Senior Access Management Engineer - Duo / MFA Specialist (Remote in the U.S.)

GuidePoint Security · Remote · Engineering

Posted 2026-09-10

Apply for this role →

General Description

GuidePoint Security is hiring a Senior Access Management Engineer specializing in Cisco Duo to join our implementation team on a full-time basis. This is a fully remote role where we are looking for deep, hands-on experience leading Duo Security deployments, migrations, and integrations — with secondary proficiency in Okta and/or Ping Identity platforms to support broader Access Management engagements.

The Senior Access Management Engineer is responsible for designing, deploying, integrating, and optimizing Duo MFA and access solutions for some of the largest organizations in the US. This role serves as the go-to technical lead for all Duo engagements, owning architecture decisions, integration design, and delivery execution. When Duo engagements are not fully utilizing capacity, this resource will flex into a supporting engineer role on Okta and Ping Identity projects, contributing hands-on technical work under the direction of the engagement's lead architect.

This role sits at the intersection of security, infrastructure, and application integration — ensuring that multi-factor authentication, device trust, and adaptive access policies are implemented securely, reliably, and at scale.

About the Access Management practice

Coming to the Access Management team means working on the leading edge in the IAM space. As a Senior Access Management Engineer, you will be partnering with other engineers and architects to help some of the largest companies in the US implement their own identity and access management programs. From participating in assessments to full delivery of IAM platforms, you can expect to be involved at all levels of interaction with our customers. Your leadership and expertise are critical to providing our customers with the guidance they need, and the excellence they expect from GuidePoint Security.

We partner with the largest vendors in the space to ensure that the latest training is always available to our team. High level communication and collaboration are the standard. Mentorship at all levels, from Senior Architects to Junior Engineers, is foundational to our culture. We don't just talk about work life balance; we facilitate it with an unlimited PTO benefit.

We understand that in order to retain our talented team, leadership must provide regular feedback and coaching. We recruit new members to the team with the understanding that opportunities for growth are important. Whether your goals include future leadership opportunities, becoming an Architect or even moving to another discipline within security in time, the leadership team is focused on partnering with you to help achieve them.

Roles and Responsibilities:

Duo Security – Lead Engineer  (Primary – 50%)

Serve as the primary technical lead on all Duo Security engagements, owning end-to-end delivery from design through implementation and handoff

Lead Duo deployment architecture and design, including:

Duo MFA — Policy design, user enrollment strategies, self-service portal configuration, and phased rollout planning

Duo Authentication Proxy — Deployment, configuration, high availability, and integration with RADIUS, LDAP, and Active Directory

Duo Single Sign-On (SSO) — SAML 2.0 and OIDC federation, application onboarding, and custom login branding

Duo Device Trust — Trusted endpoint policies, certificate-based device verification, and managed/unmanaged device posture enforcement

Duo Network Gateway (DNG) — Clientless remote access to internal web applications and SSH/RDP resources

Duo Admin Panel & API — Tenant configuration, Admin API and Auth API integrations, custom scripting, and reporting

Duo Trusted Endpoints — Integration with endpoint management platforms (Intune, Jamf, Workspace ONE, etc.)

Duo Desktop (formerly Duo Device Health) — Endpoint health verification and posture-based access policies

Design and implement Duo integrations across a wide range of application and infrastructure types, including:

VPN concentrators (Cisco ASA, Palo Alto GlobalProtect, Fortinet, Pulse/Ivanti)

Remote access platforms (Citrix, VMware Horizon, RD Gateway/NPS)

Web applications via SAML/OIDC federation or Duo Web SDK

Cloud platforms (AWS, Azure, GCP) for console and CLI MFA

On-premises infrastructure (Windows RDP, SSH, local OS logon)

Custom and legacy applications via Duo Auth API and Web SDK

Plan and execute Duo-to-Duo migrations (e.g., tenant consolidation) and competitive migrations from Duo to Okta, Duo to Entra ID, or other MFA platforms

Develop automation scripts (Python, PowerShell, Bash) leveraging Duo Admin API for bulk operations, reporting, user lifecycle management, and integration testing

Design phased MFA rollout strategies with user communication plans, pilot groups, and exception handling workflows

Conduct security reviews of Duo configurations, identifying gaps in policy coverage, authentication bypass risks, and device trust enforcement

Develop and maintain technical documentation, architecture diagrams, integration runbooks, and client-facing knowledge transfer materials

