> Markdown version of [/jobs/ext/2025459-iam-rbac-engineer](https://www.wearedevelopers.com/jobs/ext/2025459-iam-rbac-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM/RBAC Engineer - **Company:** Eliassen Group - **Location:** New York, NY, United States (Remote available) - **Salary:** $166,400.0 - $187,200.0 - **Contract:** Temporary to permanent - **Skills:** Microsoft Azure, Configuration Management, Continuous Integration, Software Design Patterns, Identity and Access Management, Virtual Private Networks (VPN), Role-Based Access Control, Azure Active Directory, Smart Cards, SQL Databases, Workflow Management Systems, Data Logging, Cloud Platform System, Azure Resource Manager - **Published:** August 11, 2026 - **Apply:** https://www.dice.com/job-detail/8d9a727c-a6b2-428f-8f98-6b4943005960 ## About the Role * Advanced knowledge of Microsoft Entra ID, Azure RBAC, security groups, PIM, and JIT access workflows. * Hands-on experience with Azure Policy and resource configurations, including managed identities and Azure AD admin role provisioning. * Familiarity with Azure monitoring and logging, AAA concepts, and integration with approval workflow tools. * Strong understanding of least-privilege access design and access control best practices in Azure. * Competence in baseline configuration management and accurate asset and data inventories. * Demonstrated experience implementing least-privilege at scale and articulating Azure RBAC rationale. * Ability to author and maintain IAM policies and procedures, perform access reviews, and support audits. * Proven capability to implement and govern remote and elevated access and emergency access processes. * Strong communication and documentation skills for technical writing and stakeholder coordination. * Ability to collaborate across engineering, security, and operations teams for compliant access practices. * Nice-to-have: Experience integrating identity workflows with approval systems and ticketing processes. * Nice-to-have: Exposure to application identity design patterns and CI/CD secret management controls. * Nice-to-have: Background in supporting audit readiness for access controls in cloud environments. Recruitment Transparency Notice ## Description Our client seeks an IAM/RBAC Engineer with deep experience in Microsoft Entra ID and Azure RBAC. The contractor will design, implement, and administer access controls, enforce least-privilege, and support secure, auditable access for privileged and non-privileged users. The role emphasizes scalable identity solutions, strong authenticator management, and consistent access governance and monitoring., * Define and maintain an enterprise role taxonomy across Azure resources. * Map permissions to roles and enforce least-privilege access via security groups and role assignments. * Prohibit broad, direct privilege assignments and document role-to-permission mappings and changes. * Implement JIT workflows for elevated access with approvals and time-bound permissions. * Establish usage restrictions and configuration norms for VPN, jump hosts, and privileged sessions. * Define and oversee emergency access procedures, incident notification, and review. * Configure MFA for privileged roles using strong authenticators such as smartcards or security keys. * Provision Azure AD administrator roles for services such as SQL where applicable. * Enforce managed identities for applications and reduce reliance on local service keys. * Ensure authorized users safeguard issued authenticators and follow secret hygiene. * Prevent unencrypted, embedded static credentials in code, images, and configurations. * Author and maintain policies, standards, and operating procedures for access controls. * Conduct periodic access reviews and support audit evidence collection. * Maintain inventories of assets and data with baseline configurations per configuration management practices. * Configure Azure-native monitoring and logging for identity and access events. * Route alerts to service owners and security teams and support audit readiness. * Validate use of emergency access through incident workflows and post-event reviews. ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Fake or News: LLMs Protect Each Other, Google Predicts Floods, and GitHub Copilot Loves COBOL - Niels Leenheer](https://www.wearedevelopers.com/videos/1860-fake-or-news-llms-protect-each-other-google-predicts-floods-and-github-copilot-loves-cobol-niels-leenheer) - [Full-stack role-based authorization in 45 minutes](https://www.wearedevelopers.com/videos/312-full-stack-role-based-authorization-in-45-minutes) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1520-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms)