Senior Identity & Access Management (IAM) Engineer, Workforce Identity

Acrisure LLC
Atlanta, GA, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Active Directory Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Cloud Engineering Multi-Factor Authentication Identity and Access Management Python (Programming Language) OAuth OpenID PCI Data Security Standards Windows PowerShell
+15 more
Role-Based Access Control Azure Active Directory Phishing Zero Trust Network Access Security Assertion Markup Language (SAML) Policy as Code Cloud Platform System Okta Cyberark Software Security Software Troubleshooting Multi-Cloud Deployment Automation SailPoint Terraform

Job description

Experteer Overview In this hands-on IAM role, you will design, automate, and operate Acrisure’s Workforce Identity Platform across Entra ID, Active Directory, and hybrid/cloud environments. You will create scalable identity patterns for secure, seamless access while upholding governance and compliance. You’ll work with cross-functional teams to turn identity into an enabler for users, applications, and services. This position offers the opportunity to shape enterprise security and authentication at scale within a growth-focused fintech leader. Compensation / Benefits * Design, implement, and maintain Microsoft Entra ID and Active Directory services for the enterprise * Develop and maintain identity architecture standards, authentication policies, and tenant governance * Manage and secure Entra ID tenant architecture and identity infrastructure * Implement and support Conditional Access, MFA, phishing-resistant authentication, and passwordless methods * Establish tenant security posture standards, admin tiering, and privileged identity controls * Design and maintain federation and enterprise SSO integrations (SAML, OIDC, OAuth2) * Support Entra B2B collaboration and external workforce access patterns * Define and maintain enterprise app onboarding standards and identity integration requirements * Automate provisioning/deprovisioning pipelines using identity APIs, SCIM, and orchestration platforms * Policy-as-code for IAM guardrails including least privilege and MFA enforcement * Engineer scalable automation to reduce manual identity operations and improve governance * Collaborate with AppSec and Cloud Engineering to secure authentication/authorization boundaries * Automate joiner/mover/leaver processes and support periodic access reviews and certifications * Deliver dashboards for identity risk indicators and support SOC 2, PCI DSS, ISO 27001 audits * Participate in on-call support and escalation for workforce identity services Tasks * 5+ years in Identity and Access Management engineering for hybrid/multi-cloud environments * Strong experience with Microsoft Entra ID, Active Directory, and hybrid identity architectures * Knowledge of AWS IAM, Azure identity services, and authentication tech (SAML, OIDC, OAuth2, SCIM) * Experience implementing Conditional Access, Identity Protection, MFA, passwordless authentication * Experience with Entra Connect, cloud synchronization, and hybrid identity operations * Automation experience with PowerShell, Microsoft Graph API, Python, Terraform * Experience with PAM platforms (Delinea, CyberArk, BeyondTrust, Azure PIM) * Experience with IGA platforms (SailPoint, Saviynt, Okta) * Understanding of Zero Trust, least privilege, RBAC, and privileged access design * Ability to translate business requirements into secure, scalable identity solutions * Strong troubleshooting across authentication, federation, and directory services Key requirements * comprehensive medical, dental, vision * life and disability insurance * 401(k) with immediate vesting * HSA and FSA options * paid time off and holidays * family and wellness benefits

Requirements

services, engineering for hybrid/multi-cloud environments * Strong experience with Microsoft Entra ID, Active Directory, and hybrid identity architectures * Knowledge of AWS IAM, Azure identity services, and authentication tech (SAML, OIDC, OAuth2, SCIM) * Experience implementing Conditional Access, Identity Protection, MFA, passwordless authentication * Experience with Entra Connect, cloud synchronization, and hybrid identity operations * Automation experience with PowerShell, Microsoft Graph API, Python, Terraform * Experience with PAM platforms (Delinea, CyberArk, BeyondTrust, Azure PIM) * Experience with IGA platforms (SailPoint, Saviynt, Okta) * Understanding of Zero Trust, least privilege, RBAC, and privileged access design * Ability to translate business requirements into secure, scalable identity solutions * Strong troubleshooting across authentication, federation, and directory services Key requirements * comprehensive medical, dental, vision * life and disability insurance * a aaaQ_ with immediate vesting * HSA and FSA options * paid time off and holidays * family and wellness benefits

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:24 min

Securing cloud deployments by utilizing OpenID Connect mapping

Chris Ayers · LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

Videos

See all

Related articles

See all