> Markdown version of [/jobs/ext/1285160-iam-engineer](https://www.wearedevelopers.com/jobs/ext/1285160-iam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Engineer - **Company:** Multiplied - **Location:** Den Haag, Netherlands - **Salary:** €6,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Active Directory, Application Programming Interfaces (APIs), User Authentication, Cyber Security, Identity and Access Management, Intrusion Detection and Prevention, Kerberos (Protocol), Network Control, NT LAN Manager, Windows PowerShell, Azure Active Directory, Security Information and Event Management, 3-tier Architectures - **Published:** July 16, 2026 - **Apply:** https://www.multiplied.nl/vacature/iam-engineer ## About the Role * Strong hands-on experience with Active Directory Domain Services (AD DS), including: * Forests, domains, and trusts * Kerberos and NTLM security concepts * Group Policy engineering * Active Directory Administrative Center * Authentication security controls * Extensive knowledge of Microsoft Entra ID, including: * Directory roles * Administrative Units * Conditional Access policies * Authentication strengths * Token protection * Privileged Identity Management (PIM) * Proven experience implementing: * Microsoft Legacy 3-Tier Model * Enterprise Access Model (EAM) * Privileged Identity Management strategies Security & Automation Skills * Experience designing and deploying: * Privileged Access Workstations (PAWs) * Secure jump servers * Tier-specific administrative environments * Strong PowerShell scripting skills for: * Identity audits * Automation of security controls * Compliance reporting * Experience with Microsoft Graph API for Entra ID automation and reporting. * Familiarity with identity security assessment tools such as: * BloodHound * PingCastle * Microsoft Defender for Identity ## Description We are looking for an IAM Engineer to lead the design and implementation of our Enterprise Credential Tiering Model. In this role, you will be the technical owner responsible for securing privileged identities, isolating high-impact administrative assets within Active Directory Domain Services (AD DS), and extending these security boundaries into Microsoft Entra ID. Your mission is to strengthen the organisation's identity security posture by eliminating lateral movement opportunities, protecting the identity control plane, and ensuring that identity architecture aligns with a strict Zero Trust security framework. You will work at the intersection of Identity & Access Management, cybersecurity, and infrastructure, partnering closely with Security Operations and IT teams to build a secure and future-proof identity environment., * Configure Active Directory Organizational Units (OUs), Group Policy Objects (GPOs), Authentication Policies, and Authentication Silos. * Prevent privileged credentials from being exposed on lower-tier systems. * Implement modern privileged access solutions, including: * Microsoft Entra Privileged Identity Management (PIM) * Conditional Access Policies (CAPs) * Secure Administrative Workstations (SAWs/PAWs) * Tier-specific administrative access models Identity Security Improvement & Legacy Cleansing * Identify and remediate identity security risks, including: * Unmanaged service accounts * Excessive permissions * Over-privileged groups * Cross-tier group nesting * Legacy configurations that bypass security boundaries * Improve overall identity hygiene and reduce attack paths., * Work closely with Security Operations (SecOps) teams to align identity controls with SIEM monitoring and security detection capabilities. * Support detection and response processes for anomalous authentication behaviour and privileged access risks. * Contribute to identity governance standards and security improvements. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [A Hitchhikers Guide to Container Security - Automotive Edition 2024](https://www.wearedevelopers.com/videos/1119-a-hitchhikers-guide-to-container-security-automotive-edition-2024) ## Related Articles - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)