GPS - IAM Engineer
Listed on 2026-01-24
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing, IT Support
Overview
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
From strategy to execution, the Government & Public Sector (GPS) practice of Ernst & Young LLP provides a full range of consulting and audit services to help our Federal, State, Local and Education clients implement new ideas to help achieve their mission outcomes. We deliver real change and measurable results through our diverse, high-performing teams, quality work at the highest professional standards, operational know-how from across our global organization, and creative and bold ideas that drive innovation.
We enable our government clients to achieve their mission of protecting the nation and serving the people; increasing public safety; improving healthcare for our military, veterans and citizens; delivering essential public services; and helping those in need. EY is ready to help our government build a better working world.
Our GPS Technology Organization is a structure within the US GPS practice that implements and maintains a new operate and technology model designed specifically to support U.S. defense and Government engagements.
The opportunity
You’ll have responsibilities within the Identity and Access Management (IAM) team that supports various applications in cloud platform services across the Government and Public Sector (GPS) business unit. You’ll support the end-to-end aspects of services including but not limited to service engineering, break/fix support, service roadmaps and standards, vendor management. You’ll also have responsibilities to include ensuring stability for application platforms and/or services under their responsibility including resolution of incidents and problems, maintenance and support, application platform change control, and automation of processes and procedures.
Working closely with other teams within EY, you’ll drive technology standards and consistency across IT Services.
Your key responsibilities
Maintaining ongoing knowledge and support of Azure infrastructure and aligned applications such as:
Azure Cloud hosted services, Bastion, Keyvault, Recovery Services Vault, Storage accounts
Azure Role Based Access Control (RBAC)
Power Automate, App Service Plan, Function Apps, Application Insights
Azure networking;
Vnets, network security groups (NSG), private and public endpoints, Azure Private DNSMicrosoft Entra Domain Services (MEDS)
Access reviews, reporting and Audit compliance
Deploying MEDS on Azure VM’s and install replica Domain Controllers or Forests in an Azure virtual network
Maintain ongoing knowledge and support of servers and networks aligned to the Active Directory environments including but not limited to:
Single Sign-On (SSO) configuration and remediation
Native Microsoft tools including but not limited to ADSI, ADUC, DNS, Domains and Trusts,
DISA STIG remediation with Group Policy Objects (GPO)
Public Key Infrastructure (PKI)
Creating and configuring Microsoft Entra Domain Services (IAAS & PAAS) for authenticating applications in Azure Cloud
Entra services management including application proxy, Licensing, Azure PIM
Application Registrations; OAuth/OpenID, API Permissions, Client /Secrets, JWT Tokens/Claims, JSON, App Roles
API Gateways, Enterprise Databases, SSO and Access Management systems, identity federation protocols (SAML), OIDC, OAuth2 and LDAP/LDAPS
Enterprise Applications; SAML, SCIM Provisioning
Managing data stored in Entra Graph and Powershell.
Multi Factor Authentication (MFA) such as Entra integration into the authentication, authorization, and single sign-on process for applications and systems
Account, Group, and entitlement management with SailPoint…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).