Contractor: Senior IBM Security Verify Access (ISVA/ISAM) Engineer

Remote
Contracted
Experienced

LOCATION REQUIREMENT: This role is remote but candidates MUST be based in India, working India Standard Time (IST) hours. Applications from outside India will not be considered.

Employment type: Contract, full-time, paid hourly

Position Summary

We are seeking a seasoned IBM Security Verify Access / IBM Security Access Manager specialist with 10+ years of IAM experience. The candidate should be hands-on in deploying, migrating, upgrading, troubleshooting, and operating enterprise-scale ISVA/ISAM environments, including IBM Security Directory Server and modern federation standards such as SAML 2.0, OAuth 2.0, and OpenID Connect. The client's environment also includes IBM Verify (SaaS); familiarity here is a strong plus but not required.

Key Responsibilities

IBM Security Verify Access / ISAM Administration

  • Design, install, configure, and administer ISVA/ISAM environments
  • Perform setup, migration, upgrade, patching, and lifecycle management of ISAM/ISVA/ISVIA virtual appliances
  • Configure and support WebSEAL, Policy Server, Runtime Components, Federation Services, Advanced Access Control, authorization policies, and reverse proxy components
  • Design and operate clustered, highly available, disaster recovery-ready ISVA environments
  • Manage snapshots, backups, restores, runbooks, rollback plans, and production cutover activities
  • Troubleshoot complex authentication, authorization, SSO, federation, appliance, certificate, and access policy issues

Federation, SSO, and Protocol Expertise

  • Design and implement enterprise SSO using SAML 2.0, OAuth 2.0, OIDC, JWT
  • Configure IdP/SP integrations, federation partners, metadata, certificates, endpoints, bindings, signatures, encryption settings
  • Develop and troubleshoot claims, assertions, scopes, token attributes, subject identifiers, relay state, ACS URLs, redirect URIs
  • Analyze SAML assertions, OAuth/OIDC tokens, authorization code flows, refresh token behavior, PKCE, token validation issues
  • Onboard SaaS and on-prem applications to enterprise SSO platforms; support large-scale federation migration programs

Mapping Rules and Custom Authentication Logic

  • Develop, enhance, and troubleshoot ISVA mapping rules using JavaScript
  • Implement attribute mapping, claims transformation, token customization, session handling, policy-driven access flows
  • Integrate mapping rules with LDAP attributes, HTTP headers, REST APIs, external decision points
  • Debug rule execution, exceptions, runtime behavior across SAML, OAuth, and OIDC integrations

IBM Security Directory Server / LDAP

  • Install, configure, administer, troubleshoot IBM Security Directory Server
  • Support schema management, indexing, replication, backup, restore, tuning, HA configuration
  • Troubleshoot LDAP bind, search, replication, SSL/TLS, schema, performance issues
  • Support directory migration and integration with IAM platforms

Required Qualifications

  • 10+ years of IAM experience with strong hands-on ISVA/ISAM administration
  • ISVA/ISAM: installation, configuration, migration, upgrade, WebSEAL, Policy Server, AAC, Federation, reverse proxy, appliance operations
  • Strong expertise in SAML 2.0, OAuth 2.0, OIDC, JWT, metadata, certificates, token claims, trust configuration
  • Hands-on JavaScript mapping rule development for SAML, OAuth, OIDC, attribute transformation, custom authentication logic
  • IBM Security Directory Server, LDAP schema, replication, indexing, tuning, SSL/TLS
  • Certificates, PKI, TLS, Linux/Unix, load balancers, DNS, networking basics, logging, monitoring, production incident handling
  • Shell scripting, Python, JavaScript, REST APIs, log analysis, support automation

Preferred Qualifications

  • IBM Verify (SaaS) experience — a strong plus given the client's environment, but not required
  • IBM Security Identity Manager / IBM Security Verify Governance familiarity
  • IBM Security Directory Integrator experience
  • Azure AD / Microsoft Entra ID, AWS Cognito, or other cloud IdP integration experience
  • Kubernetes or OpenShift experience
  • Experience leading IAM migration, modernization, consolidation, or platform upgrade initiatives
  • Experience creating architecture diagrams, technical design documents, SOPs, runbooks

Key Competencies

  • Strong analytical and troubleshooting mindset for high-severity production issues
  • Ability to lead technical discussions with application, infrastructure, network, security, and vendor teams
  • Strong documentation skills for runbooks, architecture notes, implementation plans, rollback plans, knowledge transfer material
  • Clear communication for status updates, issue summaries, root cause analysis, stakeholder reporting
  • End-to-end troubleshooting across ISVA/ISAM, WebSEAL, AAC, federation, mapping rules, IBM Security Directory Server, LDAP, certificates, DNS, load balancers
  • Ability to analyze request flows, authentication traces, policy decisions, junction behavior, HTTP headers, cookies, session issues
  • Hands-on debugging of SAML/OAuth/OIDC issues: metadata mismatch, assertion validation, signature/encryption failures, redirect URI problems, clock skew, certificate trust failures
Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

Human Check*