freehire launches on Product Hunt on 26 August.

Follow →

Contractor: Senior IBM Security Verify Access (ISVA/ISAM) Engineer

Summary

Designs, deploys, and troubleshoots enterprise-scale IBM Security Verify Access (ISVA) and Identity & Access Management (IAM) environments, focusing on authentication, authorization, SSO, and federation. Core technologies include SAML 2.0, OAuth 2.0, OpenID Connect, JWT, LDAP, and PKI.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Contractor: Senior IBM Security Verify Access (ISVA/ISAM) Engineer based in India.

This is a senior, hands-on IAM engineering opportunity focused on enterprise-scale IBM Security Verify Access and Identity & Access Management environments.
You will design, deploy, migrate, upgrade, troubleshoot, and operate highly available ISVA/ISAM platforms supporting critical authentication and authorization services.
The role combines deep expertise in WebSEAL, federation, SSO, access policies, mapping rules, and directory services with strong production troubleshooting skills.
You will work extensively with SAML 2.0, OAuth 2.0, OpenID Connect, JWT, LDAP, certificates, PKI, and enterprise integrations.
The position also offers exposure to modernization initiatives involving cloud identity providers and IBM Verify SaaS.
Success requires strong technical ownership, analytical thinking, documentation, and the ability to collaborate across application, infrastructure, networking, security, and vendor teams.
This is a fully remote, full-time contract role for candidates based in India and working India Standard Time (IST) hours.

Accountabilities:

  • Design, install, configure, administer, migrate, upgrade, patch, and maintain enterprise ISVA/ISAM environments and virtual appliances.
  • Configure and support WebSEAL, Policy Server, Runtime Components, Federation Services, Advanced Access Control, authorization policies, reverse proxies, and related IAM components.
  • Architect and operate clustered, highly available, and disaster-recovery-ready environments, including backups, snapshots, restores, rollback plans, runbooks, and production cutovers.
  • Troubleshoot complex authentication, authorization, SSO, federation, certificate, appliance, reverse-proxy, and access-policy issues in production environments.
  • Design and implement enterprise SSO integrations using SAML 2.0, OAuth 2.0, OIDC, and JWT, including IdP/SP configurations, metadata, certificates, endpoints, bindings, signatures, and encryption.
  • Analyze and resolve issues involving SAML assertions, OAuth/OIDC tokens, authorization codes, refresh tokens, PKCE, claims, scopes, redirect URIs, ACS URLs, and token validation.
  • Develop, enhance, and troubleshoot ISVA/ISAM mapping rules using JavaScript for attribute transformation, claims processing, token customization, session handling, and custom authentication logic.
  • Integrate mapping rules with LDAP attributes, HTTP headers, REST APIs, and external decision points while debugging runtime behavior across federation protocols.
  • Administer and troubleshoot IBM Security Directory Server, including schema management, indexing, replication, backup, restore, performance tuning, HA, and SSL/TLS configuration.
  • Support directory migrations and integrations with IAM platforms while resolving LDAP bind, search, replication, schema, and performance issues.
  • Manage certificates, PKI, TLS, Linux/Unix environments, load balancers, DNS, networking, logging, monitoring, and production incident response.
  • Use shell scripting, Python, JavaScript, REST APIs, and log-analysis techniques to automate support activities and improve operational efficiency.
  • Lead technical discussions with application, infrastructure, networking, security, and vendor teams and contribute to IAM migration, modernization, consolidation, and upgrade initiatives.
  • Produce and maintain architecture diagrams, technical design documents, SOPs, implementation plans, rollback procedures, runbooks, and knowledge-transfer materials.
  • Requirements

    • 10+ years of experience in Identity and Access Management, with extensive hands-on experience administering IBM Security Verify Access (ISVA) and/or IBM Security Access Manager (ISAM).
    • Strong expertise with ISVA/ISAM installation, configuration, migration, upgrades, WebSEAL, Policy Server, Advanced Access Control, Federation Services, reverse proxies, and appliance operations.
    • Deep knowledge of SAML 2.0, OAuth 2.0, OpenID Connect, JWT, federation metadata, certificates, trust configuration, token claims, and authentication flows.
    • Hands-on experience developing and modifying ISVA/ISAM mapping rules using JavaScript, including SAML, OAuth, OIDC, attribute transformation, and custom authentication logic.
    • Strong experience with IBM Security Directory Server, LDAP schema, replication, indexing, performance tuning, SSL/TLS, and directory administration.
    • Solid understanding of PKI, TLS, Linux/Unix, load balancing, DNS, networking fundamentals, logging, monitoring, and production incident management.
    • Experience with shell scripting, Python, JavaScript, REST APIs, log analysis, and support automation.
    • Strong ability to trace and troubleshoot end-to-end request flows, authentication traces, policy decisions, junction behavior, HTTP headers, cookies, sessions, and access-control issues.
    • Demonstrated ability to diagnose complex federation problems such as metadata mismatches, assertion validation errors, signature or encryption failures, redirect URI issues, clock skew, and certificate trust failures.
    • Excellent analytical and problem-solving skills, particularly when handling high-severity production incidents.
    • Strong written and verbal communication skills, with the ability to clearly document root causes, technical decisions, implementation plans, and stakeholder updates.
    • Ability to collaborate effectively with distributed technical teams and lead discussions across application, infrastructure, networking, security, and vendor functions.
    • Preferred: Experience with IBM Verify SaaS, IBM Security Identity Manager, IBM Security Verify Governance, IBM Security Directory Integrator, Azure AD/Microsoft Entra ID, AWS Cognito, Kubernetes, or OpenShift.
    • Preferred: Experience leading IAM migration, modernization, consolidation, or platform upgrade programs.
    • Benefits

      • Fully remote working arrangement for candidates located in India.
      • Full-time contract engagement with hourly compensation.
      • Work aligned with India Standard Time (IST).
      • Opportunity to work on enterprise-scale IAM and security infrastructure.
      • Hands-on exposure to complex ISVA/ISAM, WebSEAL, federation, LDAP, and SSO environments.
      • Opportunity to contribute to IAM modernization, migration, and cloud identity initiatives.
      • Collaboration with application, infrastructure, networking, security, and vendor teams.
      • Opportunity to deepen expertise across SAML, OAuth 2.0, OIDC, JWT, PKI, LDAP, and enterprise identity architectures.
      • Technical ownership and exposure to mission-critical production environments.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available