We provide IT Staff Augmentation Services!

Iam Consultant Resume

3.00/5 (Submit Your Rating)

PROFESSIONAL SUMMARY:

  • Around 7+ years of professional experience in administering and developing Identity & Access Management solutions on Linux, Solaris and Windows platforms.
  • Proven Experience in setting up SSO environments. Integrated SSO products Netegrity Siteminder 5x\6x\R12.x with existing enterprise applications and middleware applications.
  • Proficient in installation, security & performance design and configuration of Siteminder policy server, ping federate, ForgeRock and web agents in a SSO Environment.
  • Performing system monitoring, analyzing and documenting performance and conducting trend analyses as required.
  • Extensive knowledge of creating policy domains, realms, policies and rules, configuring access to User directories, setting up response attributes and cookie variables, defining authentication schemes in a SSO Environment.
  • Extensive knowledge in creating the IDP and SP connections using the Ping interface.
  • Extensive knowledge in migrating the federation connections from Siteminder to ping Federate.
  • Expertise in analysis, design and development of web centric Object Oriented applications using Java, JSP, JDBC, XML, JavaScript.
  • Use OpenIDM to develop user accounts lifecycle management (provisioning, deprovisioning etc)
  • Upgraded the ping federate engine from 6.x to 7.x
  • Migrating SiteMinder environment to ForgeRock
  • Installation and configuration of OpenDJ 5.5 and 6.x.
  • Experience in working with on databases such asOracleandMySQLServer
  • Experience in Directory Server Configuration/Administration (CA Directory Server, Sun One Directory server 5.x/6.x/7.x, MS Active Directory). Good understanding of LDAP protocol, designing of schema, planning the directory data according to the enterprise needs.
  • Experienced in Enterprise Security Strategy, Architectures, Implementation and Production Support.
  • Setting up, migrating, implementing and configuring CA Siteminder and Sun one Directory server for secure single sign - n solutions on multiple platforms.
  • Experience in LDAP server Replication Management to make sure the directory services in the enterprise are accessible in highly available mode.
  • Experienced in designing, implementing LDAP architecture which includes DIT, schema, replication (single/multi-master and consumer configuration), and chaining and data synchronization.
  • Excellent in Troubleshooting & Debugging using log files from policy server logs, web agent logs, directory server logs.
  • Expertise in using the Siteminder Test tool to run the test cases for Functional, Regression and Stress testing.
  • In-depth knowledge and experience with J2EE JACC, JAAS, JSSE, JCA and JCE, Kerberos GSS-API, Spring Security, Oauth 2.0, OpenIDConnect, SAML 2.0.
  • Experience in working with automation tools likeCHEF, PUPPET and ANSIBLE.
  • Experience with Configuration Management automation tool Ansible and has worked on integratingAnsible YAML Scripts
  • Created Ansible Custom Modules and Roles to automate ISAM Appliance tasks. Custom Modules provide the interface to python idempotent functions in IBM Security Package.
  • Worked with a repository like SVN and GIT
  • Knowledge in execution of upgrade plans for various Siteminder versions. Knowledge in Siteminder R12 components & Siteminder Active Expressions.
  • Install and configure Siteminder policy server, secure proxy servers and SharePoint agents.
  • Integrate SharePoint portal with Security infrastructure (consists of policy servers, SPS, SPA, Risk/Auth minder components).
  • Configure risk base Authentication for external users using Auth and Risk Minder.
  • Support QA and fixing bugs that come during testing phase.
  • Troubleshooting and Fine Tuning of web and Application servers to support the given User Base requirement of Application.
  • Expertise in troubleshooting Siteminder/LDAP issues.
  • Hands on using the SPLUNK to troubleshoot the issue to go through the log sniffets.
  • Ability to manage multiple tasks, works independently, and adapts to new technologies quickly.

