Identity Access Management (IAM) Engineer

GlobalLogic
New York, NY, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$130,000.0 - $140,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Microsoft Azure Microsoft Online Services Cloud Database Cyber Security Domain Name System (DNS) Multi-Factor Authentication Identity and Access Management Key Management OAuth Windows PowerShell
+18 more
Role-Based Access Control Openid Connect Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Single Sign-On Backup and Restore Data Logging Enterprise Software Applications Data Classification Cyberark Microsoft Power Automate Azure Powershell Microsoft InTune Information Technology Google Cloud Functions Atlassian Tools Hashicorp

Job description

  • Lead enterprise-wide IAM standardization, including identity lifecycle management, access governance, and policy enforcement across global regions.
  • Drive automation across IAM to streamline administration and improve user experience. Support onboarding of enterprise applications into Azure Entra ID, including Single Sign On (SSO), Conditional Access, and role-based access control (RBAC).

  • Enhance privileged access management and implement scalable monitoring, alerting, and auditability to support a secure, geographically distributed workforce.
  • Collaborate with IT, Networking, and Security teams to troubleshoot identity-related issues and support global infrastructure initiatives.
  • Advance Zero Trust Identity Fabric principles such as continuous verification, least privilege access, and identity-aware policy enforcement across users, devices, workloads, and non-human identities..

Requirements

  • 8+ years of hands-on experience in Identity and Access Management and cloud automation, particularly within the Microsoft ecosystem.
  • Strong analytical and troubleshooting skills for complex infrastructure and identity-related issues.
  • Excellent communication skills with the ability to explain technical concepts to both technical and non-technical stakeholders.
  • Deep experience with Microsoft Entra ID, including Conditional Access, Identity Governance, and Privileged Identity Management (PIM).
  • Familiarity with Microsoft 365 services such as Exchange Online, Defender, Purview, Sentinel, Intune, and related platforms.
  • Strong automation and scripting skills using PowerShell, Azure CLI, and Microsoft Graph API.
  • Working knowledge of Azure services, including Function Apps and Logic Apps.
  • Experience in onboarding and managing enterprise applications in Azure Entra ID.
  • Advanced knowledge of SSO protocols, including OAuth2, OpenID Connect, and SAML.
  • Experience with privileged access tools (Azure PIM, CyberArk), secrets management (HashiCorp Vault or Azure Key Vault), and workload identity patterns (SPIFFE & SPIRE).
  • Familiarity with Non-Human Identity (NHI) governance, including service accounts and AI agents; exposure to policy as code frameworks such as OPA/Rego.
  • Good to have familiarity with Microsoft Purview for DLP and data classification.
  • Strong understanding of multi-factor authentication and FIDO2.
  • Familiarity with IT security frameworks and compliance standards.
  • Knowledge of logging, monitoring, and alerting practices for identity and access events.
  • Basic understanding of email security and DNS.
  • Experience with backup and recovery strategies for identity-related services.
  • Understanding of Zero Trust Architecture principles.
  • Familiarity with Jira and Confluence., Education: Bachelor’’s or Master’s degree in Computer Science, Computer or Electrical Engineering, Mathematics, or a related field.

About the company

Disclaimer: GlobalLogic estimates the starting pay range for this role to be performed from New York, NY, to be $130,000 to $140,000 and reflects base salary only. This pay range is provided as a good-faith estimate, and the amount offered may be higher or lower. GlobalLogic takes many factors into consideration in making an offer, including candidate qualifications, work experience, operational needs, travel and onsite requirements, internal peer equity, prevailing wage, responsibilities, and other market and business considerations.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

5:24 min

Demonstrating database encryption at rest with HashiCorp Vault

Alex Soto Alex Soto · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

2:39 min

Generating dynamic application secrets using HashiCorp Vault engines

Alex Soto Alex Soto · LIVE

Videos

See all

Related articles

See all