IAM Engineer - Silverfort
Summary
Administers Silverfort’s identity and access management platform, integrating AD/Entra ID/Okta, enforcing MFA on RDP/SSH/SMB, and tuning AI-driven risk policies to secure hybrid environments.
As a Silverfort Administrator, responsible
for demonstrating the capabilities of Silverfort features & products.
Integrating the on-prem AD & secure the privileged access user accounts.
Implementation of security policies to strengthen server access for diverged
user base. Monitoring & troubleshooting the infrastructure and handling the
authentication requests to improve security and reduce the blast radius.
1 Roles &
Responsibilities:
1. Deploy the Silverfort infrastructure with Admin
& nodes in load balancing and failover architecture.
2. Configure and maintain direct connections with
Identity Providers (IdPs), including Microsoft Active Directory, Entra ID, &
Okta.
3. Enforce Multi-Factor Authentication (MFA) across non-standard
interfaces such as Remote Desktop Protocol (RDP), Command-Line interfaces
(PowerShell, SSH), and SMB file shares.
4. Integrate 3rd part MFA solutions like MS authenticator,
Okta, Google Authenticator & Duo with Silverfort environment to extend the
Silverfort capabilities with existing MFA solutions.
5. Oversee traffic interception parameters, ensure optimal
performance of Silverfort nodes, and troubleshoot authentications.
6. Create, tune, and optimize risk-based access policies utilizing
Silverfort’s AI-driven threat engine.
7. Discover, map, and secure machine-to-machine communications by
creating behavioral baselines and automated protection policies.
8. Audit and adjust user Role-Based Access Control (RBAC) to
eliminate unnecessary excessive privileges across both cloud and hybrid setups.
9. Set up and configure triggers to detect modern lateral movement
attacks, brute-force strategies, and credential-dumping attempts.
10. Evaluate Silverfort traffic logs to trace anomalies and generate
operational risk metrics.
11. Ingesting Silverfort logs to SIEM solutions like Splunk, LogRhythm
& Sentinel.
12. Document Silverfort platform deployments, runbooks, and
exception-handling frameworks to maintain clean IT operational continuity.
13. Manage the daily operation, health monitoring, and system upgrades
of the Silverfort admin console, nodes, and dependent services.
Requirements
1.1. Must
have skills:
1. Understanding basic authentication
flow mechanics and troubleshooting common clock-skew time sync errors.
2. Creating and updating A, AAAA, CNAME,
PTR, and SRV locator records manually.
3. Monitoring policy replication health
across DCs using Distributed File System Replication (DFSR) commands.
4. Configuring Domain Name System (DNS)
zones, Dynamic Host Configuration Protocol (DHCP) scopes, and IP Address
Management (IPAM) structures.
5. Creating, managing, and rotating
passwords for standard and Managed Service Accounts (MSAs).
6. Implementing different password
complexity rules for specific high-risk user groups via password policies.
7. Configuring standard security and
sharing tabs using inheritance and AGDLP (Account, Global, Universal, Domain
Local, Permissions) best practices.
8. Knowing the five Flexible Single
Master Operation roles and their placements across domain controllers.
9. Enabling
security audit logs on OUs to trace which admin modified or moved a specific
object.
10. Applying Group Policy Objects
conditionally based on hardware traits like operating system version or laptop
vs. desktop.
11. Mapping network printers, deploying
registry changes, and configuring local shortcut files natively
12. Understanding about networking
concepts LAN, MAN & WAN.
13. Knowledge of IP addressing and
subnetting.
1.2. Good
to have skills:
1. Strong analytical mindset with an ability to troubleshoot basic
issues.
2. High willingness to learn, adapt, and grasp new technologies
quickly.
3. Excellent verbal and written communication skills in English.
4. Understanding of networking & diagnosing system / vm related
issues.
5. Understanding of cloud network architecture & administration
techniques.
6. Exposure on AWS, Azure & GCP cloud platforms.
1.3. Education:
1. Bachelors in engineering in
departments such as IT/EEE are preferred.