Consultant PositionRequired consultant experience provided by Contractor, shall include:Experience Checkpoint firewallsExperience EXOSExperience in managing WUGExperience in DynatraceExperience CSAB orderingKnowledge of ITSMKnowledge of NISTExperience with B2C implementation in government settingExperience with Microsoft Office 365 and Outlook administrationExperience with Hyper-v and VMWare systemsExperience with cloud technologies – Azure, AWSKnowledge of general networking infrastructure technologiesKnowledge of the Information Technology Infrastructure Library (ITIL)Knowledge of Okta, Ping, Azure AD, OAuth, OpenID Connect (OIDC), SAML, Header-based authentication, LDAP, SCIM technologiesWorking in a project-oriented environmentExcellent troubleshooting skillsExcellent interpersonal and communication skillsDetail-oriented, ability to switch tasks, ability to self-direct and prioritize tasksResearching and investigating problems and developing viable solutions; reporting findings/recommendations clearly and effectivelyKnowledge of MS Office SuitePreferred Experience:Five years’ experience in architect and design of Always on VPN solutionsFive years’ experience in designing network topologyFive years’ experience in design and implementation firewall solutionsFive years’ experience in proxy (forward and reverse) designFive years’ experience in configure and management of Windows Server roles and features required for VPN functionality, such as Routing and Remote Access Services (RRAS), Network Policy Server (NPS), and Active Directory Certificate Services (AD CS)Five Years’ experience in User Identity ManagementFive years’ experience in implementing multi-factor authentication (MFA)Five years’ experience in implementing Single Sign-On (SSO)Seven years of experience with Microsoft server administrationFive years of experience with Microsoft Active DirectoryThree years of experience with Okta, Ping, Azure AD, OAuth, OpenID Connect (OIDC), SAML, Header-based authentication, LDAP, SCIM, or other relevant technologiesFive years’ experience Integrating IAM systems with various applications and platformsEnabling secure user authentication and access across multiple domainsExperience with implementing SAP authentication and authorizationExperience in enforcing least privilegeExperience with Directory ServiceExperience with Privileged Access Management (PAM)Experience automating user onboarding and offboarding processesExperience ensuring timely removal of access for departing employees or contractorsExperience in configuring VPN client settings on various devices and platforms, including Windows PCs, mobile devices, and remote laptops, ensuring seamless and secure connectionsRequired Duties and Responsibilities of Consultant shall include but are not limited to:Collaborate with stakeholders to understand business requirements for remote access.Design the architecture, topology, and components of the Always On VPN solution.Define the server placement, load balancing, and redundancy strategy.Set up and configure the necessary VPN servers and infrastructure.Implement Public Key Infrastructure (PKI) for server and client certificates.Configure VPN profiles and policies for different user groups and devices.Implement strong authentication methods, including multi-factor authentication (MFA).Ensure compliance with security protocols and encryption standards.Monitor and mitigate potential security vulnerabilities.Document the entire VPN architecture, configuration settings, and procedures.Create user guides and training materials for employees and IT staff.Provide training sessions to educate users on connecting to the VPN.Architect and implement an end-to-end B2C strategy. All application dependencies shall be included in the strategy. All services shall be included in the strategy, considering all user flows.
All federal and state statutes must be followed. Single sign on and MFA will be required.