Senior IAM Engineer, LDAP & SSO
CVS HealthAbout the role
At CVS Health, we’re building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care.
As the nation’s leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues – caring for people where, when and how they choose in a way that is uniquely more connected, more convenient and more compassionate. And we do it all with heart, each and every day.
Position Summary
As a Senior LDAP & SSO engineer, you will be supporting various LDAP systems- Radiant Logic, Ping Directory, IBM Tivoli Directory Server and Ping SSO systems - PingFederate, PingRIsk, PingOne, Ping Access, PingDavinci.
Key Responsibilities:
- Work with other engineers and be responsible for the overall direction of the current and future state of LDAP/Authentication systems, access solutions, and LDAP directory server infrastructure.
- Install, administer, and maintain LDAP Directory Services - RadiantOne FID - VDS and ICS servers, Ping Directory, ODSEE Directory and Proxy servers, IBM Tivoli directory server.
- Be part of 24x7 on-call weekly rotation schedule for LDAP directory services support. Rotates once every 3-4 weeks.
- Migrate LDAP client applications from ODSEE to RadiantOne FID and Ping Directory. Configure the required service accounts, ACIs, troubleshoot the migration/integration with the application teams.
- Understanding of Client - Server communication concepts, SSL Cryptography, Load Balancers
- Perform periodic LDAP log analysis for proactive incident prevention and improved systems performance.
- Work closely with User provisioning team for LDAP directory data management.
- Correlate user identities from different LDAP directories and merge them into a single directory and migrate the client applications over to a single directory.
- Work with server infrastructure and network teams to build and troubleshoot Virtual machines, Load balancers for LDAP servers.
- Work in a team environment and communicate well to all levels of management.
- Proficient understanding of HTTP networking, including request and response headers, and network communication protocols and transaction workflows.
- Should have extensive experience in troubleshooting SAML/OIDC/webagent/proxy related authentication issues.
- Install, administer, and maintain Siteminder (policy server/agents/SPS)/ Ping access, Ping policy servers.
- Be part of 24x7 on-call weekly rotation schedule for SSO. Rotates once every 3-4 weeks.
- Understanding of Client - Server communication concepts, SSL Cryptography, Load Balancers
- Should have extensive experience with Linux and windows platforms.
- Perform periodic Siteminder/Ping log analysis for proactive incident prevention and improved systems performance.
Required Qualifications
- 7+ years’ experience with Identity Access Management
- 5+ years’ experience with PingFederate, Radiant Logic, and/or other LDAP technologies
- 3+ years’ experience with Shell, Perl, Bash, or Python scripting.
- 3+ years’ experience with JAVA, JNDI API, .Net and other programming languages to help troubleshoot LDAP client application connection issues.
Preferred Qualifications
- Experience with logging tools like Splunk
- Experience with monitoring tools like AppDynamics.
Education
- Bachelor’s degree or equivalent experience (High School Diploma and 4 years relevant experience)
Anticipated Weekly Hours
40Time Type
Full timePay Range
The typical pay range for this role is:
$101,970.00 - $203,940.00This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.
Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
Great benefits for great people
We take pride in our comprehensive and competitive mix
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s