- Company Name
- Tilencia
- Job Title
- Consultant(e) IAM / SSO – RUN Plateformes d’Authentification (Banque) – Paris (H/F)
- Job Description
-
**Job Title**
IAM/SSO Operations Consultant – Authentication Platforms (Banking)
**Role Summary**
Provide day‑to‑day operations and maintenance of critical SSO and authentication platforms in a highly regulated banking environment. Ensure continuous availability, performance, and compliance of identity‑related services while diagnosing and resolving incident escalations, performing root‑cause analysis, and implementing preventive actions.
**Expectations**
- 3 – 5 + years of experience running production IAM/SSO platforms.
- Proven expertise in identity federation (SAML 2.0 priority) and OAuth2/OIDC.
- Strong knowledge of banking/finance compliance, audits, and availability requirements.
- Professional English language proficiency.
**Key Responsibilities**
- Operate and monitor SSO/Authentication platforms (MCO/MCS); supervise availability, performance, logs, and alerts.
- Resolve N2/N3 incidents: diagnose, troubleshoot, communicate, and, if needed, escalates.
- Conduct root‑cause analyses and drive preventive actions.
- Participate in on‑call rotations and extended coverage as required.
- Administer identity federations, configure SSO protocols (SAML2, OIDC, OAuth2, WS‑Fed).
- Integrate new applications (web, API, mobile): connectors, policies, attribute mappings, scopes.
- Manage patching, version upgrades, hardening (TLS, reverse‑proxy, MFA, credential & secret management).
- Enforce security policies, perform periodic security controls (N1), handle exemption requests.
- Assist with internal and external audits and remediation plans.
- Produce and update operational standards, guides, and procedures.
- Automate recurring operations using scripts, Ansible, CI/CD pipelines.
- Continuously improve performance, resilience, security, and cost effectiveness.
**Required Skills**
- Identity‑and‑Access‑Management (IAM) infrastructure: SAML 2.0, OpenID Connect, OAuth2, WS‑Fed.
- Directory services: LDAP, Active Directory, Azure AD.
- MFA, certificate management, secrets vaults.
- Server environments: Linux, Windows, HTTP(S), reverse‑proxy, TLS, DNS, firewall, load balancing.
- Experience with IAM solutions such as Ilex Sign&Go, Ping, ForgeRock, Keycloak, WSO2, IBM IAM, Azure AD.
- Incident management following ITIL processes (incident, problem, change).
- Log and trace analysis (HTTP traces, tokens, certificates).
- Scripting and automation: Bash, PowerShell, Python, Ansible, CI/CD.
- Strong analytical, troubleshooting, and communication skills.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Technology, or related field, or equivalent professional experience.
- No mandatory certifications specified; industry security or IAM certifications (e.g., CISSP, CISM, AWS Security) considered advantageous.