TECHNICAL SKILLS:

SSO Management: Siteminder Policy Server 5x/6.0/R12.x, Siteminder Web Agent 5x/6.0/R12.x, Siteminder secure Proxy server, ForgeRock, Siteminder Report server.

Directory Servers: CA Directory Server, Sun Directory Server 5.x/6.x/7.x, MS Active Directory, LDAP

Web Servers: Sun One web server, Apache (Vfabric & JWS), IIS 5x/6x/7x, IBM HTTP server

Operating System: Windows 2000/2003/xp/2008, Solaris/Linux.

Application Servers: Tomcat (TcServer & JWS), IBM Web Sphere

Programming: C, C++, .Net, HTML, Perl, MYSQL

Languages: Java, Java script, PL/SQL, Unix Shell Scripting, XML, SOAP, HTML, CSS

PROFESSIONAL EXPERIENCE:

Confidential

IAM Consultant

Responsibilities:

  • Hands on experience in IAM requirement analysis, implementation of Access Gateways and SAML based integrations
  • Responsible for installation and setup the new Access management environment across multiple environemnets like (Dev, Qa, Pre-Prod and Prod).
  • Involved in migration of Siteminder 6.X to 12.x on Solaris 10 LDOM’s with 100 + applications and 500 + webagents
  • Has experience in implementing IAM solution using ForgeRock Identity Stack (Open IDM, Open AM, Open DJ).
  • Worked on OpenIG to send all the traffic through a common proxy server and redirect to Resource Server.
  • Installation and configuration of ForgeRock OpenDJ 5.5 and 6.x
  • Installation and configuration of ForeRock OpenAM 13.5, 6.x version
  • Configured both Ping Access Proxy Gateway to decode the JWT tokens and installed the agent on the application server to communicate with the Ping Federate server.
  • ForgeRock SAML Based Authentication with a SP and IDP id.
  • Setting up separate ForgeRock replication server instances
  • Migrating data from LDAP to ForgeRock OpenDj
  • Worked closely with ForgeRock implementation partners during migration.
  • Settting up policies, creating agent, whitelisting URL in ForgeRock OpenAM for all applications.
  • Familiarity with Webservice Description Languages such as WSDL, XML, SOAP, REST and XSLT.
  • In-depth knowledge and experience with J2EE JACC, JAAS, JSSE, JCA and JCE, Kerberos GSS-API, Spring Security, Oauth 2.0, OpenIDConnect, SAML 2.0.
  • Setting up Load Balancing, Clustering, High Availability, separate RS Replication servers for ForgeRock newly built infrastruce.
  • Designed and deployed ForgeRock Open AM and OpenIDM to migrate from CA cloud minder
  • Containerized all the Ticketing related applications -SpringBoot Java and Node.Jsapplications using Docker.
  • Performing system monitoring, analyzing and documenting performance and conducting trend analyses as required.
  • We are driving towards continuous integration and continuous delivery using Jenkins and Ansible for docker image building and deployment.
  • Configuring ‘nginx’ for proxy RESTful API calls to micro-services in Docker containers
  • Being responsible for performance tuning, indexing, troubleshooting Replication and performance issues.
  • Performing routines and preventative maintenance such as health-checks, maintaining Back-ups,writing shell scripts, utilization monitoring and log file management
  • Implementing the Single Sign-On environment (SSO) in a mixed environment, which included Windows, and Linux environment.
  • Setting up, migrating, implementing and configuring CA Siteminder and Sun one Directory server for secure single sign-n solutions on multiple platforms.
  • Installed the CA SiteMinder R12.52 SP1 for Access and Federated Security Services that includes Configuring Admin UI, Configuring the Policy Server, policy store, key store
  • Installed OneView Monitor for monitoring the webagent and policy server components,configured the OneView Monitor settings in Siteminder management console
  • Installed CA report server and configured siteminder reports and audit server for reporting purposes
  • Good understanding of Openshift platform in managing Docker containers and Kubernetes Clusters
  • Experience in design microservices deployment using Docker and Kubernetes
  • Build and maintain the security infrastructure of siteminder, CA directory. Resolving production incidents to make sure all the protected applications are running and business runs without interruption.
  • Provide federation SSO services for various business applications which are accessed from within the network using SAML 2.0
  • Install and configure policy store and key store instances using CA directory,installing and registering admin UI
  • Incident, problem and change management is performed in the process of resolving incidents and executing new security enhancements in all the required environments.
  • Work with business stakeholders to gather necessary SSO requirements and implement the same using the security components.
  • Created Ansible Custom Modules and Roles to automate ISAM Appliance tasks. Custom Modules provide the interface to python idempotent functions in IBM Security Package.
  • Worked with a repository like SVN and GIT
  • Planned and excuted the applications migration from Dev to prod accordingly.
  • Provided the oncall support as required by the team.

