IAM Engineer
Work type: On Campus
Location: Normal, Illinois
Division Name: Finance and Planning
Department: Office of Technology Solutions
Job Summary
The Identity and Access Management (IAM) Engineer operates as a key technical lead in the Office of Identity and Access Management (OIAM), focusing on secure design, development, implementation, and maintenance of the University’s IAM systems. This role is integral in ensuring IAM configurations and customizations meet established security standards and best practices. Responsibilities include securely integrating IAM solutions with other University information systems, supporting automation for identity provisioning and deprovisioning, and adhering to secure coding standards, and conducting secure code reviews. The IAM Engineer will also collaborate with the Information Security Office, providing expertise in security investigations, urgent terminations, audit controls, and adherence to IAM-specific compliance requirements.
The responsibilities of this role will occur within the University’s IAM system which includes a central account and digital identity management system, a central group and role automation and management system, multiple system directory solutions, and multiple authentication systems with integration to global federations to support the diverse and complex academic, research, and administrative needs of the institution.
Additional Information
Position Highlights:
- There is the potential for 100% remote work or a hybrid arrangement in this position, within the State of Illinois. Illinois residency is required. Eligibility is based upon employee performance, appropriate remote working environment, and business needs.
University Benefit Highlights:
- Insurance benefits, including health, dental, vision, and life
- Retirement and supplemental retirement planning options
- Tuition waiver benefits available to staff as well as their eligible dependents
- Paid holiday/administrative closures during Thanksgiving and Winter Breaks
- Paid benefit time
For more University Benefit information: https://hr.illinoisstate.edu/benefits/
Information regarding eligibility for participation in the State Universities Retirement System and the State of Illinois Group Insurance program can be reviewed here https://hr.illinoisstate.edu/benefits/insurance/
Salary Rate / Pay Rate
$75,000 - $85,000 annual
Required Qualifications
- Master’s degree in information systems, information security, information technology, or a closely related field
- Work experience which includes the following:
a. Five years working in information technology at an institution of higher education.
b. Two years completing system administration duties such as configuration, support, and maintenance of information technology systems.
c. One year performing the following:
- completing system administration duties configuring, supporting, and maintaining single sign on (SSO) and authentication services comprised of Shibboleth, Entra ID, Active Directory, and a LDAP directory.
- developing and deploying code within a Git-based version control system such as GitLab, GitHub, or similar.
- conducting independent research and application of critical reasoning skills to solve technical issues.
- working with diverse teams to assist in the design, implementation, and maintenance of business information systems.
- self-management of assigned projects and daily tasks in an environment with shifting priorities
d. Collecting technical requirements and designing appropriate process and/or software solutions. - The following knowledge, skills, and abilities:
a. Strong analytical skills to analyze security requirements and relate them to appropriate security controls.
b. Demonstrated ability to follow established procedures, even in a high-pressure situation.
c. Excellent communication skills, verbal and written, including the ability to convey technical information to a non-technical audience.
d. Familiarity with identity and access management standards and best practices established within the Payment Card Industry Data Security Standards (PCI DSS), the NIST 800-series special publications, and related federal and state laws and regulations, including privacy and identity protection, such as HIPAA, FERPA, CALEA, and GLBA.
e. Knowledge of cloud service providers and their security practices and technology standards supporting the secure integration of access management capabilities, such as user account provisioning, group and role membership management, and user authentication.
