Roles and Responsibilities: Duo Security – Lead Engineer (Primary – 50%) Serve as the primary technical lead on all Duo Security engagements, owning end-to-end delivery from design through implementation and handoff Lead Duo deployment architecture and design, including: Duo MFA — Policy design, user enrollment strategies, self-service portal configuration, and phased rollout planning Duo Authentication Proxy — Deployment, configuration, high availability, and integration with RADIUS, LDAP, and Active Directory Duo Single Sign-On (SSO) — SAML 2.0 and OIDC federation, application onboarding, and custom login branding Duo Device Trust — Trusted endpoint policies, certificate-based device verification, and managed/unmanaged device posture enforcement Duo Network Gateway (DNG) — Clientless remote access to internal web applications and SSH/RDP resources Duo Admin Panel & API — Tenant configuration, Admin API and Auth API integrations, custom scripting, and reporting Duo Trusted Endpoints — Integration with endpoint management platforms (Intune, Jamf, Workspace ONE, etc.) Duo Desktop (formerly Duo Device Health) — Endpoint health verification and posture-based access policies Design and implement Duo integrations across a wide range of application and infrastructure types, including: VPN concentrators (Cisco ASA, Palo Alto GlobalProtect, Fortinet, Pulse/Ivanti) Remote access platforms (Citrix, VMware Horizon, RD Gateway/NPS) Web applications via SAML/OIDC federation or Duo Web SDK Cloud platforms (AWS, Azure, GCP) for console and CLI MFA On-premises infrastructure (Windows RDP, SSH, local OS logon) Custom and legacy applications via Duo Auth API and Web SDK Plan and execute Duo-to-Duo migrations (e.g., tenant consolidation) and competitive migrations from Duo to Okta, Duo to Entra ID, or other MFA platforms Develop automation scripts (Python, PowerShell, Bash) leveraging Duo Admin API for bulk operations, reporting, user lifecycle management, and integration testing Design phased MFA rollout strategies with user communication plans, pilot groups, and exception handling workflows Conduct security reviews of Duo configurations, identifying gaps in policy coverage, authentication bypass risks, and device trust enforcement Develop and maintain technical documentation, architecture diagrams, integration runbooks, and client-facing knowledge transfer materials Okta & Ping Identity – Supporting Engineer (Secondary – 35%) Serve as a supporting engineer on Okta and Ping Identity engagements when Duo workload permits, working under the direction of the engagement's lead architect Contribute hands-on technical work on Okta engagements, including: Application integration (SAML, OIDC, SWA) and SSO configuration MFA policy configuration and adaptive access policies Lifecycle Management (LCM) — provisioning, deprovisioning, and group-based automation Directory integrations (Active Directory, LDAP, HR systems via SCIM) Okta Workflows — supporting flow development for custom integrations and automations User migration and bulk import operations Contribute hands-on technical work on Ping Identity engagements, including: PingFederate — SP/IdP connection configuration, adapter setup, and federation troubleshooting PingOne — SSO, MFA, and directory service configuration PingAccess — Resource and policy configuration for web application protection On-premises Ping product support — Assisting with deployments, upgrades, and patching under architect direction Execute assigned integration tasks, configuration changes, and testing activities with quality and consistency Participate in peer reviews, knowledge-sharing sessions, and cross-training to deepen Okta and Ping Identity skills over time Project Ownership & Client Success (10%) Serve as the technical project owner on Duo engagements, taking full accountability for successful delivery and client outcomes On Okta/Ping engagements, support the lead architect with clear status updates, task completion, and proactive communication of blockers Delegate routine Duo tasks to junior engineers when available, providing clear direction and technical guidance Mentor junior resources through hands-on pairing, configuration reviews, and knowledge-sharing sessions Develop and maintain technical documentation, architecture diagrams, implementation guides, and runbooks for all engagements Contribute to the development of standard operating procedures (SOPs), delivery templates, and Duo-specific best practice frameworks Presales Support & Business Development (5%) Provide Duo-focused technical expertise during the presales process to support new business opportunities Assist with technical discovery, scoping, and requirements gathering for prospective Duo and MFA engagements Develop Level of Effort (LOE) estimates for proposed Duo implementations and migrations Contribute to Statement of Work (SOW) development, ensuring technical accuracy and feasibility Support proposal development with solution architectures, integration approaches, and implementation roadmaps Participate in client-facing presentations and technical demonstrations during the sales cycle Required Experience and Education: Bachelor’s degree in computer science, Information Security, or related field — or equivalent work experience 5+ years of experience in Identity and Access Management, with a strong emphasis on MFA and access security Deep, hands-on experience with Cisco Duo Security , including: Duo MFA policy design, deployment, and administration Duo Authentication Proxy deployment and configuration (RADIUS, LDAP, AD) Duo SSO configuration (SAML 2.0, OIDC) Duo integrations across VPN, remote access, web applications, and infrastructure Duo A