About this Identity and Access Management Consultant role at Strata Information Group
Strata Information Group (SIG) is a trusted leader in higher‑education technology consulting, supporting colleges and universities with ERP/SIS modernization, digital transformation, CRM, cybersecurity, and strategic advisory services. As a long‑standing and deeply embedded partner within the higher‑education sector, SIG brings together technical depth, operational insight, and a culture rooted in integrity, collaboration, and exceptional client service. Our heritage is built on hands‑on expertise, genuine relationships, and a commitment to delivering value with humility and excellence—values that continue to define us as we scale.
Key Responsibilities:
- For each project, understand the client's business processes, security policies, and compliance requirements to be able to design IAM solutions that meet the client's objectives.
- Develop and implement IAM architecture that includes access control, authentication, identity management, and ensure solutions are scalable, secure, and meet the client's requirements.
- Maintain technical currency for the latest IAM tools and solutions, assess their suitability for the client's requirements, and recommend solutions that meet their needs.
- Conduct IAM assessments of the client's existing IAM infrastructure, identify risks and vulnerabilities, and recommend remediation strategies to address these issues.
- Work with clients to develop IAM policies and procedures that comply with regulatory requirements and align with their business objectives.
- Provide technical guidance and support to clients throughout the IAM solution lifecycle, including requirements gathering, design, implementation, and post-implementation support.
Minimum Qualifications:
- Previous experience working in or with higher education institutions is preferred.
- 5+ years of experience in Identity and Access Management consulting.
- Bachelor's degree in Computer Science, Computer Engineering, or a related field (related industry experience will be considered in place of a degree).
- Experience developing and implementing IAM architectures, including access control, authentication, and identity management.
- Knowledge of IAM technologies and solutions, including Active Directory, LDAP, SSO, and multi-factor authentication, including their strengths and weaknesses.
- Strong analytical and problem-solving skills.
- Excellent written and verbal communication skills.
- Ability to work independently and as part of a team, managing multiple clients and projects at one time.
- SAML and CAS expertise to configure services, manage and troubleshoot IdP (user store, claim configuration), and manage certificates.
- Knowledge and experience working with IdP solutions such as Ellucian Ethos Identity, WSO2 Identity Server, Shibboleth Identity Provider, Apereo CAS, QuickLaunch, PortalGuard, Entra ID, ADFS, and Okta.
- Experience with the LDAP protocol and working with a directory server (such as Active Directory, OpenDJ/Open LDAP, etc) to configure, deploy, and manage the environment.
Preferred Qualifications:
- Experience with Ellucian Products & Single-Sign-On Configuration.
- Experience with Ellucian User Provisioning (EUP).
- Significant experience working with IAM tools including InCommon Trusted Access Platform, Shibboleth, Grouper, Midpoint, Comanage, Microsoft Identity Manager, and Entra ID.
- Technical skills working with Java and Java Server Pages.
- Knowledge and experience working a variety of multi-factor authentication (MFA) products to design, test and deploy solutions depending upon clients requirements.
- Knowledge of the SPML framework will be helpful in this position.
- Experience working with RESTFUL APIs will be helpful.
- CIAM, CISSP or CISM certifications are important.
Compensation & Benefits:
Starting salary range for this position is $110,000 - $130,000 depending on individual skills and experience.
- Remote (with possible travel for onsite client engagements)
- Flexible hours
- Annual bonus
- Medical, vision and dental
- Flexible spending/Health savings account
- PTO, Sick and holiday pay
- Life insurance
- Retirement 401(k) 5% employer contributions
- Professional Development opportunities
- Monthly Connectivity stipend
The listed salary range for this position is indicative and subject to adjustment based on the candidate's unique skills and location. Final compensation will be determined through mutual agreement between the successful candidate and SIG.
SIG is an Equal Employment Opportunity employer
California Consumer Privacy Act Notice