assists with identity lifecycle management, Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, Privileged Access Management (PAM), cloud access governance, federation services, and identity security initiatives. Contributes to the organization's Zero Trust strategy, cloud transformation efforts, automation initiatives, and regulatory compliance requirements supporting protected and sensitive data.
What you will do:- Administer and support Microsoft Entra ID, Active Directory, and Okta environments, including user lifecycle management, group administration, authentication services, directory synchronization, and access governance.
- Design, implement, and maintain Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, Passwordless Authentication, and Identity Protection capabilities across cloud and on-premises applications.
- Manage Privileged Identity Management (PIM), Role-Based Access Control (RBAC), administrative role assignments, service accounts, and privileged access operations across Microsoft Azure, Entra ID, Okta, and GCP environments.
- Configure and maintain application integrations utilizing SAML, OAuth 2.0, OpenID Connect (OIDC), SCIM, LDAP, Kerberos, and federation technologies to enable secure authentication and provisioning.
- Support Google Cloud Platform (GCP) identity services, including Cloud Identity, IAM roles, service accounts, workload identity federation, and secure access to GCP resources and services.
- Contribute to automation and workflow optimization using PowerShell, Microsoft Graph API, Terraform, Python, Okta Workflows, Azure Automation, and Infrastructure-as-Code practices to improve operational efficiency and governance.
- Investigate and resolve complex identity, authentication, provisioning, authorization, and access-related incidents escalated from Service Desk, Infrastructure, Security Operations, and application support teams.
- Participate in Identity Governance, compliance, audit readiness, security assessments, Proof-of-Concept initiatives, and continuous improvement efforts while supporting organizational requirements related to HIPAA, SOC2, NIST, and Zero Trust security frameworks.
- Perform other duties as assigned.
What you need to succeed:- Bachelor's degree in Computer Science, Information Technology, Information Systems, Cybersecurity, or a related field is preferred but not required; equivalent hands-on experience may fully substitute for formal education.3-5 years of direct experience in Identity and Access Management (IAM), Cloud Identity, Directory Services, Access Management, or Security Engineering within enterprise environments.
- Strong knowledge of identity and access management technologies including Microsoft Entra ID (Azure AD), Active Directory Domain Services, Microsoft Entra Connect/Cloud Sync, Azure RBAC, Okta Workforce Identity Cloud, Google Cloud IAM, Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, and Privileged Identity Management (PIM).
- Demonstrated hands-on expertise with enterprise authentication, federation, and identity integration technologies including SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), SCIM, and LDAP.
- Strong understanding of Identity and Access Management (IAM) concepts and best practices.
- Expertise in authentication, authorization, federation, and identity governance.
- Strong troubleshooting skills across identity, network, security, and cloud environments.
- Ability to automate operational tasks using PowerShell, Python, Terraform, Azure CLI, and APIs.
- Strong understanding of certificate-based authentication, PKI, and cryptographic concepts.
- Ability to develop technical documentation, standards, SOPs, and architecture diagrams.
- Strong collaboration and communication skills when working with Security, Infrastructure, Cloud, Application Development, and Compliance teams.
- Ability to manage multiple priorities and deliver projects within established timelines.
- Understanding of requirements for building and maintaining a secure identity environment.
- Ability to identify opportunities for automation, process improvement, and AI-assisted operational efficiencies.
The extras:- Experience supporting hybrid and cloud identity environments, including Microsoft 365, Azure, Google Cloud, and enterprise SaaS application integrations.
- Hands-on experience with user provisioning, identity synchronization, federation services, access requests, account lifecycle automation, and governance processes.
- Experience troubleshooting authentication, authorization, federation, conditional access, MFA, and identity synchronization issues across on-premises and cloud environments.
- Knowledge of security best practices related to identity protection, privileged access management, Zero Trust architecture, identity risk management, and compliance requirements.
- Experience supporting identity-related migrations, platform upgrades, cloud adoption initiatives, and enterprise access management transformations.
- Advanced knowledge of Microsoft Entra Identity Governance and Access Reviews.
- Experience with Okta Identity Engine and Okta Workflows.
- Proficiency with Microsoft Graph API, Azure Automation, and Azure Landing Zone identity controls.
- Experience with Terraform and Infrastructure-as-Code practices.
- Experience securing cloud-native applications and APIs.
- Familiarity with ServiceNow integrations and IAM workflow automation.
- Knowledge of CyberArk, Delinea, or other PAM solutions.
- Experience supporting regulated healthcare or financial environments.
- Understanding of HIPAA, SOC2, NIST, CIS Controls, and cybersecurity frameworks.
- Familiarity with security monitoring, audit logging, and incident response processes.
- Microsoft Certified in any of the following: Identity and Access Administrator Associate (SC-300); Azure Administrator Associate (AZ-104), Azure Solutions Architect Expert (AZ-305), Cybersecurity Architect Expert (SC-100)
- ITIL Foundation Certification
- Any other Identity Certification e.g. Okta
Location:BCBSRI is headquartered in downtown Providence, conveniently located near the train station and bus terminal. We actively support associate well-being and work/life balance and offer the following schedules, based on role:
- In-office: onsite 5 days per week
- Hybrid: onsite 2-4 days per week
- Remote: onsite 0-1 days per week. Permitted to reside in the following states, pending approval from the Human Resources Department: Arizona, Connecticut, Florida, Georgia, Louisiana, Massachusetts, North Carolina, Oklahoma, Rhode Island, South Carolina, Texas, Virginia