Preferred Qualifications
- At least two years of work experience:
a. with system administration of Linux server operating systems using the command-line interface for installs, updates, and upgrades of system packages.
b. with any of the following technologies: Microsoft PowerShell, Java code development, or ITSM products. - Work experience:
a. developing and implementing formalized IT policies, procedures, and standards control for the selection, implementation, or use of technology systems.
b. with containerized systems using Red Hat OpenShift.
c. Work experience developing, testing, and implementing configuration-as-code as well as code-based automation. - The following knowledge, skills, and abilities:
a. Intermediate to advanced knowledge of access provisioning for enterprise information systems and solutions.
b. Familiarity with access management protocols for user provisioning, authentication, and authorization such as PKI, OAuth, OpenID, SAML, SCIM, and JIT.
c. Familiarity with secure coding practices and principles and code review activities.
d. Ability to accurately define incidents, problems, and events in a trouble ticketing system.
e. Demonstrated proficiency in developing, updating, and maintaining standard operating procedures (SOPs).
f. Knowledge of effective disaster recovery planning, configuration, and use for enterprise systems including familiarity with architecture design to enable high-availability, failover, replication, and similar system functionality.
Work Hours
Core Hours: 8:00am-4:30pm Monday through Friday; occasional weekend and evening hours as business needs dictate
Functional Expectations
Must be able to complete the following with or without a reasonable accommodation:
- Remain at a workstation for extended periods.
- Distinguish colors on a monitor.
- Effectively communicate on a daily basis.
- Lift 45 lbs.
Proposed Starting Date
January 2025
Required Applicant Documents
Resume
Reference List
Please Note: These documents are required to be submitted online in order to complete the application process. Please have these documents ready prior to clicking on "Apply"
Optional Applicant Documents
Transcripts - See Special Instructions to Applicants for additional options
Certification of Retirement Annuity
Please Note: These documents may be submitted online in order to complete the application process. Please have these documents ready prior to clicking on "Apply"
Special Instructions for Applicants
Please fully complete the entire application including, but not limited to, the education and work history portions. Be specific on your work history, including employment dates (if part-time you must list the number of work hours) and duties for all positions held. Applicable part-time work experience will be considered toward qualifying for this position; however, it will be converted to a full-time equivalency to determine combined length of experience. Please do not put "see resume" in the duties and responsibilities section of the work history. This will be considered an incomplete application and incomplete applications will not be considered.
College or university transcripts (may be unofficial) must be submitted prior to the application deadline to receive full consideration. Transcripts can either be uploaded with your application or submitted via the options listed below.
To be eligible for Veteran's Preference points on the exam, appropriate military service documentation such as a DD-214 must be submitted prior to the application deadline.
Transcripts and/or military service documentation may be faxed or mailed to Human Resources by the application deadline:
Fax: 309.438.0011, Attn: Kira Shelton
Address: Illinois State University
Human Resources
Campus Box 1300
Normal, IL 61790-1300
The Civil Service examination for this classification is based on your application materials and responses to the supplemental questions. No participation other than submission of applicant materials is required from applicants that qualify to take the exam. If you meet the minimum required qualifications for this position, you will receive a score calculated based on your education and experience, and your name will be placed on the active employment register by exam score. After the application deadline, the names within the top three scores will be referred to the department for interview. The active register for this classification will be voided when the position is filled.
Illinois State University is authorized to do business within the State of Illinois. All work under this appointment is required to be performed from within the State of Illinois. If hired, out-of-state candidates must establish Illinois residency within 180 calendar days from the start date for this position. Illinois residency requires proof of a valid Illinois driver’s license or a valid State of Illinois ID card. Failure to produce the required documentation within 180 calendar days will result in immediate termination of employment.
Contact Information for Applicants
Kira Shelton
Human Resources
kgshelt@ilstu.edu
(309) 438-2120
Important Information for Applicants
This position is subject to a criminal background investigation and if applicable, an employment history review, based on University Policy 3.1.30 and any offer of employment is contingent upon you passing a satisfactory criminal background investigation and/or an employment history review. You may not begin work until the criminal background investigation results have been received and cleared by Human Resources.
Illinois State University is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
If you are an individual with a disability and need a reasonable accommodation under the Americans with Disabilities Act (ADA) or other state or federal law you may request an accommodation by contacting the Office of Equal Opportunity and Access at (309) 438-3383. The Office of Equal Opportunity and Access will hold any confidential information you provide in confidence.
If you are having difficulty accessing the system, please call Human Resources at (309) 438-8311.