Okta & Ping Identity – Supporting Engineer (Secondary – 35%)

Serve as a supporting engineer on Okta and Ping Identity engagements when Duo workload permits, working under the direction of the engagement's lead architect

Contribute hands-on technical work on Okta engagements, including:

Application integration (SAML, OIDC, SWA) and SSO configuration

MFA policy configuration and adaptive access policies

Lifecycle Management (LCM) — provisioning, deprovisioning, and group-based automation

Directory integrations (Active Directory, LDAP, HR systems via SCIM)

Okta Workflows — supporting flow development for custom integrations and automations

User migration and bulk import operations

Contribute hands-on technical work on Ping Identity engagements, including:

PingFederate — SP/IdP connection configuration, adapter setup, and federation troubleshooting

PingOne — SSO, MFA, and directory service configuration

PingAccess — Resource and policy configuration for web application protection

On-premises Ping product support — Assisting with deployments, upgrades, and patching under architect direction

Execute assigned integration tasks, configuration changes, and testing activities with quality and consistency

Participate in peer reviews, knowledge-sharing sessions, and cross-training to deepen Okta and Ping Identity skills over time

Project Ownership & Client Success (10%)

Serve as the technical project owner on Duo engagements, taking full accountability for successful delivery and client outcomes

On Okta/Ping engagements, support the lead architect with clear status updates, task completion, and proactive communication of blockers

Delegate routine Duo tasks to junior engineers when available, providing clear direction and technical guidance

Mentor junior resources through hands-on pairing, configuration reviews, and knowledge-sharing sessions

Develop and maintain technical documentation, architecture diagrams, implementation guides, and runbooks for all engagements

Contribute to the development of standard operating procedures (SOPs), delivery templates, and Duo-specific best practice frameworks

Presales Support & Business Development (5%)

Provide Duo-focused technical expertise during the presales process to support new business opportunities

Assist with technical discovery, scoping, and requirements gathering for prospective Duo and MFA engagements

Develop Level of Effort (LOE) estimates for proposed Duo implementations and migrations

Contribute to Statement of Work (SOW) development, ensuring technical accuracy and feasibility

Support proposal development with solution architectures, integration approaches, and implementation roadmaps

Participate in client-facing presentations and technical demonstrations during the sales cycle

Required Experience and Education:

Bachelor’s degree in computer science, Information Security, or related field — or equivalent work experience

5+ years of experience in Identity and Access Management, with a strong emphasis on MFA and access security

Deep, hands-on experience with Cisco Duo Security, including:

Duo MFA policy design, deployment, and administration

Duo Authentication Proxy deployment and configuration (RADIUS, LDAP, AD)

Duo SSO configuration (SAML 2.0, OIDC)

Duo integrations across VPN, remote access, web applications, and infrastructure

Duo Admin API and Auth API for automation and custom integrations

Duo Device Trust and Trusted Endpoints configuration

Working proficiency with at least one of the following:

Okta — Application integration, SSO, MFA, Lifecycle Management, directory integrations

Ping Identity — PingFederate, PingOne, PingAccess configuration and administration

Strong understanding of SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), and RADIUS protocols

Proficiency with Python, PowerShell, or Bash for automation and API integrations

Experience integrating MFA solutions with VPN, Citrix, RD Gateway/NPS, and cloud platforms

Familiarity with Active Directory, LDAP, and enterprise directory services

Experience with endpoint management platforms (Intune, Jamf, Workspace ONE) in the context of device trust

Strong understanding of Zero Trust principles, least-privilege access, and identity security best practices

Demonstrated ability to own technical delivery, manage client expectations, and work independently with minimal oversight

Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes.

Preferred Experience and Education

Experience with Duo-to-Okta or Duo-to-Entra ID migration projects

Hands-on experience with both Okta and Ping Identity platforms (not just one)

Familiarity with Okta Workflows for custom automation and integration development

Experience with PingFederate federation hub architecture and multi-protocol bridging

Experience with DaVinci orchestration (Ping Identity)

Familiarity with Microsoft Entra ID / Azure AD, including Conditional Access and MFA

Infrastructure-as-code experience (Terraform, Ansible) for identity platform deployments

Professional certifications such as:

Cisco Duo certifications

Okta Certified Professional / Administrator / Consultant

Ping Identity Certified Professional

CISSP, CISM, or equivalent security certifications

Physical Requirements:

Sedentary work

Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day

Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day

Apply for this role →

← Back to all jobs