Dallas (hybrid) role with a strong focus on identity assurance and passwordless access. EY offers a comprehensive compensation and benefits package, including medical and dental coverage, pension and 401(k) plans, and paid time off with a flexible approach to vacation. Most client-serving teams follow a team-led, leader-enabled hybrid model working together 40-60% of the time in person over the course of an engagement, project, or year. Additional time off may include designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence.
This Senior Identity Verification Engineer position builds and supports identity verification and passwordless solutions using 1Kosmos or Microsoft Verified ID. The work spans identity proofing, biometric and liveness verification, verifiable credentials, and enterprise IAM integrations.
Responsibilities
- Design and implement identity proofing workflows using 1Kosmos or Microsoft Verified ID.
- Configure and support document verification, biometric authentication, facial recognition, liveness detection, and identity assurance controls.
- Implement IAL2-grade identity proofing processes aligned with NIST 800-63.
- Support onboarding journeys for employees, contractors, vendors, and privileged users.
- Configure and administer 1Kosmos BlockID and associated services.
- Manage user enrollment, credential issuance, identity verification policies, and authentication workflows.
- Integrate and orchestrate biometrics verification using IdRamp and CLEAR with Microsoft Entra.
- Monitor platform health, performance, and operational effectiveness.
- Troubleshoot identity verification and authentication issues.
- Deliver and maintain integrations across Microsoft Entra ID / Azure AD, Active Directory, and platforms including SailPoint, Saviynt, ISIM/ISVG, Ping, and Okta.
- Integrate 1Kosmos with ServiceNow (ITSM), and connect to AWS, Citrix, VMware Horizon, and VDI environments.
- Integrate 1Kosmos with HR and workforce onboarding systems and develop API-based integrations for identity verification and identity lifecycle workflows.
- Configure SAML, OAuth, OIDC, and SCIM integrations.
- Implement passwordless authentication strategies including biometrics, mobile authenticators, FIDO2/WebAuthn, QR code authentication, and push-based authentication.
- Support enterprise migration initiatives from traditional authentication to passwordless access.
- Ensure solutions meet organizational security requirements and industry standards, and support audit and compliance activities.
- Develop security documentation, operational runbooks, and implementation standards; participate in architecture reviews and design workshops.
- Support POCs, pilot deployments, production rollouts, and hypercare; collaborate with IAM architects, cybersecurity teams, application owners, and business stakeholders.
Requirements
- Bachelorβs degree in Computer Science, Information Security, Information Systems, or related field.
- 3-5+ years of experience in Identity and Access Management (IAM).
- 2+ years hands-on implementation experience with 1Kosmos or Microsoft Verified ID.
- Experience implementing identity proofing, passwordless authentication, and biometric verification solutions.
- Experience with enterprise identity lifecycle management and user onboarding processes.
- Hands-on platform and standards exposure, including 1Kosmos BlockID, Microsoft Verified ID, IdRamp, CLEAR, Entra ID / Azure AD, and Active Directory.
- Working knowledge of SAML, OIDC, OAuth 2.0, SCIM, and REST APIs and integration frameworks.
Key Success Metrics
- Successful deployment of identity verification and passwordless authentication solutions.
- Reduction in account takeover and impersonation risks.
- Improved onboarding user experience.
- High identity proofing completion rates.
- Compliance with security and regulatory requirements.
- Stable and scalable enterprise integrations.
Technologies
- 1Kosmos, Microsoft Verified ID Identity Platform, 1Kosmos BlockID, Microsoft Entra Verified ID
- Microsoft Entra ID / Azure AD, IdRamp, CLEAR, Active Directory
- SailPoint, Saviynt, ISIM/ISVG, Ping, Okta, ServiceNow
- AWS, Citrix, VMware Horizon, VDI, REST APIs
- NIST 800-63, Biometrics, Liveness Detection, FIDO2/WebAuthn
- QR code authentication, Push-based authentication, Verifiable Credentials (VCs), Decentralized Identity (DID)
- Microsoft Identity & Access Administrator, CIAM, CISSP, Certified Identity and Access Manager (CIAM)
Preferred Qualifications
- Experience with SailPoint ISC, IdentityIQ, Saviynt, Ping Identity, or Okta.
- Knowledge of Verifiable Credentials (VCs), Decentralized Identity (DID), and Microsoft Entra Verified ID.
- Experience supporting large-scale workforce or contractor onboarding programs.
- Familiarity with NIST Digital Identity Guidelines (800-63).
- Knowledge of cloud environments including Azure and AWS.
- Relevant certifications, including CIAM, CISSP, Microsoft Identity & Access Administrator, and IAM security certifications.
Location: Dallas, TX (hybrid); Anywhere in Country
Salary: Competitive. Base salary range for this job in all geographic locations in the US is $104,800 to $192,200. Base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $125,800 to $218,500.
Requisition ID: 1724862
Date: Aug 7, 2026
Minimum Experience: 2 years