> Markdown version of [/jobs/ext/1249816-sr-iam-implementation-engineer-microsoft-entra-id-and-cyberark-pam](https://www.wearedevelopers.com/jobs/ext/1249816-sr-iam-implementation-engineer-microsoft-entra-id-and-cyberark-pam). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. IAM Implementation Engineer (Microsoft Entra ID and CyberArk PAM) - **Company:** Cloudious LLC - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $150,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Application Programming Interfaces (APIs), Artificial Intelligence, Microsoft Azure, Databases, Identity and Access Management, Key Management, OAuth, OpenID, Windows PowerShell, Role-Based Access Control, Openid Connect, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, Cyberark, Microsoft Power Automate, Model Validation, Splunk, Network Server - **Published:** July 12, 2026 - **Apply:** https://www.careerjet.com/jobad/us18ed201b13ea14285d91b24211daafb9 ## About the Role * 8 15 years of IAM / Security engineering experience in regulated environments * Strong hands on experience with: * Microsoft Entra ID (Azure AD) * CyberArk PAM (Vault, PSM, CPM, Secrets) * Conditional Access, MFA, Passwordless, RBAC * SAML, OAuth 2.0, OpenID Connect * Production troubleshooting in large enterprise environments Regulated Industry Experience * Experience supporting financial services, banking, insurance, or similarly regulated clients * Exposure to audit, compliance, or risk workflows related to identity and privileged access * Comfort operating under strict change management and approval processes Nice to Have * Identity Governance (PIM, Access Reviews) * SIEM integrations (Azure Sentinel, Splunk) * PowerShell / automation for IAM & PAM * Zero Trust architecture implementation experience Soft Skills * Strong hands on engineering mindset (not architecture only). * Process driven mindset with strong documentation discipline. * Pragmatic problem solver with strong risk awareness * Excellent client communication and stakeholder management skills. Clear communication with technical and business stakeholders. * Ability to build long term, trusted relationships. * Calm and methodical approach in high impact production incidents. Ability to support incidents under pressure Preferred Certifications * Microsoft SC 300 / AZ 104 / AZ 900 * CyberArk PAM certifications * Security or identity related certifications (preferred) ## Description We are seeking a Senior / Principal IAM & PAM Implementation Engineer with deep hands on experience in Microsoft Entra ID (Azure AD) and CyberArk Privileged Access Management, combined with AI / GenAI identity security exposure, to support financial services and highly regulated clients. This role is execution driven and operates in mission critical environments where identity failures directly impact business continuity, regulatory compliance, and customer trust. The engineer will design, implement, and operate IAM and PAM controls aligned to Zero Trust principles, audit requirements, and financial industry regulations. Key Responsibilities Identity & Access Management (Microsoft Entra ID / Azure AD) * Design and hands on implement Microsoft Entra ID solutions in regulated, production critical environments * Design and enforce Conditional Access, MFA, passwordless authentication, and device based access * Integrate internal and third party applications using SAML, OAuth 2.0, OIDC * Implement identity lifecycle (JML), RBAC, access reviews, and entitlement management * Maintain role-based access control (RBAC) aligned with least privilege principles. * Support IAM integrations with CyberArk PAM, DLP, and security platforms where applicable. * Troubleshoot complex sign in, token, MFA, PRT, and policy enforcement issues with minimal user disruption Privileged Access Management (CyberArk PAM) * Hands on deployment and administration of CyberArk components: Vault, PSM, CPM, Secrets Management * Onboard privileged accounts across servers, databases, network, cloud, and service identities * Enforce least privilege, credential rotation, session recording, and approval workflows * Integrate CyberArk with Microsoft Entra ID for identity driven privileged access. * Monitor privileged access activity and investigate suspicious or non compliant usage. * Support PAM audits, regulatory reviews, and emergency access scenarios (break glass) AI / GenAI Identity Security * Implement identity and access controls for AI and GenAI platforms (e.g., Microsoft Copilot, enterprise AI workloads) * Secure: * AI service identities and service principals * API access and automation credentials * AI training and inference access pipelines * Align IAM, PAM controls with enterprise AI governance, model risk, and data protection standards Governance, Compliance & Risk * Implement IAM and PAM controls aligned with Financial services regulatory expectations and Internal risk & audit frameworks * Support audits and compliance reviews (e.g., access evidence, privileged access reports) * Design and maintain audit ready documentation, including: * Architecture diagrams * Policy definitions * Access workflows and operational procedures * Participate in identity related incident response, RCA, and remediation activities Delivery & Client Engagement * Lead IAM/PAM implementations from design through production rollout * Work closely with Security leadership, Risk & compliance teams, Application owners, Auditors and regulators (as required) * Provide clear, pragmatic recommendations balancing security, usability, and regulatory compliance * Act as a trusted technical advisor to clients in high stakes environments, As our Customer Success & Implementation Engineer, your first priority is making our customers successful - starting from the moment they sign. You own their journey from technical… + 11 hours ago + ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters)