IAM/RBAC Engineer

Eliassen Group
New York, NY, United States
26 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Compensation
$166,400.0 - $187,200.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Azure Configuration Management Continuous Integration Software Design Patterns Identity and Access Management Virtual Private Networks (VPN) Role-Based Access Control Azure Active Directory Smart Cards SQL Databases Workflow Management Systems Data Logging
+2 more
Cloud Platform System Azure Resource Manager

Job description

Our client seeks an IAM/RBAC Engineer with deep experience in Microsoft Entra ID and Azure RBAC. The contractor will design, implement, and administer access controls, enforce least-privilege, and support secure, auditable access for privileged and non-privileged users. The role emphasizes scalable identity solutions, strong authenticator management, and consistent access governance and monitoring., * Define and maintain an enterprise role taxonomy across Azure resources.

  • Map permissions to roles and enforce least-privilege access via security groups and role assignments.
  • Prohibit broad, direct privilege assignments and document role-to-permission mappings and changes.
  • Implement JIT workflows for elevated access with approvals and time-bound permissions.
  • Establish usage restrictions and configuration norms for VPN, jump hosts, and privileged sessions.
  • Define and oversee emergency access procedures, incident notification, and review.
  • Configure MFA for privileged roles using strong authenticators such as smartcards or security keys.
  • Provision Azure AD administrator roles for services such as SQL where applicable.
  • Enforce managed identities for applications and reduce reliance on local service keys.
  • Ensure authorized users safeguard issued authenticators and follow secret hygiene.
  • Prevent unencrypted, embedded static credentials in code, images, and configurations.
  • Author and maintain policies, standards, and operating procedures for access controls.
  • Conduct periodic access reviews and support audit evidence collection.
  • Maintain inventories of assets and data with baseline configurations per configuration management practices.
  • Configure Azure-native monitoring and logging for identity and access events.
  • Route alerts to service owners and security teams and support audit readiness.
  • Validate use of emergency access through incident workflows and post-event reviews.

Requirements

  • Advanced knowledge of Microsoft Entra ID, Azure RBAC, security groups, PIM, and JIT access workflows.
  • Hands-on experience with Azure Policy and resource configurations, including managed identities and Azure AD admin role provisioning.
  • Familiarity with Azure monitoring and logging, AAA concepts, and integration with approval workflow tools.
  • Strong understanding of least-privilege access design and access control best practices in Azure.
  • Competence in baseline configuration management and accurate asset and data inventories.
  • Demonstrated experience implementing least-privilege at scale and articulating Azure RBAC rationale.
  • Ability to author and maintain IAM policies and procedures, perform access reviews, and support audits.
  • Proven capability to implement and govern remote and elevated access and emergency access processes.
  • Strong communication and documentation skills for technical writing and stakeholder coordination.
  • Ability to collaborate across engineering, security, and operations teams for compliant access practices.
  • Nice-to-have: Experience integrating identity workflows with approval systems and ticketing processes.
  • Nice-to-have: Exposure to application identity design patterns and CI/CD secret management controls.
  • Nice-to-have: Background in supporting audit readiness for access controls in cloud environments.

Recruitment Transparency Notice

Benefits & conditions

This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.

Rate: $80.00 to $90.00/hr. w2, Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.

W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality. If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:

When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.

About the company

Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients’ capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:14 min

Evolution of distributed SQL database architectures

Wei Hu Wei Hu · World Congress 2024

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

2:14 min

Exploring internal AI product initiatives and global engineering roles

Maria Apazoglou · Coffee With Developers

1:36 min

Evolution from key-value stores to distributed SQL

Wei Hu Wei Hu · World Congress 2025

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

Videos

See all

Related articles

See all