Thanks for the click. We know your time is valuable so we will get right to it.
We’ve amassed some of the best and brightest minds in cyber security who are passionate about protecting the digital world. Our team blends advanced technology alongside deep expertise to tackle the toughest cyber threats out there. Put simply, our mission is to stay ahead of the curve and create a safer digital landscape for our partners, and we think adding an Identity Security Engineer (Duo Security) will up our cyber game.
We are seeking an experienced MFA / Identity Security Engineer with deep hands-on expertise implementing, configuring, troubleshooting, and supporting Cisco Duo Security solutions in enterprise environments.
The ideal candidate will have significant experience with Duo Authentication Proxy, including both LDAP and RADIUS-based integrations, as well as experience implementing and supporting Duo Single Sign-On (SSO). This position requires a strong understanding of authentication protocols, Active Directory, network security, identity providers, and enterprise application integration.
Experience with Microsoft Entra ID (Azure AD) is highly desirable. Previous experience implementing or supporting RSA SecurID is also valuable, particularly for organizations migrating from legacy RSA authentication environments to Duo.
This is a highly technical, hands-on engineering role intended for someone who can independently design, deploy, troubleshoot, document, and support MFA solutions across diverse customer and enterprise environments
What you’ll be doing.
- Design, deploy, configure, and support Cisco Duo Security MFA solutions across a variety of enterprise applications, infrastructure platforms, and remote-access technologies.
- Install, configure, upgrade, and troubleshoot Duo Authentication Proxy servers.
- Configure Duo Authentication Proxy integrations using:
- RADIUS
- LDAP / LDAPS
- Active Directory
- Other Duo-supported authentication configurations as required.
- Integrate Duo MFA with technologies such as:
- Firewalls
- Remote-access VPN solutions
- Windows servers
- Network infrastructure
- Privileged administrative systems
- Design and implement resilient Duo Authentication Proxy architectures, including redundant proxy servers and appropriate failover configurations.
- Implement and support Duo Single Sign-On (SSO).
- Configure SAML-based integrations between Duo and SaaS or internally hosted applications.
- Integrate Duo SSO with enterprise identity directories and identity providers.
- Troubleshoot SAML authentication, assertions, claims, certificates, metadata, redirects, and application configuration issues.
- Configure and support Duo Universal Prompt integrations.
- Configure Duo application policies, authentication policies, user enrollment policies, device policies, trusted networks, and other access-control settings.
- Assist with deployment and troubleshooting of Duo integrations with Microsoft Windows environments, including Active Directory and Windows Logon/RDP.
- Analyze authentication logs and application logs to diagnose MFA, RADIUS, LDAP, SAML, networking, certificate, and directory-related issues.
- Perform packet-level troubleshooting when required using tools such as Wireshark, tcpdump, firewall packet captures, and related diagnostic utilities.
- Work with firewall and networking teams to identify connectivity, routing, NAT, DNS, certificate, and firewall-policy issues affecting authentication services.
- Maintain secure configuration standards for authentication infrastructure.
- Develop implementation plans, technical documentation, diagrams, configuration standards, and troubleshooting procedures.
- Participate in migrations from existing MFA platforms, including RSA SecurID, to Cisco Duo.
- Assist with evaluating existing authentication environments and developing migration strategies that minimize disruption to users and applications.
- Provide technical guidance and escalation support for complex MFA and identity-related issues.
- Work directly with customers, internal engineering teams, application owners, security teams, and vendors during implementations and troubleshooting engagements.
What does it take to succeed in this role?
- Cisco Duo Security
Candidates should be comfortable reviewing and troubleshooting authproxy.cfg configurations and understanding how multiple authentication and application sections interact within the Duo Authentication Proxy.
- Cisco Duo Administration
- Duo Authentication Proxy installation and configuration
- RADIUS-based Duo integrations
- LDAP / LDAPS integrations
- Active Directory integration
- Duo Single Sign-On
- Duo Universal Prompt
- Duo application integrations
- Duo policy configuration
- User and device enrollment
- Duo troubleshooting and log analysis
- Authentication Proxy redundancy and high-availability design
- Authentication and Identity Technologies
The engineer should understand the complete authentication flow between the end user, application, network device, Duo Authentication Proxy, identity directory, Duo cloud services, and other components involved in an authentication transaction.
- RADIUS
- LDAP
- LDAPS
- SAML 2.0
- Single Sign-On
- Multi-Factor Authentication
- Active Directory
- TLS / SSL certificates
- Public Key Infrastructure fundamentals
- Identity providers and service providers
- Authentication and authorization concepts
What are desirables?
- Bachelor’s degree in computer science, information technology, and previous work experience.
- 5+ years of experience in IT infrastructure, networking, security, identity, or systems engineering.
- 3+ years of hands-on experience implementing and supporting MFA technologies.
- Significant hands-on experience with Cisco Duo Security.
- Experience migrating organizations from RSA SecurID or another MFA solution to Duo.
- Experience working with enterprise firewalls and VPN technologies.
Work Arrangement
This is an onsite position based in the United States.
At this time, we are not hiring candidates who require visa sponsorship. All applicants must be legally authorized to work in the United States without the need for current or future visa sponsorship.
How we work.
Our 3 values define how we operate internally as well as externally:
Vision - We embrace a forward-thinking mindset. Our team has a clear and inspiring picture of the future that helps drive our decisions towards creating and delivering world-class security services.
Velocity - We have a bias for action. We move swiftly and with purpose toward our goals and objectives and can easily adapt (and adjust) along the way.
Vigilance – We foster a culture of proactive awareness for our company and our customers, who trust us to be an extension of their team. We are always looking for areas where we can innovate, improve, fix, transform and revolutionize, which ensures the protection, safety and success of everyone at SilverSky.
Individuals that can act intelligently and confidently without an ego will thrive.
If this opportunity sounds interesting and you are passionate about redefining how the world thinks about cyber security, we want to hear from you. Apply now if you are interested in learning more about how we can change the rules of engagement, together.
About SilverSky
We are a global cyber security company with more than 20 years of professional experience in the industry. Our 300+ employees are on a mission to protect our customers with comprehensive, adaptive security services that maximize technology and automate responses, while empowering security analysts to hunt for threats, react and respond immediately. It’s the human enhanced response that differentiates SilverSky and allows us to create the most comprehensive managed detection and response (MxDR) solution in the industry by delivering on our Vision, Velocity, Vigilance philosophy. Follow us on X and LinkedIn to learn more.