Digital Identity & Authentication SME (Microsoft Entra, Okta, Ping, Saviynt)
In today’s rapidly evolving IT landscape, organizations face increasingly complex cybersecurity risks and regulatory pressures. Identity—both human and non-human—is at the core of every enterprise. As a Digital Identity & Authentication SME, you will help clients enhance user experience, reduce risk, and increase operational efficiency by designing and implementing robust identity solutions using Microsoft Entra, Okta, Ping, Saviynt, and related technologies.
Key Responsibilities
- Strategy & Assessment
- Conduct current state and application access assessments
- Perform capability maturity and benchmarking assessments
- Analyze IAM data and provide actionable insights
- Develop IAM strategy and roadmaps, including operating models, governance, policies, procedures, and standards
- Solution Design & Implementation
- Architect and implement identity and authentication solutions using Microsoft Entra, Okta, Ping, Saviynt
- Design cloud security and IAM architectures for Azure, AWS, GCP, and hybrid environments
- Implement cloud IAM services (e.g., provisioning, authentication, authorization, identity management)
- Design and re-engineer processes for centralized cloud access provisioning
- Access Management & Governance
- Implement access management standards (SAML 2.0, OpenID Connect, OAuth, SCIM)
- Support privileged access management, roles and rules management, and segregation of duties (SOD)
- Assist with IAM program management and compliance activities
- Client Engagement
- Align security management strategies with business goals
- Communicate security trends, risks, and solutions to clients and internal teams
- Deliver quality client services and presentations
Skills & Attributes for Success
- Deep knowledge of identity and access management (IAM) technologies and industry trends
- Experience with user provisioning, role-based access control, directory services, and web access control solutions
- Understanding of access control concepts (directory services, SAML, LDAP, PKI)
- Strong process definition, workflow design, and process mapping skills
- Excellent presentation and communication abilities
- Intellectual curiosity and a passion for cybersecurity
Qualifications
- Bachelor’s degree in a related field (or equivalent experience)
- 6-8 years of relevant work experience (or 3-5 years with a graduate degree)
- Hands-on experience with Microsoft Entra, Okta, Ping, Saviynt, and similar IAM solutions
- Relevant certifications (CISSP, CISM, CISA, CIPT, CIPM, CRISC) preferred
- Valid driver’s license and passport; willingness to travel as needed
What we offer you
At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn .
- We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $144,900 to $265,800. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $173,900 to $302,100. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
- Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
- Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.