Senior Access Management Engineer - Duo / MFA Specialist (Remote in the U.S.)
GuidePoint Security · Remote
📍 Remotevia greenhousePosted 2026-09-17
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to GuidePoint Security.
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.
General Description
GuidePoint Security is hiring a Senior Access Management Engineer specializing in Cisco Duo to join our implementation team on a full-time basis. This is a fully remote role where we are looking for deep, hands-on experience leading Duo Security deployments, migrations, and integrations — with secondary proficiency in Okta and/or Ping Identity platforms to support broader Access Management engagements.
The Senior Access Management Engineer is responsible for designing, deploying, integrating, and optimizing Duo MFA and access solutions for some of the largest organizations in the US. This role serves as the go-to technical lead for all Duo engagements, owning architecture decisions, integration design, and delivery execution. When Duo engagements are not fully utilizing capacity, this resource will flex into a supporting engineer role on Okta and Ping Identity projects, contributing hands-on technical work under the direction of the engagement's lead architect.
This role sits at the intersection of security, infrastructure, and application integration — ensuring that multi-factor authentication, device trust, and adaptive access policies are implemented securely, reliably, and at scale.
About the Access Management practice
Coming to the Access Management team means working on the leading edge in the IAM space. As a Senior Access Management Engineer, you will be partnering with other engineers and architects to help some of the largest companies in the US implement their own identity and access management programs. From participating in assessments to full delivery of IAM platforms, you can expect to be involved at all levels of interaction with our customers. Your leadership and expertise are critical to providing our customers with the guidance they need, and the excellence they expect from GuidePoint Security.
We partner with the largest vendors in the space to ensure that the latest training is always available to our team. High level communication and collaboration are the standard. Mentorship at all levels, from Senior Architects to Junior Engineers, is foundational to our culture. We don't just talk about work life balance; we facilitate it with a flexible time off (FTO) benefit.
We understand that in order to retain our talented team, leadership must provide regular feedback and coaching. We recruit new members to the team with the understanding that opportunities for growth are important. Whether your goals include future leadership opportunities, becoming an Architect or even moving to another discipline within security in time, the leadership team is focused on partnering with you to help achieve them.
Roles and Responsibilities:
Duo Security – Lead Engineer (Primary – 50%)
Serve as the primary technical lead on all Duo Security engagements, owning end-to-end delivery from design through implementation and handoff
Lead Duo deployment architecture and design, including:
Duo MFA — Policy design, user enrollment strategies, self-service portal configuration, and phased rollout planning
Duo Authentication Proxy — Deployment, configuration, high availability, and integration with RADIUS, LDAP, and Active Directory
Duo Single Sign-On (SSO) — SAML 2.0 and OIDC federation, application onboarding, and custom login branding
Duo Device Trust — Trusted endpoint policies, certificate-based device verification, and managed/unmanaged device posture enforcement
Duo Network Gateway (DNG) — Clientless remote access to internal web applications and SSH/RDP resources
Duo Admin Panel & API — Tenant configuration, Admin API and Auth API integrations, custom scripting, and reporting
Duo Trusted Endpoints — Integration with endpoint management platforms (Intune, Jamf, Workspace ONE, etc.)
Duo Desktop (formerly Duo Device Health) — Endpoint health verification and posture-based access policies
Design and implement Duo integrations across a wide range of application and infrastructure types, including:
VPN concentrators (Cisco ASA, Palo Alto GlobalProtect, Fortinet, Pulse/Ivanti)
Remote access platforms (Citrix, VMware Horizon, RD Gateway/NPS)
Web applications via SAML/OIDC federation or Duo Web SDK
Cloud platforms (AWS, Azure, GCP) for console and CLI MFA
On-premises infrastructure (Windows RDP, SSH, local OS logon)
Custom and legacy applications via Duo Auth API and Web SDK
Plan and execute Duo-to-Duo migrations (e.g., tenant consolidation) and competitive migrations from Duo to Okta, Duo to Entra ID, or other MFA platforms
Develop automation scripts (Python, PowerShell, Bash) leveraging Duo Admin API for bulk operations, reporting, user lifecycle management, and integration testing
Design phased MFA rollout strategies with user communication plans, pilot groups, and exception handling workflows
Conduct security reviews of Duo configurations, identifying gaps in policy coverage, authentication bypass risks, and device trust enforcement
Develop and maintain technical documentation, architecture diagrams, integration runbooks, and client-facing knowledge transfer materials
Okta & Ping Identity – Supporting Engineer (Secondary – 35%)
Serve as a supporting engineer on Okta and Ping Identity engagements when Duo workload permits, working under the direction of the engagement's lead architect
Contribute hands-on technical work on Okta engagements, including:
Application integration (SAML, OIDC, SWA) and SSO configuration
MFA policy configuration and adaptive acce
More Remote jobs
Remote jobs · Browse all locations