> Markdown version of [/jobs/ext/1239779-iam-engineer](https://www.wearedevelopers.com/jobs/ext/1239779-iam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Engineer - **Company:** iManage LLC - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $90,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Application Programming Interfaces (APIs), Systems Engineering, Audit Trail, Bash Shell, Software as a Service, System Configuration, Dynamic Host Configuration Protocol, Domain Name System (DNS), Identity and Access Management, Virtual Private Networks (VPN), Python (Programming Language), Network Architecture, OAuth, OpenID, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), TCP/IP, User Provisioning Software, Computer Network Technologies, Cyberark, Firewalls (Computer Science), Ceridian Dayforce, Microsoft Sentinel, Graphql - **Published:** July 11, 2026 - **Apply:** https://www.careerjet.com/job/us68cc81944080d1cc85e919f27abab3aa/eaa ## About the Role * 5+ years of experience in infrastructure or systems engineering with a primary focus on identity and access management. * Deep hands-on expertise with Microsoft Entra ID including conditional access, PIM, Identity Protection, entitlement management, and access reviews. * Demonstrated experience designing and maintaining SSO integrations for SaaS applications using SAML 2.0, OAuth 2.0, OIDC, and SCIM. * Strong scripting capability for IAM automation using PowerShell and Microsoft Graph API; Python or Bash a plus. * Working knowledge of PAM concepts and tooling; experience with CyberArk preferred. * Familiarity with Microsoft 365 E5 security tooling: Microsoft Defender for Identity, Microsoft Sentinel, and Purview. * Foundational networking knowledge (TCP/IP, DNS, DHCP, VPN, firewall basics) sufficient to provide secondary coverage; Palo Alto familiarity a plus. * Strong communication skills with the ability to convey technical detail clearly to both engineering peers and non-technical stakeholders. ## Description We offer a flexible working policy that supports a healthy balance between personal and professional well-being. This role requires in-office presence on Tuesdays & Thursdays to collaborate, connect, and learn from peers - while also maintaining the flexibility for meaningful work-life balance. Being an IAM Engineer at iManage Means… You are iManage's identity authority. You own the infrastructure that governs how every employee and service authenticates and accesses systems across a global, Microsoft-centric environment. Your core focus is Entra ID, SSO integrations for SaaS applications, and IAM automation - with secondary coverage for network infrastructure to support a distributed Infrastructure team. This is an individual contributor role based in London, working closely with colleagues in Belfast, Chicago, and Bangalore. iM Responsible For… * Owning IAM infrastructure across the iManage environment: identity federation, SSO, directory services, and PAM via CyberArk. * Designing and maintaining SSO integrations for SaaS applications using SAML 2.0, OAuth 2.0, OIDC, and SCIM. * Administering Entra ID as the primary identity provider: user lifecycle, group management, app registrations, and conditional access. * Configuring and maintaining Entra ID PIM, Identity Protection, entitlement management, and access reviews. * Automating user lifecycle management (provisioning, deprovisioning, access reviews) via PowerShell, Graph API, and Entra ID Governance. * Enforcing zero-trust principles, least-privilege access, and RBAC policies across the environment. * Monitoring sign-in activity, risky users, and identity alerts; remediating in line with internal SLAs. * Managing MFA policies including Conditional Access controls, authentication methods, and exception handling. * Governing service account lifecycle: creation standards, CyberArk vaulting, credential rotation, and decommissioning. * Maintaining documentation for IAM configurations, access policies, runbooks, and SOPs. * Leading IAM incident response, performing root cause analysis, and implementing preventive controls. * Owning stale account detection and remediation, drawing on Dayforce and Active Directory lifecycle signals. * Supporting JML automation in partnership with Dayforce to ensure timely access changes across the employee lifecycle. * Managing break-glass accounts including regular review, audit logging, and alerting. * Providing on-call coverage for identity incidents and participating in scheduled IAM maintenance windows., LinkedIn Profile URL: Desired salary In 150 characters or fewer, tell us what makes you unique. Try to be creative and say something that will catch our eye! 150 By submitting this application, you acknowledge that the data collected during the recruitment process will be processed in accordance with iManage's Recruitment Privacy Notice, referenced at the bottom of the job description. For any questions or additional requests, please contact us at By clicking "I have read and understood the privacy notice," you confirm that you have read and agree to the Privacy Notice and consent to being contacted by iManage regarding this application.* How did you hear about us?* Who were you referred by? (If applicable, please) This role requires working from our Chicago office on Tuesdays and Thursdays. Can you commit to this hybrid schedule?* Human Check* This website uses cookies and other analytics technologies. By selecting "Allow", you consent to the recording, use and sharing of your website activity by this website and its service providers. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)