远程工作雷达

高级访问管理工程师 - Duo / MFA专家(美国远程)

Senior Access Management Engineer - Duo / MFA Specialist (Remote in the U.S.)

开发工程全球可投
公司guidepointsecurity
薪资未公开
工作地点Remote
地域资格全球可投
时区要求无特别要求
用工类型未标注
发布时间6 天前
数据来源Greenhouse
前往企业招聘页投递 →
全球可投:该职位未限制候选人所在地区。仍需注意薪资可能按地区折算,以及实际签约方式(正式雇佣 / 独立合同)。

GuidePoint Security 提供值得信赖的网络安全专业知识、解决方案和服务,帮助组织做出更好的决策并降低风险。通过采用三层、全面的方法来评估安全态势和生态系统,GuidePoint 使一些国内顶尖组织,如财富 500 强公司和美国政府机构,能够识别威胁、优化资源并集成最适合的解决方案以降低风险。

职位概述

GuidePoint Security 正在招聘一名高级访问管理工程师,专注于 Cisco Duo,加入我们的实施团队,全职工作。这是一个完全远程的职位,我们寻找在 Duo Security 部署、迁移和集成方面有深入实践经验的候选人——同时具备 Okta 和/或 Ping Identity 平台的次级熟练技能,以支持更广泛的访问管理项目。

高级访问管理工程师负责为美国最大的组织设计、部署、集成和优化 Duo 多因素认证(MFA)和访问解决方案。该职位是所有 Duo 项目的首要技术负责人,负责架构决策、集成设计和交付执行。当 Duo 项目未充分利用资源时,该人员将转为支持工程师角色,参与 Okta 和 Ping Identity 项目,在项目负责人指导下进行实际的技术工作。

该职位位于安全、基础设施和应用集成的交汇点——确保多因素认证、设备信任和自适应访问策略得到安全、可靠且可扩展的实现。

关于访问管理团队

加入访问管理团队意味着在 IAM 领域的最前沿工作。作为高级访问管理工程师,您将与其他工程师和架构师合作,帮助美国最大的公司实施他们自己的身份和访问管理计划。从参与评估到 IAM 平台的完整交付,您将在与客户互动的各个层面发挥作用。您的领导力和专业技能对为客户提供所需指导以及 GuidePoint Security 所期望的卓越服务至关重要。

我们与该领域的最大供应商合作,以确保我们的团队始终可以获得最新的培训。高水平的沟通和协作是标准。

查看英文原文

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

General Description

GuidePoint Security is hiring a Senior Access Management Engineer specializing in Cisco Duo to join our implementation team on a full-time basis. This is a fully remote role where we are looking for deep, hands-on experience leading Duo Security deployments, migrations, and integrations — with secondary proficiency in Okta and/or Ping Identity platforms to support broader Access Management engagements.

The Senior Access Management Engineer is responsible for designing, deploying, integrating, and optimizing Duo MFA and access solutions for some of the largest organizations in the US. This role serves as the go-to technical lead for all Duo engagements, owning architecture decisions, integration design, and delivery execution. When Duo engagements are not fully utilizing capacity, this resource will flex into a supporting engineer role on Okta and Ping Identity projects, contributing hands-on technical work under the direction of the engagement's lead architect.

This role sits at the intersection of security, infrastructure, and application integration — ensuring that multi-factor authentication, device trust, and adaptive access policies are implemented securely, reliably, and at scale.

About the Access Management practice

Coming to the Access Management team means working on the leading edge in the IAM space. As a Senior Access Management Engineer, you will be partnering with other engineers and architects to help some of the largest companies in the US implement their own identity and access management programs. From participating in assessments to full delivery of IAM platforms, you can expect to be involved at all levels of interaction with our customers. Your leadership and expertise are critical to providing our customers with the guidance they need, and the excellence they expect from GuidePoint Security.

