APPLICATION ADMINISTRATOR-LEAD- 09222026- 81070
LOCATION OF (1) POSITION(S) TO BE FILLED: DEPARTMENT OF FINANCE AND ADMINISTRATION, DAVIDSON COUNTY
This position requires a criminal background check and CJIS/FTI Fingerprints. Therefore, you may be required to provide information about your criminal history in order to be considered for this position.
This position is designed as Hybrid (In office and Remote).
The Department of Finance & Administration does not sponsor applicants for work visas.
Qualifications
Education and Experience: Bachelor's degree and five years of relevant experience in system administration, infrastructure, or application support. Associate degree with equivalent experience may be substituted. Graduate coursework may replace up to two years of experience.
Overview
The Application Administrator Lead for Identity and Access Management (IAM) supports the Tennessee Department of Human Services (DHS) within the Strategic Technology Solutions (STS) organization. The position serves as the internal administrator and technical lead for the DHS Ping/ForgeRock IAM platform and works with application owners, cybersecurity teams, Active Directory, agency teams and vendor partners.
The primary focus is to maintain reliable and secure IAM platform services, coordinate application integrations, and provide internal oversight of changes, upgrades, patches, releases, incidents, and vendor work. The role supports access certifications and identity lifecycle controls, including onboarding, role changes, and timely offboarding, while helping reduce excessive or accumulated access.
This is a platform administration and governance role rather than a front-line access-request processing position. The successful candidate must be able to evaluate technical changes, troubleshoot complex issues, document the environment, communicate clearly with technical and business partners, and transfer platform knowledge from vendors to DHS staff.
Responsibilities
PRINCIPAL DUTIES AND RESPONSIBILITIES
- Administer and provide internal technical ownership of the DHS Ping/ForgeRock IAM platform, including platform configuration, availability, performance, security, and lifecycle planning.
- Coordinate and review IAM platform changes, upgrades, patches, releases, and maintenance activities; assess dependencies, test results, implementation plans, rollback plans, and operational readiness.
- Serve as the primary internal contact for IAM platform outages, service interruptions, and escalations; coordinate diagnosis, communications, restoration, root-cause review, and corrective actions.
- Coordinate integrations between Ping/ForgeRock and agency applications, Active Directory, ServiceNow, human-resources data, portals, and other connected systems.
- Partner with application owners and technical teams to define authentication, authorization, federation, single sign-on, provisioning, and deprovisioning requirements.
- Support identity lifecycle processes for new hires, transfers, role changes, separations, and urgent terminations, and help verify that access is granted, changed, and removed accurately and on time.
- Coordinate periodic access certifications and work with business and application owners to identify and remove inappropriate, excessive, conflicting, or accumulated access.
- Monitor platform health, logs, scheduled processes, integrations, and service measures; identify trends and coordinate resolution before issues affect agency operations.
- Validate vendor configuration, maintenance, troubleshooting, and integration work; review deliverables, track commitments, and confirm that changes meet DHS requirements and standards.
- Lead structured knowledge transfer from vendor personnel to DHS staff and develop the internal capability needed to assume appropriate platform responsibilities over time.
- Create and maintain platform architecture records, configuration documentation, integration inventories, runbooks, support procedures, test evidence, change records, and recovery information.
- Support audit and compliance activities by producing accurate access, change, configuration, incident, and control evidence and by coordinating remediation of identified gaps.
- Apply least privilege, separation of duties, secure configuration, and other IAM and cybersecurity requirements in coordination with agency and enterprise security partners.
- Plan and execute testing for platform changes and integrations, including functional, regression, security, and failover testing, and document results and approvals.
- Track and report operational measures such as change volume and success, incidents, escalation resolution time, access-review completion, documentation progress, vendor workload, and responsibilities transitioned to DHS.
SKILLS
- Working knowledge of IAM concepts and controls, including authentication, authorization, federation, single sign-on, identity lifecycle management, access certification, least privilege, separation of duties, and timely deprovisioning.
- Ability to administer and troubleshoot enterprise IAM platforms and connected services in a production environment.
- Understanding of common identity technologies and protocols, such as SAML, OAuth 2.0, OpenID Connect, LDAP, REST APIs, directories, and certificates.
- Ability to evaluate technical changes, dependencies, test evidence, implementation plans, and rollback plans and to coordinate safe production releases.
- Strong incident analysis and problem-solving skills, including the ability to interpret logs, isolate integration failures, coordinate escalation, and verify resolution.
- Ability to translate business access requirements into practical IAM configurations and integration requirements while maintaining security and compliance controls.
- Strong vendor-management and quality-review skills, including the ability to validate work, document expectations, track commitments, and lead knowledge transfer.
- Strong technical writing and organizational skills for architecture records, integration inventories, runbooks, procedures, change records, test evidence, and audit documentation.
- Clear written and verbal communication, facilitation, and relationship-building skills with technical teams, application owners, business partners, auditors, and vendors.
- Sound judgment, attention to detail, discretion with sensitive information, and the ability to manage concurrent operational work, projects, incidents, and deadlines.
Competencies (KSA's)
Competencies:
- Business Insight
- Decision Quality
- Self-Development
- Customer Focus
- Instills Trust
Knowledges:
- Reliability Engineering & Automation
- Incident Response & Root Cause Analysis
- Performance Tuning & Scalability
- Infrastructure as Code (IaC)
- Operational Excellence
Skills:
- Observability (Metrics, Logging, Tracing)
- Communication & Cross-Team Collaboration
- Security & Compliance Awareness
Abilities:
- Perseverance
- Logical Thought
Tools & Equipment
- Observability platforms (Datadog, Prometheus)