Job Summary
The IAM Engineer is a hands on technical role responsible for the implementation configuration and day to day operations of the organizations Identity and Access Management platforms. The role focuses on administering Ping Identity (SSO or MFA) and BeyondTrust (PAM) solutions managing user and access lifecycle activities configuring authentication policies and enforcing least privilege access. The Engineer will work closely with the IAM Architect security operations
Responsibilities
Experience Required
5 to 8 years of hands on experience in Identity and Access Management engineering including PAM SSO and MFA platform administration.
Key Responsibilities
Perform day to day administration of PAM (BeyondTrust) SSO and MFA (Ping Identity) platforms including configuration changes integrations and health checks.
Execute user and access lifecycle management activities onboarding role changes transfers terminations and privileged account provisioning.
Resolve access issues and incidents troubleshoot authentication failures SSO or federation problems MFA enrollment issues and PAM session errors.
Implement Access & Policy Management changes configure roles authentication policies adaptive access rules and policy maintenance per approved standards.
Enforce Least Privilege onboard privileged accounts to the vault configure session management and recording and remediate excessive entitlements.
Execute periodic access reviews generate certification campaigns support reviewers and process revocations and remediation actions.
Integrate applications with Ping Identity (SAML OAuth OIDC) and onboard privileged systems into BeyondTrust.
Maintain operational documentation runbooks and configuration baselines support audits and compliance evidence gathering.
Technical Skills & Technologies
Ping Identity PingFederate PingAccess PingOne PingID (hands on configuration).
BeyondTrust Password Safe Privileged Remote Access Endpoint Privilege Management.
Authentication standards SAML 2.0 OAuth 2.0 OIDC MFA technologies.
Directory services Active Directory Azure AD or Entra ID LDAP.
Scripting PowerShell Python or Bash for automation (advantageous).
Required Qualifications
Bachelors degree in Computer Science Information Technology Information Security or a related field.
Hands on experience administering Ping Identity and BeyondTrust platforms.
Strong understanding of SSO MFA federation and PAM concepts.
Experience with user lifecycle management and access certification processes.
Familiarity with ITIL based change incident and problem management.
Certifications Required
Ping Identity Certified Associate / Professional
BeyondTrust Certified Engineer / Administrator
CompTIA Security+
Microsoft Identity certifications (SC-300) (preferred)
ITIL Foundation (preferred)
What we offer
- The chance to work with impact. Here, you’re empowered to bring your biggest thinking to help our company and clients improve everyday life.
- Ownership over your career. Stay at the top of your game through our award-winning learning and development ecosystem. And when your ambitions change or we offer new opportunities, we help you pivot by providing reskilling, on-the-job learning and guidance to find new roles that might be a better fit.
- The opportunity to thrive on a high caliber team with heart. We celebrate each other’s experiences and perspectives and promote a sense of belonging through our affinity groups and diversity and inclusion initiatives.
- A comprehensive total rewards package, including a competitive salary and a pension plan with matching contributions.
- Flexible health and financial benefits to support you and your eligible dependents—from day one.
- True work-life balance. Be at your best through paid time off, flexible work arrangements, volunteering opportunities, social events, and so much more.
About us
Cognizant (Nasdaq: CTSH) is an AI Builder and technology services provider, building the bridge between AI investment and enterprise value by building full-stack AI solutions for our clients. Our deep industry, process and engineering expertise enables us to build an organization’s unique context into technology systems that amplify human potential, realize tangible returns and keep global enterprises ahead in a fast-changing world. See how at www.cognizant.com or @cognizant.
Other employment-related information
Cognizant is an equal opportunity employer. Your application and candidacy will not be considered based on race, color, sex, religion, creed, sexual orientation, gender identity, national origin, disability, genetic information, pregnancy, veteran status or any other characteristic protected by federal, provincial or local laws.
If you have a disability that requires reasonable accommodation to search for a job opening or submit an application, please email [email protected] with your request and contact information.
Language requirements vary depending on roles, but we ask that all candidates have basic English proficiency for company-wide communications purposes. For roles based in Quebec, professional English proficiency is required, as you’ll deliver services to and collaborate with stakeholders outside the province who may not speak French.










