
Job Title: Senior Engineer, Identity Access Management - Directory Services
<p style="text-align:left"><b>Working with Us</b><br />Challenging. Meaningful.
Life-changing. Those aren’t words that are usually associated with a job.
But working at Bristol Myers Squibb is anything but usual. Here, uniquely interesting work happens every day, in every department.
From optimizing a production line to the latest breakthroughs in cell therapy, this is work that transforms the lives of patients, and the careers of those who do it. You’ll get the chance to grow and thrive through opportunities uncommon in scale and scope, alongside high-achieving teams.
Take your career farther than you thought possible.</p><p style="text-align:inherit"></p><p style="text-align:left">Bristol Myers Squibb recognizes the importance of balance and flexibility in our work environment. We offer a wide variety of competitive benefits, services and programs that provide our employees with the resources to pursue their goals, both at work and in their personal lives.
Read more: <a href="https://careers.bms.com/working-with-us" target="_blank"><span><span><span><span><span><span><span><span><span><span><span class="WIN0">careers.bms.com/working-with-us</span></span></span></span></span></span></span></span></span></span></span></a>.</p><p style="text-align:inherit"></p><p style="text-align:inherit"></p><p><span> <b>Job Profile</b></span></p><p><span>Bristol Myers Squibb (BMS) is seeking an experienced <b>Senior Engineer – Identity Access Management (Directory Services)</b> to design, implement, and support enterprise directory platforms that enable secure identity services across the global organization. The ideal candidate combines deep directory services expertise with strong Linux, cloud, automation, and troubleshooting skills, and thrives in a highly collaborative environment focused on innovation, reliability, security, and operational excellence.</span></p><p><span>This role is responsible for ensuring stability, scalability, security, and availability of critical directory services that support authentication, authorization, and identity-related business processes across the enterprise.
The successful candidate will work closely with Architecture, Infrastructure, Security, and Application teams to deliver modern identity solutions and drive continuous improvement initiatives.</span></p><p><span> </span></p><p><span><b>Key Responsibilities</b></span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Provide technical leadership for enterprise directory services platforms based on LDAP technologies, including Ping DS (formerly ForgeRock Directory Services), Ping Directory, Oracle DSEE, Microsoft Entra ID (Azure AD), and virtual directory solutions.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Design, implement, administer, monitor, and optimize directory infrastructure, including replication topologies, indexing strategies, backups, disaster recovery, performance tuning, and capacity planning.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Ensure Directory Services platforms remain secure, compliant, resilient, and highly available.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Partner with Architecture, Security, and Infrastructure teams to evaluate, implement, and integrate new technologies and solutions.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Drive modernization initiatives and proactively identify opportunities to improve performance, scalability, automation, and operational efficiency.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Support business-critical production environments and lead the resolution of complex incidents and escalations.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Conduct Root Cause Analysis (RCA), Problem Management activities, and implement preventive measures to improve service reliability.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Develop and maintain architecture documentation, technical standards, requirements, network designs, roadmaps, implementation plans, recovery procedures, rollback strategies, and disaster recovery solutions.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Direct and support installation, configuration, maintenance, patching, and lifecycle management of directory service platforms.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Collaborate effectively with internal infrastructure teams, application owners, security teams, vendors, and business stakeholders to deliver identity-related capabilities and operational support.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Demonstrate strong ownership and accountability by driving issues to resolution and leading technical initiatives across cross-functional teams.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Mentor and provide technical guidance to junior engineers and team members.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Participate in an on-call support rotation and perform maintenance, deployment, and upgrade activities during approved maintenance windows as required.</span></p><p><span> </span></p><p><span><b>Required Technical Experience</b></span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Advanced expertise with LDAP-based directory technologies, including Ping DS (ForgeRock Directory Services), Oracle DSEE, and other enterprise-grade directory solutions.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Hands-on experience with public cloud platforms such as AWS and Azure.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Strong experience administering Linux operating systems, including software installation, patching, troubleshooting, automation, and performance tuning.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Experience supporting enterprise application servers such as Apache Tomcat, JBoss, WebLogic, and WebSphere.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Strong scripting and automation skills using technologies such as Bash, PowerShell, Python, JavaScript, or similar languages.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Software development experience with knowledge of Object-Oriented Programming (OOP), REST APIs, MVC architecture, and Java frameworks such as Spring.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Strong understanding of networking concepts, including DNS, TLS/SSL, load balancers, reverse proxies, and end-to-end encryption architectures.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Experience integrating directory platforms with enterprise applications, cloud services, and third-party technologies.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Strong troubleshooting and diagnostic skills across identity platforms, infrastructure, network, and application layers.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Experience with SQL and/or PL/SQL for querying, troubleshooting, and supporting enterprise identity and directory-related applications.</span></p><p><span> </span></p><p><span><b>Preferred Qualifications</b></span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Foundational knowledge of Agentic AI concepts, frameworks, and emerging use cases, with an interest in leveraging AI-assisted capabilities to enhance identity operations, security, automation, and user experience.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Working knowledge of Access Management and Identity Federation technologies, including Single Sign-On (SSO), SAML, OAuth 2.0, OpenID Connect (OIDC), Multi-Factor Authentication (MFA), LDAP integrations.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Experience with enterprise identity platforms such as Ping Identity, ForgeRock, Okta, or Microsoft Entra ID.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Experience implementing infrastructure-as-code, automation, and DevOps practices within identity and infrastructure environments.</span></p><p><span> </span></p><p><span><b>Qualifications</b></span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>5+ years of hands-on experience administering and supporting enterprise LDAP directory solutions such as Ping DS (ForgeRock Directory Services), Oracle DSEE, or other leading enterprise-grade directory technologies.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Deep expertise in directory services engineering, architecture, troubleshooting, and operations.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Hands-on experience with cloud infrastructure platforms such as AWS and/or Azure.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Strong Linux administration experience, including deployment, patching, security, and operational support.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Experience supporting enterprise middleware and application server technologies.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Proficiency in one or more programming and scripting languages such as Python, Java, JavaScript, PowerShell, or Bash.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Strong troubleshooting skills across IAM platforms, networking, web technologies, cloud services, and enterprise integrations.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Excellent verbal and written communication skills with the ability to create technical documentation and present complex concepts to technical and non-technical audiences.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Demonstrated ability to lead technical initiatives, mentor engineers, and drive complex problem resolution.</span></p><p><span style="color:#4a4a4a"><span>· </span></span><span>Bachelor's degree (or equivalent experience) in Information Technology, Computer Science, Computer Engineering, or a related field.</span></p><p><span> </span></p><p style="text-align:inherit"></p><p style="text-align:left"><i>If you come across a role that intrigues you but doesn’t perfectly line up with your resume, we encourage you to apply anyway. You could be one step away from work that will transform your life and career.</i></p><p style="text-align:inherit"></p><p style="text-align:left"><b>Uniquely Interesting Work, Life-changing Careers</b><br />With a single vision as inspiring as “Transforming patients’ lives through science™ ”, every BMS employee plays an integral role in work that goes far beyond ordinary.
