IAM Engineer
Role details
Job location
Tech stack
Job description
A large technology R&D client is seeking a hands-on IAM Engineer Contractor to support an enterprise identity modernization initiative. The primary focus of this engagement is to perform a baseline IAM assessment, clean up stale and risky access, rationalize conditional access policies, and develop a practical RBAC model aligned to least-privilege principles.
This role is best suited for an engineer with strong Microsoft Entra ID / Azure AD, Active Directory, conditional access, identity lifecycle, and access governance experience. Familiarity with privileged access management concepts, including CyberArk PAM and Bitwarden, is preferred.
Key Responsibilities
-
Perform a baseline IAM assessment across users, groups, service accounts, shared accounts, privileged accounts, and application access.
-
Identify stale, orphaned, inactive, duplicate, excessive, or misconfigured accounts and access assignments.
-
Support cleanup and remediation of stale users, groups, service accounts, privileged accounts, and access policies.
-
Review conditional access policies for gaps, overlap, conflicts, stale exceptions, and excessive complexity.
-
Recommend improvements for MFA enforcement, privileged access protection, device posture, location-based access, and exception handling.
-
Analyze existing groups, roles, permissions, and access patterns to support RBAC model development.
-
Define practical roles based on job function, department, application access, infrastructure access, and privilege level.
-
Align privileged account handling with CyberArk PAM and Bitwarden standards where applicable.
-
Produce documentation, cleanup trackers, role catalogs, policy recommendations, and operational procedures.
-
Partner with security, infrastructure, application, and business teams to validate access changes and support remediation.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Requirements
Hands-on IAM engineering experience in enterprise environments.
-
Strong experience with Microsoft Entra ID / Azure AD and Active Directory.
-
Experience with enterprise password vaulting solutions
-
Understanding of IAM lifecycle processes, including joiner, mover, leaver, provisioning, deprovisioning, and access review.
-
Practical experience with RBAC design, group rationalization, entitlement mapping, and least-privilege access.
-
Familiarity with MFA, privileged access management, service accounts, shared accounts, and break-glass account controls. - Experience with CyberArk PAM or similar privileged access management platforms.
-
Experience with Bitwarden Enterprise or other enterprise password vaulting solutions.
-
Familiarity with IGA platforms, access certification, and HR-driven identity lifecycle processes.
-
Experience with Workday-to-IAM or Workday-to-IGA integrations.
-
Knowledge of SAML, OAuth/OIDC, SCIM, REST APIs, and SaaS application access integration.
-
Experience supporting audit, compliance, and access governance activities.
-
Relevant IAM, Microsoft, CyberArk, or security certifications