Identity Access Management Consultant - Senior
Summary
Join Ontario Health as a Senior Oracle 12C IAM Consultant to lead the upgrade of its ONEID service—Ontario’s secure identity solution for accessing patient health information. This hybrid role focuses on designing and implementing high-availability architectures using Oracle Access Manager (OAM), Oracle Unified Directory (OUD), and related IAM technologies. You’ll bring 12+ years of expertise in Oracle IAM (11G/12C), strong integration skills across OAM, OIM, OUD/OVD, and Microsoft AD, and experience deploying on Red Hat OpenShift. Ideal for a seasoned architect with hands-on experience, deep security protocol knowledge (SAML, OAuth, PKI), and strong documentation and collaboration skills.
Description
Background Information

Ontario Health’s ONEID service is a secure identity solution leveraged by the Ministry of Health and Long-Term Care and numerous health care organizations in Ontario for purposes of accessing patient health information (PHI). The ONEID service enhances protection of PHI and user account information through privacy and security safeguards while providing access to multiple digital health services using the same login credentials.

The ONE ID service is based on Oracle 12C Identity Access Management suite including Oracle Access Manager (OAM), Oracle Unified Directory (OUD), Oracle Identity Management (OIM), Oracle database, Microsoft Active Directory, and other Ontario Health custom systems. As such, Ontario Health requires Oracle Access Manager (OAM) and Oracle Unified Directory (OUD) experts to help resolve and navigate challenges in configuring and setting up the new 12C OAM and OUD to establish interoperability with the existing 10G based ONE ID and provide a smooth transition to the upgraded our current 10G/11G systems including Oracle Identity Manager (OIM) and Oracle Virtual Directory (OVD) to the full Oracle 12C IAM suite.

Deliverables:

The purpose of this procurement is to procure one (1) Senior Oracle 12C IAM Consultant required to perform the role of OAM/OUD Specialist – ISM Technical Consultant within a dedicated team for the ONEID Oracle 12c Upgrade.

Must haves:

·      Minimum 12 years’ experience as a solution architect on Oracle Identity Access Management systems, 11G and 12C, who has successfully modeled and implemented end-to-end solutions and infrastructure.

·      Minimum 3 years solution development with 12C Oracle Access Manager (OAM) and 12C Oracle Unified Directory (OUD).

·      Minimum 7 years in setting up 11G and 12C OAM and OUD in active-active multi-data center configuration and set-up.

·      Minimum 7 years integration experience in Oracle IAM suite including OAM, OIM, OUD/OVD, Oracle HTTP Server (OHS), Microsoft AD, and Oracle databases.

·      Over 10 years of experience in tuning Oracle IAM suites to work efficiently with high availability to work on WebLogic and Linux.

·      Must be associated with a recognized Gold Oracle IAM Partner.

·      Must be at expert level in Security Assertion Mark-up Language, SMAL 2.0, and OAuth 2.0.

·      Must know TLS/SSL and Public key Infrastructure (PKI) on Single Sign-On (SSO).

·      Experience translating conceptual to logical to physical application architecture in alignment with business and architecture.

·      Able to articulate technical issues and provide options to resolve them clearly and concisely.

·      Able to produce clear and concise documentation including design/architecture documents, deployment and integration guides, and physical application design documents.

Responsibilities:

·      Work with Ontario Health (OH) teams in design and development to improve the availability of ONE ID service

·      Work with Ontario Health (OH) teams to integrate logging and monitoring into an actionable process to improve availability and fault-tolerance

·      Document the final design, installation, configuration, and integration procedures for improved availability

·      Work collaboratively with other Ontario Health teams such as database, networking, and infrastructure.

·      Provide weekly updates to team leads and project manager.

Desired Skills:

·      Experience with Oracle and Identity and Access Management Suite Plus and Microsoft Active Directory Suite

·      Knowledge of general IAM best practises

·      Experience integrating business applications with Oracle IAM and Microsoft Active Directory Suite

·      Experience triaging, analyzing, diagnosing (trouble-shooting), evaluating options, and resolving application problems, especially those related to identity and access management systems

·      Experience with developing user identity, service creation and enrolments with Oracle Identity Manager (OIM) and Governance (OIG).

·      Knowledge of IT security technologies particularly encryption and authentication technologies such as PKI, PKI, and TLS/SSL

·      Excellent organizational skills, verbal and written communication skills, team working skills

·      Experience with monitoring tools e.g. Oracle Enterprise Manager , IBM Tivoli

·      Experience in working with Agile development and CI/CD pipelines

·      Knowledge of JIRA and Confluence

·      Experience with Red Hat Openshift

Required Experience / Evaluation Criteria:  

Minimum 10 years’ experience as a solution Architect on Oracle Identity Access Management systems, 11G and 12C, who has successfully modeled and implemented end-to-end solutions and infrastructure.: 25 Points

Minimum 3 years solution development with 12C, and overall 7+ years with 11G Oracle Access Manager (OAM) and 12C Oracle Unified Directory in active-active multi-data center configuration and set-up to achieve high-availability and high performance.: 25 Points

Must be associated with a recognized Gold Oracle IAM Partner for over 5 years.: 20 Points

Must know deployment of Oracle 12C OAM and OUD on Red Hat Openshift.: 20 Points

Development experience in high-availability architecture.: 10 Points

Total Capabilities Evaluation Criteria: 100 Points

Deliverables
Deliverables include, but are not limited to:

·      Architecture of ONE ID based on Oracle 12C IAM including OIM, OAM, OUD, OHS, OAAM, EAS and 19C Oracle database in multiple environments, especially pre-production and production environments for high availability.

·      Identify all other systems on which the 12C ONE ID is depending.

·      Identity the teams responsible for ONE ID’s dependent systems, managers and primes.

·      Examine current logging and monitoring of end-to-end ONE ID 12C systems

·      Develop an actionable plan and procedures to improve the availability of ONE ID 12C systems.

·      All design and implementation documents for the above tasks.

Additional Terms
Term: The term of this position is 102 Business Days. The resource will comply with Ontario Health policies and procedures. Ontario Health assets including laptops and related equipment cannot be removed from the province of Ontario without prior written approval from Ontario Health.

Assignment Type: This position is currently listed as "Hybrid". The resource under this request will be required to work onsite as per Hiring Manager sole discretion.

Knowledge Transfer Details:

·      The resource will ensure full knowledge transfer is provided to the Ontario Health team before end of engagement. Some of this might occur at the end of the engagement but will also be shared as information is obtained/consolidated. Key deliverables will be shared with team.

·      The resource must provide all related documentation as part of Knowledge transfer protocol. Documents will be reviewed by the appropriate leads and signed off by manager/director.

·      The resource will work collaboratively with the Ontario Health team throughout the assignment and ensure key deliverables, milestones, and documentation are shared.

·      A walkthrough of any demos, development, etc. will be required before the end of the engagement.

Must Haves:

·         ·      Minimum 12 years’ experience as a solution architect on Oracle Identity Access Management systems, 11G and 12C, who has successfully modeled and implemented end-to-end solutions and infrastructure.

·         ·      Minimum 3 years solution development with 12C Oracle Access Manager (OAM) and 12C Oracle Unified Directory (OUD).

·         ·      Minimum 7 years in setting up 11G and 12C OAM and OUD in active-active multi-data center configuration and set-up.

·         ·      Minimum 7 years integration experience in Oracle IAM suite including OAM, OIM, OUD/OVD, Oracle HTTP Server (OHS), Microsoft AD, and Oracle

Location: Fully remote

Public Sector Experience: No