Summary
Cornell University is seeking an Identity Management Developer to support cybersecurity-focused Identity & Access Management services within the university IT Security Office. The role provides engineering leadership for enterprise authentication, authorization, and directory services, while collaborating with campus partners, vendors, and internal teams to improve security, reliability, scalability, and usability.
Responsibilities
- Reporting to the Assistant Director for Identity & Access Management, the Identity Management Developer (CEMI) provides cybersecurity‑focused technical leadership and engineering expertise in support of Cornell University’s Identity & Access Management services within the university IT Security Office (ITSO)
- This position plays a key role in ensuring the secure, reliable, and effective delivery of enterprise authentication, authorization, and directory services that underpin the university’s academic, research, and administrative operations
- The Identity Management environment at Cornell consists of a diverse ecosystem of homegrown, open‑source, and vendor‑provided applications and services
- The Identity Manager Developer operates primarily in an engineering‑focused capacity, contributing deep technical expertise to the design, planning, implementation, and ongoing improvement of identity services
- This role is instrumental in maintaining a strong security posture while enabling scalability, resiliency, and ease of use for a broad and varied campus community
- In addition to technical leadership, this position serves as a key liaison between ITSO, campus business units, and external partners
- The Identity Management Developer supports strong service relationships by helping stakeholders understand identity service capabilities, status, and access processes, and by translating complex technical concepts into clear, non‑technical guidance when needed
- The role also contributes to the evolution of next‑generation Identity Management solutions by collaborating with vendors, peer institutions, and internal partners to stay current with emerging technologies and best practices in higher education cybersecurity
- The Identity Management Developer is expected to work collaboratively within the Identity Management team and across ITSO to meet service levels, support operational objectives, and respond effectively to system outages or changes, including availability outside of standard university business hours when required
- While the position is remote, periodic travel to Cornell University's Ithaca, New York campus will be required for meetings, team collaboration, training, and other departmental or university business needs
Skills
- Required Qualifications:
* Bachelor's degree with a minimum of **three to five years** of relevant experience, or an equivalent combination of education and experience.
* Demonstrated success providing technical support and application or middleware development in a distributed, team‑focused computing environment.
* Demonstrated expertise with one or more scripting or programming languages, such as **Java, Perl, Python, and/or VB (.NET), ReactJS, Ruby, and/or PHP**
* Approximately **1 year+** of professional experience developing **ReactJS applications and/or Ruby on Rails.**
* **System administration experience with** **Linux required; and Windows experience preferred.**
* Working to advanced knowledge of one or more identity and access management technologies, including **directory services, virtual directories, SAML2, OAuth2, LDAP, and Active Directory authorization technologies.**
* Proven experience writing technical design documentation, conducting code reviews, and working with version control systems such as **Git**.
* Ability to translate user and business needs into clear functional requirements and technical specifications, and to promote effective and efficient information sharing.
* Demonstrated ability to communicate complex Identity Management concepts—including system functions, capabilities, and processes—into business terms that are clear, accessible, and meaningful to non‑technical stakeholders.
* Proven ability to work effectively in a dynamic, deadline‑driven, and complex environment with multiple competing priorities.
* Strong facilitation, problem‑solving, analytical, reasoning, and judgment skills, with the ability to evaluate options and recommend sound technical solutions.
* Experience supporting and managing mission‑critical systems in a production environment, including troubleshooting and incident response.
* Proven ability to identify, scope, and implement opportunities for automation or architectural improvements that enhance system reliability, security, or efficiency.
* Ability to cultivate and develop inclusive working relationships with students, faculty, staff, and community members
- Preferred Qualifications:
* Experience working in higher education, research, or similarly complex enterprise environments, particularly those with diverse identity populations and federated access needs.
* Familiarity with cloud‑based identity platforms and services (e.g., **Azure AD, AWS IAM, Google Identity, or similar**).
* Experience with identity lifecycle management, provisioning/de‑provisioning workflows, and access governance.
* Knowledge of zero trust, least‑privilege, and modern identity security architectures.
* Experience integrating identity services with enterprise applications, including SaaS platforms and custom applications.
* Demonstrated experience participating in cross‑functional technical initiatives, including collaboration with security, infrastructure, and application teams.
* Experience supporting incident response, audits, or compliance efforts related to identity and access management.
* Familiarity with **DevOps or CI/CD** practices, automated deployments, and infrastructure‑as‑code concepts.
* Strong customer‑service orientation with the ability to balance security requirements with usability and operational needs
Qualifications
Must Haves
- Required Qualifications:
* Bachelor's degree with a minimum of **three to five years** of relevant experience, or an equivalent combination of education and experience.
* Demonstrated success providing technical support and application or middleware development in a distributed, team‑focused computing environment.
* Demonstrated expertise with one or more scripting or programming languages, such as **Java, Perl, Python, and/or VB (.NET), ReactJS, Ruby, and/or PHP**
* Approximately **1 year+** of professional experience developing **ReactJS applications and/or Ruby on Rails.**
* **System administration experience with** **Linux required; and Windows experience preferred.**
* Working to advanced knowledge of one or more identity and access management technologies, including **directory services, virtual directories, SAML2, OAuth2, LDAP, and Active Directory authorization technologies.**
* Proven experience writing technical design documentation, conducting code reviews, and working with version control systems such as **Git**.
* Ability to translate user and business needs into clear functional requirements and technical specifications, and to promote effective and efficient information sharing.
* Demonstrated ability to communicate complex Identity Management concepts—including system functions, capabilities, and processes—into business terms that are clear, accessible, and meaningful to non‑technical stakeholders.
* Proven ability to work effectively in a dynamic, deadline‑driven, and complex environment with multiple competing priorities.
* Strong facilitation, problem‑solving, analytical, reasoning, and judgment skills, with the ability to evaluate options and recommend sound technical solutions.
* Experience supporting and managing mission‑critical systems in a production environment, including troubleshooting and incident response.
* Proven ability to identify, scope, and implement opportunities for automation or architectural improvements that enhance system reliability, security, or efficiency.
* Ability to cultivate and develop inclusive working relationships with students, faculty, staff, and community members
Nice to Haves
- Preferred Qualifications:
* Experience working in higher education, research, or similarly complex enterprise environments, particularly those with diverse identity populations and federated access needs.
* Familiarity with cloud‑based identity platforms and services (e.g., **Azure AD, AWS IAM, Google Identity, or similar**).
* Experience with identity lifecycle management, provisioning/de‑provisioning workflows, and access governance.
* Knowledge of zero trust, least‑privilege, and modern identity security architectures.
* Experience integrating identity services with enterprise applications, including SaaS platforms and custom applications.
* Demonstrated experience participating in cross‑functional technical initiatives, including collaboration with security, infrastructure, and application teams.
* Experience supporting incident response, audits, or compliance efforts related to identity and access management.
* Familiarity with **DevOps or CI/CD** practices, automated deployments, and infrastructure‑as‑code concepts.
* Strong customer‑service orientation with the ability to balance security requirements with usability and operational needs
Benefits
- Eligible for remote work within the United States
- Comprehensive health care options
- Generous retirement contributions
- Access to wellness programs
- Employee discounts with local and national retail brands
- Health and personal leave
- Three weeks of vacation
- 13 holidays
- Two additional floating holidays
- Tuition-free Extramural Study and Employee Degree Program
- Tuition aid for external education
- Cornell Children's Tuition Assistance Program