Identity Operation Engineer

Ekman Associates, Inc.

Los Angeles (CA)

Hybrid

USD 120,000 - 150,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Ekman Associates, Inc. is seeking an Identity Operations Engineer to manage and optimize hybrid identity, access, and governance services. The role covers Workday-driven lifecycle processes, Saviynt/IGA, AD/Entra ID, 365, MFA, PAM, and application integrations across on-site and remote environments.

The engineer will handle incidents, requests, changes, and audits, maintain integration reliability, and support 24/7 operations with strong communication across diverse teams.

Qualifications

  • Bachelor’s degree in computer science or related field.
  • Experience with at least two of: PingOne/Aura, 1Password, HashiCorp Vault, Microsoft Graph, SAML/OIDC/OAuth.
  • Experience integrating or troubleshooting ServiceNow orchestration with identity platforms.
  • Understanding of Microsoft 365 identity and federation dependencies.
  • Experience with PowerShell, Python, JSON/REST, SQL for IAM automation.
  • IT Certifications in Identity Management or ITIL Foundations desired.
  • International experience and multilingual skills a plus.
  • Strong hands-on experience with Active Directory and Entra ID.

Responsibilities

  • Operate and support identity lifecycle integrations with Workday and IGA workflows.
  • Provide ITIL-based operational support across identity services.
  • Troubleshoot identities, systems, access, authentication, and entitlements.
  • Maintain ServiceNow CMDB relationships for identity services.
  • Participate in security incident response related to IAM.
  • Ensure auditable evidence for access approvals and reviews.

Skills

IAM operations
Troubleshooting
Automation
ServiceNow
Workday integration
Entra ID/AD

Education

Bachelor’s degree in CS/Engineering
IT Certifications (MCSE CAMS ITIL)

Tools

PowerShell
Python
JSON/REST
Microsoft Graph
Saviynt
CyberArk
Splunk
ServiceNow
Workday

Job description

Title: Identity Operation Engineer
Location: Nashville, TN / 4 days onsite and 1 day remote

Ekman Associates is a management consulting firm that specializes in developing business, digital, and technology strategy, delivering solutions, and addressing human resource demands.

Summary

The Identity Operations Engineer operates and continuously improves hybrid identity, access, authentication, privileged-access, and identity-governance services. The role provides specialist operational support across Workday-driven identity lifecycle processes, Saviynt/IGA, Active Directory, Microsoft Entra ID, Microsoft 365, MFA, PAM, enterprise application integrations, and connected services.
The position will be a team player working to maintain reliable identity integrations and resolve operational issues involving joiners, movers, leavers, contractors, application access, entitlements, authentication, privileged accounts, and non-human identities. This role includes incident, request, change, problem, access-review, audit-evidence, monitoring, and automation activities. Effective communication skills are a must, all while being sensitive to a wide diversity of cultural and technical backgrounds in a global business environment.