We partner with the largest vendors in the space to ensure that the latest training is always available to our team. High level communication and collaboration are the standard. Mentorship at all levels, from Senior Architects to Junior Engineers, is foundational to our culture. We don't just talk about work life balance; we facilitate it with an unlimited PTO benefit.

We understand that in order to retain our talented team, leadership must provide regular feedback and coaching. We recruit new members to the team with the understanding that opportunities for growth are important. Whether your goals include future leadership opportunities, becoming an Architect or even moving to another discipline within security in time, the leadership team is focused on partnering with you to help achieve them.

Roles and Responsibilities:

Duo Security – Lead Engineer  (Primary – 50%)

  • Serve as the primary technical lead on all Duo Security engagements, owning end-to-end delivery from design through implementation and handoff
  • Lead Duo deployment architecture and design, including:
  • Duo MFA — Policy design, user enrollment strategies, self-service portal configuration, and phased rollout planning
  • Duo Authentication Proxy — Deployment, configuration, high availability, and integration with RADIUS, LDAP, and Active Directory
  • Duo Single Sign-On (SSO) — SAML 2.0 and OIDC federation, application onboarding, and custom login branding
  • Duo Device Trust — Trusted endpoint policies, certificate-based device verification, and managed/unmanaged device posture enforcement
  • Duo Network Gateway (DNG) — Clientless remote access to internal web applications and SSH/RDP resources
  • Duo Admin Panel & API — Tenant configuration, Admin API and Auth API integrations, custom scripting, and reporting
  • Duo Trusted Endpoints — Integration with endpoint management platforms (Intune, Jamf, Workspace ONE, etc.)
  • Duo Desktop (formerly Duo Device Health) — Endpoint health verification and posture-based access policies
  • Design and implement Duo integrations across a wide range of application and infrastructure types, including:
  • VPN concentrators (Cisco ASA, Palo Alto GlobalProtect, Fortinet, Pulse/Ivanti)
  • Remote access platforms (Citrix, VMware Horizon, RD Gateway/NPS)
  • Web applications via SAML/OIDC federation or Duo Web SDK
  • Cloud platforms (AWS, Azure, GCP) for console and CLI MFA
  • On-premises infrastructure (Windows RDP, SSH, local OS logon)
  • Custom and legacy applications via Duo Auth API and Web SDK
  • Plan and execute Duo-to-Duo migrations (e.g., tenant consolidation) and competitive migrations from Duo to Okta, Duo to Entra ID, or other MFA platforms
  • Develop automation scripts (Python, PowerShell, Bash) leveraging Duo Admin API for bulk operations, reporting, user lifecycle management, and integration testing
  • Design phased MFA rollout strategies with user communication plans, pilot groups, and exception handling workflows
  • Conduct security reviews of Duo configurations, identifying gaps in policy coverage, authentication bypass risks, and device trust enforcement
  • Develop and maintain technical documentation, architecture diagrams, integration runbooks, and client-facing knowledge transfer materials

Okta & Ping Identity – Supporting Engineer (Secondary – 35%)

  • Serve as a supporting engineer on Okta and Ping Identity engagements when Duo workload permits, working under the direction of the engagement's lead architect
  • Contribute hands-on technical work on Okta engagements, including:
  • Application integration (SAML, OIDC, SWA) and SSO configuration
  • MFA policy configuration and adaptive access policies
  • Lifecycle Management (LCM) — provisioning, deprovisioning, and group-based automation
  • Directory integrations (Active Directory, LDAP, HR systems via SCIM)
  • Okta Workflows — supporting flow development for custom integrations and automations
  • User migration and bulk import operations
  • Contribute hands-on technical work on Ping Identity engagements, including:
  • PingFederate — SP/IdP connection configuration, adapter setup, and federation troubleshooting
  • PingOne — SSO, MFA, and directory service configuration
  • PingAccess — Resource and policy configuration for web application protection
  • On-premises Ping product support — Assisting with deployments, upgrades, and patching under architect direction
  • Execute assigned integration tasks, configuration changes, and testing activities with quality and consistency
  • Participate in peer reviews, knowledge-sharing sessions, and cross-training to deepen Okta and Ping Identity skills over time

