Identity Operation Engineer

Ekman Associates, Inc

  • Woodland Hills, CA
  • Today
  • Full-time
  • Employee

Highlights

Operate and support on-premises and cloud identity services and their configuration, including Active Directory domain services, Microsoft Entra ID, Microsoft 365, Duo, YubiKey/FIDO/PIV authentication, CyberArk/PAM, Saviynt/IGA, Splunk, Active Roles where applicable, PingOne/Aura where applicable, 1Password, HashiCorp Vault, and connected enterprise applications. Support privileged and non-human identities, including elevated accounts, service accounts, application accounts, RPA accounts, resource/test accounts, B2B/guest identities, and accounts requiring vault onboarding, password rotation, or ownership validation.

Numbers & Facts

LocationWoodland Hills, CA
Job TypeFull-time, Employee

Description

Job Description

Title: Identity Operation Engineer
Location: Nashville, TN / 4 days onsite and 1 day remote

Ekman Associates is a management consulting firm that specializes in developing business, digital, and technology strategy, delivering solutions, and addressing human resource demands.
​
Summary:
The Identity Operations Engineer operates and continuously improves hybrid identity, access, authentication, privileged-access, and identity-governance services. The role provides specialist operational support across Workday-driven identity lifecycle processes, Saviynt/IGA, Active Directory, Microsoft Entra ID, Microsoft 365, MFA, PAM, enterprise application integrations, and connected services.

The position will be a team player working to maintain reliable identity integrations and resolve operational issues involving joiners, movers, leavers, contractors, application access, entitlements, authentication, privileged accounts, and non-human identities. This role includes incident, request, change, problem, access-review, audit-evidence, monitoring, and automation activities.Effective communication skills are a must, all while being sensitive to a wide diversity of cultural and technical backgrounds in a global business environment.


Responsibilities:
  • Apply least-privilege, segregation-of-duties, secure administration, and identity-governance best practices to protect information resources from unauthorized use, inappropriate access, disclosure, damage, or loss.
  • Troubleshoot and resolves issues related to identities, systems, access, accounts, authentication, authorization, entitlements, and permissions.
  • Investigate and resolve specialist escalations from AD Services and TechOps IAM queues, including application-role access, SecAdmin access, reference-user comparisons, disabled application accounts, access removals, and entitlement issues.
  • Provide ITIL-based operational support across identity services, including incident, request, change, problem, and major-incident participation. Maintain clear ServiceNow assignment, evidence, troubleshooting notes, resolution details, and closure criteria.
  • Operate and troubleshoot identity lifecycle integrations, including joiner, mover, leaver, contractor, rehire/rejoiner, and exception scenarios. Investigate failed provisioning tasks, reconciliation issues, orphaned accounts, and mismatches between authoritative HR data, IGA records, directories, and target applications.
  • Support Workday-driven lifecycle processes and Saviynt/IGA workflows, including access requests, approvals, entitlement ownership, access reviews, remediation, audit evidence, and provisioning/reconciliation failures.
  • Operate and support on-premises and cloud identity services and their configuration, including Active Directory domain services, Microsoft Entra ID, Microsoft 365, Duo, YubiKey/FIDO/PIV authentication, CyberArk/PAM, Saviynt/IGA, Splunk, Active Roles where applicable, PingOne/Aura where applicable, 1Password, HashiCorp Vault, and connected enterprise applications.
  • Troubleshoot Microsoft Entra enterprise applications and federation integrations, including SAML, OIDC/OAuth, claims, redirect URIs, app registrations, group assignments, Conditional Access, Microsoft Graph, certificates, and token/authentication failures.
  • Support privileged and non-human identities, including elevated accounts, service accounts, application accounts, RPA accounts, resource/test accounts, B2B/guest identities, and accounts requiring vault onboarding, password rotation, or ownership validation.
  • Support MFA and authentication operations, including Duo, YubiKey, FIDO/PIV, recovery/reset workflows, OAuth-token issues, and authentication failures across workforce and application services.
  • Complete the key metric reporting and analysis for the Identity Management environment as required.
  • Work to ensure audit tasks related to Identity Management are completed on time, with participation of appropriate parties. Maintain auditable evidence for access approvals, reviews, privileged access, lifecycle actions, exceptions, and remediation.
  • Participate in security incident response teams as needed, including identity compromise, suspicious authentication, privileged-access, credential, and account-containment activities.
  • Utilize industry best practices for appropriate standards, processes, procedures, tools, and documentation.
  • Ensure the maintenance, patching, operating, and monitoring of IAM systems is in place and completed on schedule. Use Splunk and observability service dashboards to identify failures, trends, and emerging operational risk.
  • Maintain accurate ServiceNow CMDB relationships for identity services, configuration items, application integrations, owners, support groups, and dependencies; identify and report stale or incomplete CMDB data.
  • Participate in developing automation to reduce the time spent on routine tasks.
  • This is a shift-based role supporting 24/7 follow-the-sun Technical Operations Center.
  • The role participates in scheduled shifts, weekend/public-holiday coverage, on-call rotation, and structured handoffs with regional operations teams

