SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Aurora is seeking a hands-on Senior Identity Management Engineer to lead the technical implementation of a modern identity ecosystem built on Zero Trust principles. You will be the primary execution engine responsible for implementing newly licensed IAM tools (Conductor One and Ping Directory) while working closely with the IAM Architect.
The role encompasses the full IAM lifecycle, evolving Aurora's existing infrastructure—which already features SPIRE, Open Policy Agent (OPA), and a custom-built group management engine—into a scalable, modern ecosystem that serves as a competitive advantage.
Key responsibilities include:
- Complete baseline environment configuration for Ping Directory and Conductor One across Dev and Prod tiers
- Integrate HRIS (Workday) with the IGA platform to automate Joiner-Mover-Leaver (JML) processes
- Build and validate production-ready connectors for the core ecosystem, including Okta, AWS, Google, Slack, and Squad
- Deploy "Justify or Revoke" workflows and automated reporting to support SOX/ISO privileged access reviews
- Execute migration of Workforce and Service identities to Ping Directory
- Define technical test plans, draft formal procedural documentation for audits, and create system runbooks for the operations team
Required qualifications: 4+ years in Information Security with at least 2 years implementing IAM solutions in large enterprise environments. Expert-level knowledge of at least one major Cloud Identity Provider (AWS IAM, Azure) and core protocols including SAML, OAuth 2.0, OIDC, SCIM, and LDAP. Deep understanding of Zero Trust principles and access models (RBAC, ABAC, PBAC). Bachelor's or Master's degree in Computer Science, IT, or equivalent practical experience. Ability to develop code in Python or Go.
Desirable qualifications include experience with IdPs (Okta, Auth0, Microsoft Entra ID), IGA/PAM platforms (Conductor One, SailPoint, Saviynt), Ping Directory or similar LDAP solutions, AWS cloud infrastructure, Kubernetes, Infrastructure-as-Code (Terraform, Helm), CI/CD platforms (ArgoCD), and API security using OAuth scopes and claims.