Environment: CA SiteMinder R12.5,R12.52 SP1, CA Directory R12 SP10, IIS 7, Apache 2.2, Docker, SSO, ForgeRock, OPENAM, LDAP, SAML 2.0, Windows Server 2008, Spring, Jenkins, Java, Solaris 10, RHEL 5.

Confidential

IAM Consultant

Responsibilities:

  • Install and configure Siteminder Federation security services on Jboss and Tomcat servers on various platforms.
  • Configure applications with ADFS where Siteminder acting as Service Provider and ADFS acting as Identity Provider using SAML 2.0 in IDP initiated method.
  • Configure applications with ADFS where Siteminder acting as Resource Partner and ADFS acting as Account Partner using WS-Federation.
  • Installed and configured the Ping federate 6.x
  • Created various connections both IDP and SP using the ping federate.
  • Developing scripts for build, deployment, maintenance and related tasks using Jenkins, Docker, Maven, Python and Bash.
  • Upgraded the ping federate engine from 6.x to 7.x
  • Utilized IAM protocols such as SAML, Oauth, OpenID
  • Involved in troubleshooting different Federation issues using the log files and supported day to day tasks accordingly.
  • Expertise in integrating and protecting web applications and other resources with Siteminder Policy Server and its components.
  • Defining the Realms, Rules, Responses, setting up response attributes as Cookie variables or HTTP variables, Defining User directories, Policies, configure them to the given set of user DNs.
  • Good understanding of Openshift platform in managing Docker containers and Kubernetes Clusters
  • Experience in design microservices deployment using Docker and Kubernetes
  • Proactively engaged in migration of directory server from Sun DS 5.2 to directory server 6.x
  • Configure different applications where siteminder is IDP & Ping Federate as SP using SAML 2.0 Post methods.
  • ConfigureOracle HTTPserver 11g andOracle Web gate11g to secure URLs.
  • Involved in writing the scripts like backup, replication monitoring and configuration statistics directory server 6.x.
  • Extended schema updates and access control items (ACI)
  • Using Siteminder SDK, created an Assertion Generator Plugin which will take query parameters, insert them to SAML Assertion as per business requirements.
  • Can design and document the first level support to be given to help desk team to improve efficiency
  • End to end Architecture designing and implementation of Sun Directory Services.
  • Gather requirements to complete successful installation and configuration of Siteminder SharePoint SP3 agent Siteminder R12 on Windows.
  • Troubleshooting issues and worked with CA to resolve them.
  • Troubleshooting day-to-day issues on LDAP servers and monitoring replication problems.

