About the Role
The Identity and Access Management (IAM) Engineer provides technical and operational support for the University's IAM services, including authentication, authorization, access provisioning, multifactor authentication, public key infrastructure, and SSL/TLS certificate operations. This role emphasizes configuration, troubleshooting, service reliability, customer support, documentation, and automation.
Responsibilities
- Provide day-to-day operational support for IAM and access management services, including MFA, access provisioning, authentication and authorization support, and service monitoring.
- Troubleshoot access, login, certificate, provisioning, and related service issues; coordinate with support teams, application owners, customers, and vendors.
- Configure and maintain existing IAM services and related security controls, including role-based and attribute-based access concepts, SSL/TLS certificates, PKI-related services, and selected directory or identity repository functions.
- Support Linux-based IAM service hosts and cloud-hosted service components, including patching coordination, maintenance, monitoring, and operational readiness.
- Develop scripts, reports, documentation, and lightweight automation to improve repeatability, reduce operational toil, validate access controls, support metrics, and assist with service transition or retirement efforts.
- Provide secondary/backfill support for SSO and federation-related work using technologies such as SAML, OAuth, and OIDC.
- Participate in a shared on-call rotation for critical IAM services.
Requirements
- Bachelor's degree and 2-3 years of related experience in identity and access management, information security, systems administration, application support, or a related technical operations role, or equivalent combination of education and experience.
- Experience supporting production systems, troubleshooting complex technical issues, working with customers or support teams, and using scripting or automation.
- Comfortable working independently with limited supervision.
- Ability to communicate clearly with technical and non-technical stakeholders.
- Willingness to learn new IAM and security technologies as service needs evolve.
- Background checks may be required after a conditional job offer is made.
Skills
- Identity and Access Management (IAM)
- Authentication
- Authorization
- Access Provisioning
- Multifactor Authentication (MFA)
- Public Key Infrastructure (PKI)
- SSL/TLS Certificates
- SAML
- OAuth
- OIDC
- Scripting
- Automation
Location
- Philadelphia, Pennsylvania
Work Type
- Onsite
Experience Level
- 2-3 years
Education Level
- Bachelor's degree
Salary/Compensations
- $71,733.00 - $90,000.00 Annual Rate
Benefits
- Comprehensive medical, prescription, behavioral health, dental, vision, and life insurance benefits.
- Flexible spending accounts for health care and dependent care expenses.
- Tuition assistance for employees, spouses, and dependent children at Penn and potentially other institutions.
- Generous retirement plans (Basic, Matching, Supplemental) with pre-tax or Roth options through TIAA and Vanguard.
- Substantial time away from work for vacation, personal affairs, illness, or family needs.
- Long-Term Care Insurance partnership with Genworth Financial.
- Wellness and Work-life Resources programs.
- Professional and Personal Development resources.
- Access to University resources, cultural activities, and recreational facilities.
- Discounts and special services on arts, entertainment, transportation, mortgages, and more.
- Flexible Work Hours options.
- Penn Home Ownership Services forgivable loan.
- Adoption Assistance reimbursement.
About the Company
- The University of Pennsylvania is the largest private employer in Philadelphia, a world-renowned leader in education, research, and innovation, and a historic, Ivy League school consistently ranking among the top 10 universities.
- Information Systems & Computing (ISC) is the University of Pennsylvania’s central IT organization, providing core network, data, voice, video, and enterprise application infrastructure and services.
- ISC strives to be easy to work with and serve as a trusted advisor to Penn’s IT community, faculty, staff, and students.
- ISC’s focus on customer service and high-quality, cost-effective, reliable implementation of modern IT solutions advances the mission of the University.
Equal Opportunity
- The University of Pennsylvania is an equal opportunity employer. Candidates are considered for employment without regard to race, color, sex, sexual orientation, religion, creed, national origin (including shared ancestry or ethnic characteristics), citizenship status, age, disability, veteran status or any class protected under applicable federal, state or local law.
