Full Job Description
Westat is seeking a Senior Identity and Access Management (IAM) Engineer to design, implement, and support the organization's IAM solutions across on-premises, cloud, and hybrid environments. This role will interface with the Infrastructure and IT Security team and serve as the subject-matter expert for IAM technologies, cloud-based identity services, and secure access management.
This is a US-based role, and applicants must reside in the Greater D.C. Metropolitan (DMV) Area and be able to work in Westat's Bethesda office 3 days per week.
Job Responsibilities:
- Manage and optimize hybrid identity infrastructure across on-premises Active Directory, Azure AD/Entra AD, including domain controllers, group policies, authentication mechanisms, and cloud-based identity services.
- Design and support multiple DNS zones and troubleshoot related issues.
- Maintain and enhance Okta identity and access management solutions, including single sign-on (SSO), multi-factor authentication (MFA), and secure access for cloud and on-premises applications.
- Work with Entra AD, M365, and other cloud-based identity management systems to streamline user provisioning, deprovisioning, access control, and identity-based cloud service integrations.
- Continuously improve identity services by evaluating innovative technologies, implementing best practices, and optimizing performance.
- Work closely with security, network, and application teams to integrate identity services seamlessly while ensuring compliance and other regulatory requirements.
- Provide technical support by troubleshooting and resolving complex identity-related issues, minimizing impact on end users.
- Create comprehensive documentation and conduct training sessions for IT staff and end-users.
- Ensure compliance with industry and regulatory requirements, including FISMA Moderate compliance.
Basic Qualifications:
- A minimum of 7 years of progressive IT experience; or a bachelor's degree in a related technical field with a minimum of 5 years of progressive IT experience.
- Demonstrated knowledge of Active Directory, Azure AD/Entra AD, and cloud identity services, with a focus on access control, authentication, and secure user lifecycle management.
- Demonstrated knowledge of domain controllers, trusts, and replication.
- Demonstrated experience in DNS management and troubleshooting.
- Experience with Okta or other cloud-based identity and access management (IAM) platforms, including Single Sign-On technologies and multi-factor authentication.
- Demonstrated experience supporting enterprise infrastructure solutions.
- Demonstrated experience supporting cloud infrastructure and services, including Amazon Web Services (AWS), Microsoft Azure, and Azure Cloud Services.
Preferred Qualifications:
- Meticulous with excellent organization and analytical and critical thinking skills.
- Able to communicate clearly and effectively.
- Ability to explain highly technical concepts in simple terms.
- Ability to analyze complex issues, propose effective solutions, and implement them efficiently.
- Excellent people skills to work effectively with cross-functional teams and build strong relationships.
Westat offers a well-rounded and comprehensive benefits program focused on wellness and work/life balance. Subject to plan requirements, employees may participate in:
- Employee Stock Ownership Plan
- 401(k) Retirement Plan
- Paid Parental Leave
- Vacation Leave (20 days per year)
- Sick Leave (9 days per year)
- Holiday Leave (7 government holidays and 2 floating holidays)
- Professional Development
- Health Advocate
- Employee Assistance Program
- Travel Accident Insurance
- Medical Insurance
- Dental Insurance
- Vision Insurance
- Short Term Disability Insurance
- Long Term Disability Insurance
- Life and AD&D Insurance
- Critical Illness Insurance
- Supplemental Life Insurance
- Flexible Spending Account
- Health Savings Account
This opportunity will be posted for a minimum of 5 days and applications will be accepted on an ongoing basis.
Employment Eligibility: This is a U.S.-based position. Candidates must be authorized to work in the United States on a full-time basis. Westat does not offer employment-based visa sponsorship (including H-1B sponsorship) for this role. Depending on project requirements, some positions may require employees to meet specific residency criteria.
#LI-WST1 #HYBRID