Environment: Siteminderpolicy server 6.0/R12.x, Siteminder Web agent 6x/R12.x, Sun ONE Directory Server 5.x/6.x, CA Directory Server R12, Ping Federate6.x/7.x, Oracle, Jboss 4.x, Python, Jenkins, Maven, Tomcat 6x, windows 2003/2008, IIS 6.0/IIS 7.0 Web servers, Web Sphere 6.1/7.0, Red Hat 4/5, AIX 6.1

Confidential

IAM Consultant

Responsibilities:

  • Successful migration of Siteminder v6 sp5 to Siteminder R12 Sp2 on Windows 2003/2008 environment.
  • Designed and architected Siteminder R12 solution as per Company requirements.
  • Upgraded federated solution from v6sp5 to r12 sp2.Installed and configured SAML Affiliate agent at the consumer side on Windows environment.
  • Installed and configured the Wily Introscope monitoring solution.
  • Strong knowledge on deploying Siteminder Federation Web Services on JBoss 4.0.5 and Web Sphere 6.1.
  • Successful upgrade of Siteminder Web agent’s from 6qmr5 cr22 to R12 SP2 in all environments.
  • Manually Extended R12 Policy store schema on Sun One Directory server.
  • Configured the Replication for user directories on Sun One LDAP servers.
  • Revised LDAP directory and security architecture for J2EE applications
  • Completed Performance testing with positive results after Siteminder R12 upgrade.
  • Identified defect on Wily Introscope for Siteminder and reported CA about it.
  • Achieved Siteminder R12 from CA.
  • Worked on JavaScript Object Notation (JSON), modified and updated language as per the infrastructure requirement.
  • Configured mixed-mode replication between directory server 5.x and 6.x
  • Designed and analyzed migration plan for Sun One Directory (LDAP) from 5.x to 6.x
  • Worked with app teams to coordinate Siteminder upgrades in time.
  • Worked with Sun in resolving the replication and high CPU issues after upgrading to directory server 6.x
  • Worked on a proof of concept to show Siteminder Report server and Administrative UI to the business.

Environment: Siteminderpolicy server 6.0/R12, Siteminder Web agent R12/6x, Wily Introscope Monitor 12X, Sun ONE Directory Server 5.x/6.x, Java, windows 2003/2008, IIS 6.0/IIS 7.0 Web servers, Web Sphere 6.1/7.0, Red Hat 4/5, AIX 6.1

Confidential

Siteminder Developer

Responsibilities:

  • Create Siteminder Active Expressions as required for the company business logic.
  • Create Siteminder Authorization API (Active policy) to authorize the user with custom business logic.
  • Involved in configuring mixed mode replication between directory server 5.x and 6.x.
  • Create Siteminder Authorization APIs (Active Response, Active Rule) to work as per the custom requirement.
  • Create Perl Scripts by using Perl Policy Management Api to modify the policy store with the new active expressions developed.
  • Installed and configured Siteminder User Context Gateway on policy server and IIS web server to work with pc based applications.
  • Configured User Context Gateway to provide Single Sign on with PC based applications like Citrix.
  • Worked in setting up synchronization between Sun LDAP and Microsoft Active directory using ISW 6.x
  • Involved in setting up password policies and ACIS in directory server 5.x according to requirement.
  • Deployed and configured Directory Server 5.x as User Store and Policy Store in different environments.
  • Involved in designing the directory server architecture according to requirement.
  • Create the Perl scripts to export the policy objects as per the requirement.
  • Working on .net pages to route Siteminder target using Custom Authentication.
  • Helped in documenting the procedure for migration and replication of directory server
  • Configured the Replication for user directories on Sun One LDAP servers.
  • Troubleshooting login, Authorization problems using Trace Files in 6.0 or (Log files in 4.51/6) and solve them on timely basis.
  • Installing the Siteminder web agent on the web server side as per required and verify trusted host is created properly.
  • Developed some scripts for checking the performance in directory server 5.x/6.x
  • Troubleshooting the directory server replication and high CPU issues in User Store.
  • Troubleshooting the Siteminder issues and working with CA to resolve the issues.

Environment: Solaris 8/10, Sun Directory Server 5.x, Windows 2000/2003, Netegrity Siteminder 5.5 / 6.0, Sun web server 6.x, Active Directory, Apache web server 1.3.1/2,0 IIS 5.0/6.0 web servers.

We'd love your feedback!