Project Ownership & Client Success (10%)

  • Serve as the technical project owner on Duo engagements, taking full accountability for successful delivery and client outcomes
  • On Okta/Ping engagements, support the lead architect with clear status updates, task completion, and proactive communication of blockers
  • Delegate routine Duo tasks to junior engineers when available, providing clear direction and technical guidance
  • Mentor junior resources through hands-on pairing, configuration reviews, and knowledge-sharing sessions
  • Develop and maintain technical documentation, architecture diagrams, implementation guides, and runbooks for all engagements
  • Contribute to the development of standard operating procedures (SOPs), delivery templates, and Duo-specific best practice frameworks

Presales Support & Business Development (5%)

  • Provide Duo-focused technical expertise during the presales process to support new business opportunities
  • Assist with technical discovery, scoping, and requirements gathering for prospective Duo and MFA engagements
  • Develop Level of Effort (LOE) estimates for proposed Duo implementations and migrations
  • Contribute to Statement of Work (SOW) development, ensuring technical accuracy and feasibility
  • Support proposal development with solution architectures, integration approaches, and implementation roadmaps
  • Participate in client-facing presentations and technical demonstrations during the sales cycle

Required Experience and Education:

  • Bachelor’s degree in computer science, Information Security, or related field — or equivalent work experience
  • 5+ years of experience in Identity and Access Management, with a strong emphasis on MFA and access security
  • Deep, hands-on experience with Cisco Duo Security, including:
  • Duo MFA policy design, deployment, and administration
  • Duo Authentication Proxy deployment and configuration (RADIUS, LDAP, AD)
  • Duo SSO configuration (SAML 2.0, OIDC)
  • Duo integrations across VPN, remote access, web applications, and infrastructure
  • Duo Admin API and Auth API for automation and custom integrations
  • Duo Device Trust and Trusted Endpoints configuration
  • Working proficiency with at least one of the following:
  • Okta — Application integration, SSO, MFA, Lifecycle Management, directory integrations
  • Ping Identity — PingFederate, PingOne, PingAccess configuration and administration
  • Strong understanding of SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), and RADIUS protocols
  • Proficiency with Python, PowerShell, or Bash for automation and API integrations
  • Experience integrating MFA solutions with VPN, Citrix, RD Gateway/NPS, and cloud platforms
  • Familiarity with Active Directory, LDAP, and enterprise directory services
  • Experience with endpoint management platforms (Intune, Jamf, Workspace ONE) in the context of device trust
  • Strong understanding of Zero Trust principles, least-privilege access, and identity security best practices
  • Demonstrated ability to own technical delivery, manage client expectations, and work independently with minimal oversight
  • Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes.

Preferred Experience and Education

  • Experience with Duo-to-Okta or Duo-to-Entra ID migration projects
  • Hands-on experience with both Okta and Ping Identity platforms (not just one)
  • Familiarity with Okta Workflows for custom automation and integration development
  • Experience with PingFederate federation hub architecture and multi-protocol bridging
  • Experience with DaVinci orchestration (Ping Identity)
  • Familiarity with Microsoft Entra ID / Azure AD, including Conditional Access and MFA
  • Infrastructure-as-code experience (Terraform, Ansible) for identity platform deployments
  • Professional certifications such as:
  • Cisco Duo certifications
  • Okta Certified Professional / Administrator / Consultant
  • Ping Identity Certified Professional
  • CISSP, CISM, or equivalent security certifications

Physical Requirements:

  • Sedentary work
  • Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
  • Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day

We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.

Why GuidePoint?

GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,300 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.

Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.

This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.

Some added perks….

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option
本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位