Identity and Access Management Engineer
Role details
Job location
Tech stack
Job description
We are looking for an engineer who is forward thinking, automation driven, and passionate about leveraging modern identity technologies.This role is responsible for engineering, enhancing, and supporting Identity and Access Management capabilities with a focus on Entra ID, Active Directory, application integrations, Identity Provider (IdP) technologies, and Zero Trust authentication models. Collaborate with parent company stakeholders on aligning processes, standards, and technology strategies while supporting multiple regional companies., * Engineer and support enterprise identity solutions across Entra ID, Active Directory, SSO, and federated identity platforms
- Design and maintain policies for MFA, Conditional Access, workload identities, and modern authentication protocols.
- Identify opportunities for automation and help evolve an "automate first" engineering culture.
- Lead complex problem resolution and support escalations requiring deep IAM expertise.
- Document architecture, decisions, playbooks, and engineering patterns.
- Collaborate in agile teams and mentor engineers on identity engineering best practices.
- Migration of acquired companies to Entra and Office 365.
- Maintain and govern privileged access and administrative roles across identity platforms.
- Support legacy identity processes while contributing to their transition toward modern identity solutions.
- Partner with cross functional teams to support and secure Office 365 applications including Teams and Exchange.
- Asses and monitor application permissions.
Requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems or equivalent work experience in the IT field.
- Minimum five years' experience in Information Security and/or Identity Access Management positions
- Experience with engineering best practices to include analyzing, designing, developing, deploying, and supporting software solutions and infrastructure implementations/upgrades.
- Strong experience in the following domains: Privileged Access, SSO/IdP integrations, Identity lifecycle automation, Active Directory, Entra ID, Conditional Access, Azure, AWS
- Hands-on experience with scripting/automation (PowerShell and/or Python).
- Strong problem-solving skills.
- Strong documentation, testing and automation skills.
- Strong sense of ownership and the ability to work with a limited set of requirements.
- Ability to explain technical solutions to technical teams and non-technical teams.
- Strong ability to align and mature to security practices.
- Strong ability to align technical needs to business processes.
- Strong ability to prioritize work based on business objectives.
- Knowledge and understanding of CIS, NIST, ISO27K and SOC-2 information security standards.
- Strong understanding of security fundamentals and general security technologies
- Relevant industry certifications such as CISSP, Microsoft Certified: Identity and Access Administrator Associate (SC-300), Certified Identity and Access Manager (CIAM) and Certified Access Management Specialist (CAMS) a plus.
Benefits & conditions
At Komatsu, your base pay is one part of your total compensation package. This role pays $99,300-124,100. The actual offer will consider a wide range of factors, including experience and location.
Company Benefits
Komatsu provides an extensive and robust employee benefits package that is designed to enhance the well-being of our employees and family members. We embrace a positive and empowering employee experience with a culture that prides itself on a diverse and inclusive environment.
- Health benefits: Medical, dental, vision, HSA, wellness programs, etc.
- 401k and/or employee savings programs
- Employee time off (vacation and designated holidays)
- Employee and family assistance programs
- Disability benefits
- Life insurance
- Employee learning and development programs