Qualifications:
  • Bachelor's degree in computer science, engineering, a closely related field, or comparable education and experience.
  • Experience with at least two of the following is desirable: PingOne/Aura, 1Password, HashiCorp Vault, Microsoft Graph, SAML/OIDC/OAuth, enterprise application onboarding, or secrets/service-account rotation.
  • Experience integrating or troubleshooting ServiceNow orchestration with identity platforms, directories, SaaS applications, or enterprise applications is desirable.
  • Understanding of Microsoft 365 identity, group, collaboration, and federation dependencies.
  • Experience using PowerShell, Python, JSON/REST, Microsoft Graph, SQL, or comparable scripting/API technologies for IAM automation and troubleshooting. Legacy Java, SOAP, or database experience.
  • IT Certifications including MCSE Certification specialization in Identity Management, Certified Access Management Specialist (CAMS), and ITIL Foundations certifications desired.
  • International experience beneficial; multiple language skills a plus.
  • Solid technical skills in the Identity Management space, including Active Directory and Entra ID.
  • Minimum of five years directly related experience in Identity & Access Management (IAM).
  • A strong ability for troubleshooting and problem analysis is required, along with the ability to clearly communicate the results of problem analysis to business stakeholders, IT support teams, and network providers to quickly and effectively resolve operational issues.
  • Experience troubleshooting and solving issues related to identities, systems, access, accounts, authentication, authorization, entitlements, and permissions
  • Hands-on experience operating and supporting Active Directory and Entra ID, including directory services, delegated administration, group policy, OUs, sites/replication, identity synchronization, enterprise applications, federation, Conditional Access, and authentication.
  • Hands-on experience with Saviynt or another IGA platform, including access requests, approvals, entitlement administration, access reviews, failed-task remediation, reconciliation, and audit evidence.
  • Experience with identity lifecycle integrations from an authoritative HR source such as Workday, including joiner/mover/leaver, contractor, rehire, and exception handling.
  • Customer service driven/focused with a proactive and positive can-do approach. Demonstrates commitment to organization's policy framework and practices continuous improvement.
  • Hands-on experience and skills with systems such as M365 and ServiceNow are required. Experience using ServiceNow for IAM incidents, requests, changes, knowledge, evidence, assignment groups, and CMDB relationships is required.
  • Demonstrated current work experience supporting integrated IAM solutions such as Entra ID, Active Roles where applicable, Duo, PKI, and CyberArk/PAM
  • Working knowledge of site-reliability/operational-engineering principles, monitoring, automation, and safe use of AI-assisted tools.
  • Demonstrated organizational skills, attention to detail and ability to work both independently and as part of a team.

Qualified Candidates Only: If you wish to learn more about this opportunity and additional qualifications/responsibilities, please submit your resume. To learn more about Ekman Associates, Inc. please visit our website at www.ekmanassociates.com.

Similar Jobs

See more jobs