Each of us is empowered to apply our individual talents and unique perspectives in a supportive culture, promoting <span>global participation </span>in clinical trials, while our shared values of passion, innovation, urgency, accountability, inclusion and integrity bring out the highest potential of each of our colleagues.</p><p style="text-align:inherit"></p><p style="text-align:left"><b>On-site Protocol</b></p><p style="text-align:left"><span>BMS has an occupancy structure that determines where an employee is required to conduct their work. This structure includes site-essential, site-by-design, field-based and remote-by-design jobs.
The occupancy type that you are assigned is determined by the nature and responsibilities of your role:</span></p><p style="text-align:inherit"></p><p style="text-align:left"><span>Site-essential roles require 100% of shifts onsite at your assigned facility. Site-by-design roles may be eligible for a hybrid work model with at least 50% onsite at your assigned facility.
For these roles, onsite presence is considered an essential job function and is critical to collaboration, innovation, productivity, and a positive Company culture. For field-based and remote-by-design roles the ability to physically travel to visit customers, patients or business partners and to attend meetings on behalf of BMS as directed is an essential job function.</span></p><p style="text-align:inherit"></p><p style="text-align:left"><b>Supporting People with Disabilities</b></p><p style="text-align:left"><span>BMS is dedicated to ensuring that people with disabilities can excel through a transparent recruitment process, reasonable workplace <span><span class="WIN0">accommodations/adjustments</span></span> and ongoing support in their roles.
Applicants can request a reasonable workplace <span><span class="WIN0">accommodation/adjustment</span></span> prior to accepting a job offer. If you require reasonable <span><span class="WIN0">accommodations/adjustments</span></span> in completing this application, or in any part of the recruitment process, direct your inquiries to </span><span><a href="mailto:adastaffingsupport@bms.com" target="_blank"><span><span class="WIN0">adastaffingsupport@bms.com</span></span></a></span><span>.
Visit </span><span><a href="https://careers.bms.com/eeo-accessibility" target="_blank"><span>careers.bms.com/</span></a><a href="https://careers.bms.com/eeo-accessibility" target="_blank"><span>eeo</span></a><a href="https://careers.bms.com/eeo-accessibility" target="_blank"><span>-accessibility</span></a></span><span> to access our complete Equal Employment Opportunity statement.</span></p><p style="text-align:inherit"></p><p style="text-align:left"><b>Candidate Rights</b></p><p style="text-align:left"><span>BMS will consider for employment qualified applicants with arrest and conviction records, pursuant to applicable laws in your area.</span></p><p style="text-align:inherit"></p><p style="text-align:left"><span>If you live in or expect to work from Los Angeles County if hired for this position, please visit this page for important additional information: </span><span><a href="https://careers.bms.com/california-residents/" target="_blank"><span><span class="WIN0">https://careers.bms.com/california-residents/</span></span></a></span></p><p style="text-align:inherit"></p><p style="text-align:left"><b>Data Protection</b></p><p style="text-align:left">We will never request payments, financial information, or social security numbers during our application or recruitment process. Learn more about protecting yourself at <a href="http://careers.bms.com/fraud-protection" target="_blank"><span class="WIN0">https://careers.bms.com/fraud-protection</span></a>.</p><p style="text-align:inherit"></p><p style="text-align:left">Any data processed in connection with role applications will be treated in accordance with applicable data privacy policies and regulations.</p><p></p><p><span>If you believe that the job posting is missing information required by local law or incorrect in any way, please contact BMS at </span><a href="mailto:TAEnablement@bms.com" target="_blank">TAEnablement@bms.com</a><span>.
Please provide the Job Title and Requisition number so we can review. Communications related to your application should not be sent to this email and you will not receive a response.
Inquiries related to the status of your application should be directed to Chat with Ripley.</span></p><p></p><p></p>R1604572 : Job Title: Senior Engineer, Identity Access Management - Directory Services
Originally posted by RayzeBio. View original posting
Similar roles at other companies
BioCareerAI is an independent job platform and is not affiliated with or endorsed by RayzeBio.
