Identity & Access Management (IAM) Engineer

Robert @
Houston, United States
24 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$130,000.0 - $160,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Artificial Intelligence Microsoft Azure Cyber Security Domainkeys Identified Mail Domain-Based Message Authentication Reporting and Conformance (DMARC) Multi-Factor Authentication Identity and Access Management Knowledge Management Microsoft Security Essentials Microsoft Visio
+15 more
OAuth OpenID Windows PowerShell Role-Based Access Control Openid Connect Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Single Sign-On Enterprise Software Applications Microsoft Power Automate Sender Policy Framework (SPF) AI Platforms IronPort Cisco

Job description

As the Identity & Access Management (IAM) Engineer, you’ll play a critical role in supporting, modernizing, and continuously improving our enterprise identity and access infrastructure. This position focuses on Microsoft Entra ID (Azure AD) and Active Directory, while also supporting Microsoft 365 messaging environments, secure email infrastructure, and enterprise identity governance. We’re looking for someone with an AI-first mindset who enjoys leveraging automation, Microsoft Copilot, and intelligent tooling to simplify operations, strengthen security, and improve the end-user experience. This role goes beyond traditional IAM administration-you’ll help shape how enterprise identity is managed through automation, Zero Trust principles, and continuous optimization.

Responsibilities Identity & Access Management

  • Administer and optimize Microsoft Entra ID (Azure AD) and on-premises Active Directory
  • Design and implement secure enterprise identity solutions
  • Configure and manage Single Sign-On (SSO) integrations using SAML, OAuth, and OpenID Connect (OIDC)
  • Administer Enterprise Applications within Entra ID, including onboarding, provisioning, access assignments, and lifecycle management
  • Troubleshoot authentication, federation, SSO, and directory-related issues
  • Partner with application owners to design secure authentication and authorization models
  • Implement and manage:

o Multi-Factor Authentication (MFA) o Conditional Access Policies o Identity Protection o Risk-Based Access Controls

  • Administer Privileged Identity Management (PIM), including just-in-time access and privileged governance
  • Manage Joiner, Mover, and Leaver identity lifecycle processes
  • Implement least privilege and Role-Based Access Control (RBAC)
  • Support hybrid identity environments and directory synchronization

Security & Compliance

  • Apply Zero Trust principles across enterprise identity
  • Monitor and respond to identity-related threats and anomalies
  • Support identity governance initiatives, access reviews, and certification campaigns
  • Partner with security and compliance teams to support audits, policy enforcement, and risk mitigation

Messaging & Email Infrastructure

  • Support Microsoft 365 and Exchange Online environments
  • Assist with Exchange Hybrid administration and troubleshooting
  • Resolve mail flow and messaging issues
  • Support email security technologies including SPF, DKIM, and DMARC
  • Maintain awareness of secure email gateway solutions such as Cisco IronPort or similar technologies

AI-First Operations & Automation

  • Utilize Microsoft Copilot and AI-assisted tools to accelerate troubleshooting and operational efficiency
  • Develop PowerShell automation and orchestration workflows
  • Use AI to improve root cause analysis, anomaly detection, and operational support
  • Identify opportunities to automate identity, messaging, and security operations
  • Evaluate emerging Microsoft AI capabilities and implement practical enterprise use cases

Documentation & Knowledge Management

  • Develop and maintain technical documentation and operational runbooks
  • Create architecture and process diagrams using Microsoft Visio or similar tools
  • Document current-state and future-state identity architectures
  • Contribute to internal knowledge management resources

Collaboration & Continuous Improvement

  • Partner with Infrastructure, Security, and Application teams
  • Recommend improvements to enterprise identity architecture
  • Continuously improve security posture, operational efficiency, and user experience
  • Participate in an on-call support rotation as needed

Requirements

  • Bachelor’s degree from an accredited college or university
  • 5+ years of Identity & Access Management experience in enterprise environments
  • Strong expertise administering Microsoft Entra ID (Azure AD)
  • Strong Active Directory administration experience
  • Hands-on experience with:

o Conditional Access o Multi-Factor Authentication (MFA) o Single Sign-On (SSO) o Role-Based Access Control (RBAC) o Privileged Identity Management (PIM)

  • Experience supporting Microsoft 365 and Exchange Online
  • Experience with hybrid identity and directory synchronization
  • Strong PowerShell scripting and automation experience
  • Knowledge of Zero Trust architecture and least-privilege security models
  • Experience troubleshooting complex authentication and identity issues
  • Familiarity with Microsoft Security and Compliance solutions
  • Understanding of identity governance and access review processes
  • Knowledge of email authentication technologies including SPF, DKIM, and DMARC
  • Excellent communication and collaboration skills

Preferred Qualifications

  • Microsoft Azure certifications
  • Microsoft 365 certifications
  • Microsoft Security certifications
  • Experience with Microsoft Copilot or enterprise AI platforms
  • Experience implementing AI-driven operational improvements
  • Familiarity with Cisco IronPort or similar secure email gateway solutions
  • Microsoft Visio experience
  • Experience supporting large enterprise environments
  • Passion for automation and continuous process improvement

Benefits & conditions

  • Competitive compensation and comprehensive benefits package
  • Generous PTO and vacation program
  • Ongoing training and professional development
  • Opportunity to influence enterprise security strategy
  • Collaborative culture focused on innovation and continuous improvement
  • Long-term career growth within a global organization

About the company

We are a globally recognized real estate investment and development organization with a long-standing reputation for innovation, operational excellence, and investing in cutting-edge technology. Our technology team supports a large, complex enterprise environment where security, scalability, and automation are at the forefront of everything we do.

We’re seeking an Identity & Access Management (IAM) Engineer to help modernize and strengthen our enterprise identity infrastructure. This is an opportunity to work with the latest Microsoft cloud technologies, AI-powered automation, and Zero Trust security principles while partnering with talented infrastructure, security, and application teams. If you’re passionate about improving identity security, automating operations, and leveraging AI to solve complex challenges, you’ll find plenty of opportunities to make a meaningful impact and grow your career.

Why join us?

  • Join one of the world’s premier real estate investment and development firms
  • Work with modern Microsoft cloud technologies and AI-powered solutions

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all