Identity Provider Engineer
Booz Allen Hamilton
Job Overview
Who's the hiring manager?
Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Job Description
Opportunity Overview
You know that the user is the last frontier for cybersecurity. It’s where the perimeter is drawn, and securing identities is pivotal in the fight against cybercriminals. As an Identity and Access Management (IAM) specialist, you have the skills and experience to keep hackers from taking data and breaking processes. We’re looking for someone like you to help our clients meet their missions without disruption.
What You'll Do
As an Identity Provider Engineer at Booz Allen, you’ll play a critical role in the world of IAM and zero trust. In this role, you’ll support large-scale IAM projects for our clients. You’ll interface with stakeholders and engineering teams to delve into the details and dependencies of critical processes and users’ roles within them.
You’ll analyze the identity lifecycle, articulating access requirements and defining enterprise identity records. You’ll use your experience in IAM to design, deploy, and support systems that verify appropriate user privileges and manage credentials for accessing our clients’ most valuable assets. From single sign-on to privileged access systems, you’ll have the chance to implement enterprise-class solutions and stop adversaries in their tracks.
Required Qualifications
- 5+ years of experience with Ping Federate, Okta, Entra ID, or ADFS
- Experience with SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC)
- Experience with Identity federation and Single Sign-On (SSO)
- Experience with access control models such as RBAC and ABAC
- Experience integrating IdPs with directory services such as Active Directory (AD) and LDAP, including synchronization and authentication workflows
- Knowledge of Zero Trust architectures and implementation of password-less authentication or multifactor authentication (MFA) within the IdP environment
- Ability to resolve complex identity and federation issues, including token validation errors, assertion mismatches, and connectivity problems
- Ability to design and operate IdP solutions across on-premises, hybrid, and cloud infrastructures, including AWS, Azure, or Google Cloud
- Active TS/SCI clearance; willingness to take a polygraph exam
- HS diploma or GED
Desired Qualifications
- Experience implementing System for Cross-domain Identity Management (SCIM) protocols for automated user provisioning and lifecycle management between identity providers and applications
- Experience with advanced platform features such as Okta Workflows, Ping Identity Suite advanced policy scripting, adaptive authentication, and the development of custom login pages
- Experience with scripting languages such as Python, PowerShell, or Bash to automate IdP configuration, monitoring, and remediation tasks
- Knowledge of cloud-native IAM services, including Azure Active Directory, AWS IAM, or Google Cloud Identity
- TS/SCI clearance with a polygraph
Clearance and Compensation Information
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; TS/SCI clearance is required. Compensation at Booz Allen is determined by various factors and includes comprehensive benefits, with a projected salary range of $86,800.00 to $198,000.00 (annualized USD).
Work Model and Non-Discrimination
Our people-first culture prioritizes the benefits of flexibility and collaboration. While the work model varies, this role likely involves a hybrid approach, combining in-person and remote work. All qualified applicants will receive consideration for employment without regard to disability, protected veteran status, or any other status protected by applicable law.
Key skills/competency
- Identity and Access Management (IAM)
- Ping Federate
- Okta
- Entra ID
- ADFS
- SAML 2.0
- OAuth 2.0
- OpenID Connect (OIDC)
- Zero Trust Architecture
- Multifactor Authentication (MFA)
- Role-Based Access Control (RBAC)
How to Get Hired at Booz Allen Hamilton
- Research Booz Allen Hamilton's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor.
- Tailor your resume for Identity Provider roles: Highlight your 5+ years of experience with Ping Federate, Okta, Entra ID, ADFS, and Zero Trust architectures.
- Showcase IAM expertise: Emphasize practical experience with SAML 2.0, OAuth 2.0, OIDC, RBAC, ABAC, and IdP integrations with AD/LDAP.
- Prepare for technical and clearance discussions: Be ready to discuss complex identity federation issues and confirm your active TS/SCI clearance eligibility for Booz Allen Hamilton.
- Demonstrate client-facing and problem-solving skills: Focus on your ability to interface with stakeholders and resolve intricate IdP deployment challenges.
Frequently Asked Questions
Find answers to common questions about this job opportunity
Explore similar opportunities that match your background