Overview
Phone / Skype Hire. Onsite from day 1 / Hybrid
Location : Brooklyn, NY
Duration : 12–24+ months (High Possibility of Further Extensions)
Responsibilities
Assess and develop a roadmap for OTI's disparate directories consolidation
Provide guidance and implementation support for integration with Entra and other IAM security enhancements
Architect and implement Citywide-level PKI modernization, including infrastructure changes for reduced certificate lifespans
Advice on governance, compliance, lifecycle management and automation of digital certificates
Lead migration planning, risk assessment, and mitigation for directories and PKI modernization
Perform technical knowledge transfer, upskilling internal teams on new infrastructure and practices
Tasks
- PKI Architecture, Engineering and Administrator 40%
- Entra ID Architecture, Engineering and Administrator 30%
- Directory Architecture, Engineering and Administrator 20%
- IAM Level 3 Technical Support 10%
Qualifications
12 years in IAM architect, engineering, administration, and operations with focus on directory services and PKIDeep expertise in Active Directory (on-prem and hybrid), Entra ID, and eDirectoryHands-on experience in designing and operating Microsoft PKI, including certificate authority management, certificate lifecycle, and automationSolid understanding of modern authentication / authorization protocols (OAuth, SAML, Kerberos, etc.)Experience with security roadmap development, risk assessment, and compliance (NIST, ISO, SOX or PCI-DSS)Strong documentation, communication, and stakeholder management skillsExperience with cloud PKI servicesFamiliarity with Entra ID Governance, Conditional Access Policy, and modern security controlsExperience automating PKI workflows (API / script-based certificate management)Multi-forest, multi-tenant IAM architecture expertisePrior experience working with NYC agencyWorking knowledge of enterprise ITSM, change management, and project management methodologiesAbility to work cross-functionality with technical and business stakeholders in a complex enterpriseAvailability to provide after-hours support to critical migrations and incident responseJ-18808-Ljbffr