Responsibilities
  • Apply least-privilege, segregation-of-duties, secure administration, and identity-governance best practices to protect information resources from unauthorized use, inappropriate access, disclosure, damage, or loss.
  • Troubleshoot and resolve issues related to identities, systems, access, accounts, authentication, authorization, entitlements, and permissions.
  • Investigate and resolve specialist escalations from AD Services and TechOps IAM queues, including application-role access, SecAdmin access, reference-user comparisons, disabled application accounts, access removals, and entitlement issues.
  • Provide ITIL-based operational support across identity services, including incident, request, change, problem, and major-incident participation. Maintain clear ServiceNow assignment, evidence, troubleshooting notes, resolution details, and closure criteria.
  • Operate and troubleshoot identity lifecycle integrations, including joiner, mover, leaver, contractor, rehire/rejoiner, and exception scenarios. Investigate failed provisioning tasks, reconciliation issues, orphaned accounts, and mismatches between authoritative HR data, IGA records, directories, and target applications.
  • Support Workday-driven lifecycle processes and Saviynt/IGA workflows, including access requests, approvals, entitlement ownership, access reviews, remediation, audit evidence, and provisioning/reconciliation failures.
  • Operate and support on-premises and cloud identity services and their configuration, including Active Directory domain services, Microsoft Entra ID, Microsoft 365, Duo, YubiKey/FIDO/PIV authentication, CyberArk/PAM, Saviynt/IGA, Splunk, Active Roles where applicable, PingOne/Aura where applicable, 1Password, HashiCorp Vault, and connected enterprise applications.
  • Troubleshoot Microsoft Entra enterprise applications and federation integrations, including SAML, OIDC/OAuth, claims, redirect URIs, app registrations, group assignments, Conditional Access, Microsoft Graph, certificates, and token/authentication failures.
  • Support privileged and non-human identities, including elevated accounts, service accounts, application accounts, RPA accounts, resource/test accounts, B2B/guest identities, and accounts requiring vault onboarding, password rotation, or ownership validation.
  • Support MFA and authentication operations, including Duo, YubiKey, FIDO/PIV, recovery/reset workflows, OAuth-token issues, and authentication failures across workforce and application services.
  • Complete the key metric reporting and analysis for the Identity Management environment as required.
  • Work to ensure audit tasks related to Identity Management are completed on time, with participation of appropriate parties. Maintain auditable evidence for access approvals, reviews, privileged access, lifecycle actions, exceptions, and remediation.
  • Participate in security incident response teams as needed, including identity compromise, suspicious authentication, privileged-access, credential, and account-containment activities.
  • Utilize industry best practices for appropriate standards, processes, procedures, tools, and documentation.
  • Ensure the maintenance, patching, operating, and monitoring of IAM systems is in place and completed on schedule. Use Splunk and observability service dashboards to identify failures, trends, and emerging operational risk.
  • Maintain accurate ServiceNow CMDB relationships for identity services, configuration items, application integrations, owners, support groups, and dependencies; identify and report stale or incomplete CMDB data.
  • Participate in developing automation to reduce the time spent on routine tasks.
  • This is a shift-based role supporting 24/7 follow-the-sun Technical Operations Center.
  • The role participates in scheduled shifts, weekend/public-holiday coverage, on-call rotation, and structured handoffs with regional operations teams
Qualifications
  • Bachelor’s degree in computer science, engineering, a closely related field, or comparable education and experience.
  • Experience with at least two of the following is desirable: PingOne/Aura, 1Password, HashiCorp Vault, Microsoft Graph, SAML/OIDC/OAuth, enterprise application onboarding, or secrets/service-account rotation.
  • Experience integrating or troubleshooting ServiceNow orchestration with identity platforms, directories, SaaS applications, or enterprise applications is desirable.
  • Understanding of Microsoft 365 identity, group, collaboration, and federation dependencies.
  • Experience using PowerShell, Python, JSON/REST, Microsoft Graph, SQL, or comparable scripting/API technologies for IAM automation and troubleshooting. Legacy Java, SOAP, or database experience.
  • IT Certifications including MCSE Certification specialization in Identity Management, Certified Access Management Specialist (CAMS), and ITIL Foundations certifications desired.
  • International experience beneficial; multiple language skills a plus.
  • Solid technical skills in the Identity Management space, including Active Directory and Entra ID.
  • Minimum of five years directly related experience in Identity & Access Management (IAM).
  • A strong ability for troubleshooting and problem analysis is required, along with the ability to clearly communicate the results of problem analysis to business stakeholders, IT support teams, and network providers to quickly and effectively resolve operational issues.
  • Experience troubleshooting and solving issues related to identities, systems, access, accounts, authentication, authorization, entitlements, and permissions
  • Hands-on experience operating and supporting Active Directory and Entra ID, including directory services, delegated administration, group policy, OUs, sites/replication, identity synchronization, enterprise applications, federation, Conditional Access, and authentication.
  • Hands-on experience with Saviynt or another IGA platform, including access requests, approvals, entitlement administration, access reviews, failed-task remediation, reconciliation, and audit evidence.
  • Experience with identity lifecycle integrations from an authoritative HR source such as Workday, including joiner/mover/leaver, contractor, rehire, and exception handling.
  • Customer service driven/focused with a proactive and positive can-do approach. Demonstrates commitment to organization’s policy framework and practices continuous improvement.
  • Hands-on experience and skills with systems such as M365 and ServiceNow are required. Experience using ServiceNow for IAM incidents, requests, changes, knowledge, evidence, assignment groups, and CMDB relationships is required.
  • Demonstrated current work experience supporting integrated IAM solutions such as Entra ID, Active Roles where applicable, Duo, PKI, and CyberArk/PAM
  • Working knowledge of site-reliability/operational-engineering principles, monitoring, automation, and safe use of AI-assisted tools.
  • Demonstrated organizational skills, attention to detail and ability to work both independently and as part of a team.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr Identity and Access Management Analyst
Sr Identity and Access Management Analyst

Chicago Bridge & Iron Company • The Woodlands (TX)

On-site
USD 100,000 - 130,000
Identity & Security Engineer
Identity & Security Engineer

Coda Search│Staffing • Town of Texas (WI)

Hybrid
USD 110,000 - 170,000
Sr Identity & Access Management Engineer (IAM)
Sr Identity & Access Management Engineer (IAM)

Early Warning • Chicago (IL)

Hybrid
USD 150,000 - 190,000
Hybrid work model
Senior Identity and Access Management Analyst
Senior Identity and Access Management Analyst

Baptist Memorial Health Care Corporation • Memphis (TN)

On-site
USD 110,000 - 140,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000
Staff Identity Governance and Access Engineer
Staff Identity Governance and Access Engineer

United States Digital Space LLC • Washington

On-site
USD 180,000 - 230,000
Senior Identity and Access Management Analyst
Senior Identity and Access Management Analyst

Baptist Memorial Health Care • Memphis (TN)

On-site
USD 110,000 - 160,000
Identity Operations Engineer - IAM & Automation Lead
Identity Operations Engineer - IAM & Automation Lead

Ekman Associates, Inc. • Los Angeles (CA)

Hybrid
USD 120,000 - 150,000
Sr. Identity & Access Management (IAM) Engineer
Sr. Identity & Access Management (IAM) Engineer

NKC Health • Kansas City (MO)

On-site
USD 100,000 - 130,000
Identity & Access Management (IAM)- Senior Engineer - Microsoft Entra
Identity & Access Management (IAM)- Senior Engineer - Microsoft Entra

ARK Infotech Spectrum India Pvt. Ltd • Dallas (TX)

Hybrid
USD 110,000 - 150,000
Hybrid work arrangement