IAM Engineer

Multiplied
Den Haag, Netherlands
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
€6,000.0
Working hours
Regular working hours

Tech stack

Microsoft Access Active Directory Application Programming Interfaces (APIs) User Authentication Cyber Security Identity and Access Management Intrusion Detection and Prevention Kerberos (Protocol) Network Control NT LAN Manager Windows PowerShell Azure Active Directory
+2 more
Security Information and Event Management 3-tier Architectures

Job description

We are looking for an IAM Engineer to lead the design and implementation of our Enterprise Credential Tiering Model. In this role, you will be the technical owner responsible for securing privileged identities, isolating high-impact administrative assets within Active Directory Domain Services (AD DS), and extending these security boundaries into Microsoft Entra ID.

Your mission is to strengthen the organisation’s identity security posture by eliminating lateral movement opportunities, protecting the identity control plane, and ensuring that identity architecture aligns with a strict Zero Trust security framework.

You will work at the intersection of Identity & Access Management, cybersecurity, and infrastructure, partnering closely with Security Operations and IT teams to build a secure and future-proof identity environment., * Configure Active Directory Organizational Units (OUs), Group Policy Objects (GPOs), Authentication Policies, and Authentication Silos.

  • Prevent privileged credentials from being exposed on lower-tier systems.
  • Implement modern privileged access solutions, including:
  • Microsoft Entra Privileged Identity Management (PIM)
  • Conditional Access Policies (CAPs)
  • Secure Administrative Workstations (SAWs/PAWs)
  • Tier-specific administrative access models

Identity Security Improvement & Legacy Cleansing

  • Identify and remediate identity security risks, including:
  • Unmanaged service accounts
  • Excessive permissions
  • Over-privileged groups
  • Cross-tier group nesting
  • Legacy configurations that bypass security boundaries
  • Improve overall identity hygiene and reduce attack paths., * Work closely with Security Operations (SecOps) teams to align identity controls with SIEM monitoring and security detection capabilities.
  • Support detection and response processes for anomalous authentication behaviour and privileged access risks.
  • Contribute to identity governance standards and security improvements.

Requirements

  • Strong hands-on experience with Active Directory Domain Services (AD DS), including:
  • Forests, domains, and trusts
  • Kerberos and NTLM security concepts
  • Group Policy engineering
  • Active Directory Administrative Center
  • Authentication security controls
  • Extensive knowledge of Microsoft Entra ID, including:
  • Directory roles
  • Administrative Units
  • Conditional Access policies
  • Authentication strengths
  • Token protection
  • Privileged Identity Management (PIM)
  • Proven experience implementing:
  • Microsoft Legacy 3-Tier Model
  • Enterprise Access Model (EAM)
  • Privileged Identity Management strategies

Security & Automation Skills

  • Experience designing and deploying:
  • Privileged Access Workstations (PAWs)
  • Secure jump servers
  • Tier-specific administrative environments
  • Strong PowerShell scripting skills for:
  • Identity audits
  • Automation of security controls
  • Compliance reporting
  • Experience with Microsoft Graph API for Entra ID automation and reporting.
  • Familiarity with identity security assessment tools such as:
  • BloodHound
  • PingCastle
  • Microsoft Defender for Identity

Benefits & conditions

  • Competitive salary up to €6,000 gross per month, depending on experience.
  • Lease car as part of your employment package.
  • Attractive bonus scheme based on performance.
  • The opportunity to work on strategic identity security projects with a strong focus on Zero Trust.
  • A challenging role where you can directly influence enterprise security architecture.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.multiplied.nl

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

1:26 min

Bridging the sim-to-real gap with multi-control networks

Alexander Schwarz Alexander Schwarz · WWC 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:14 min

Securing analysis platforms via network access controls

Jennifer Reif · LIVE

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all