> Markdown version of [/jobs/ext/2210879-iam-engineer](https://www.wearedevelopers.com/jobs/ext/2210879-iam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Engineer - **Company:** jazzhr - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $90,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Application Programming Interfaces (APIs), Systems Engineering, Audit Trail, Bash Shell, Software as a Service, System Configuration, Dynamic Host Configuration Protocol, Domain Name System (DNS), Identity and Access Management, Virtual Private Networks (VPN), Python (Programming Language), OAuth, OpenID, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), TCP/IP, User Provisioning Software, Computer Network Technologies, Cyberark, Firewalls (Computer Science), Ceridian Dayforce, Microsoft Sentinel, Graphql - **Published:** August 24, 2026 - **Apply:** https://imanagecom.applytojob.com/apply/6yBCqcg2do/IAM-Engineer?source=GS ## About the Role * 5+ years of experience in infrastructure or systems engineering with a primary focus on identity and access management. * Deep hands-on expertise with Microsoft Entra ID including conditional access, PIM, Identity Protection, entitlement management, and access reviews. * Demonstrated experience designing and maintaining SSO integrations for SaaS applications using SAML 2.0, OAuth 2.0, OIDC, and SCIM. * Strong scripting capability for IAM automation using PowerShell and Microsoft Graph API; Python or Bash a plus. * Working knowledge of PAM concepts and tooling; experience with CyberArk preferred. * Familiarity with Microsoft 365 E5 security tooling: Microsoft Defender for Identity, Microsoft Sentinel, and Purview. * Foundational networking knowledge (TCP/IP, DNS, DHCP, VPN, firewall basics) sufficient to provide secondary coverage; Palo Alto familiarity a plus. * Strong communication skills with the ability to convey technical detail clearly to both engineering peers and non-technical stakeholders. ## Description We offer a flexible working policy that supports a healthy balance between personal and professional well-being. This role requires in-office presence on Tuesdays & Thursdays to collaborate, connect, and learn from peers - while also maintaining the flexibility for meaningful work-life balance. Being an IAM Engineer at iManage Means… You are iManage's identity authority. You own the infrastructure that governs how every employee and service authenticates and accesses systems across a global, Microsoft-centric environment. Your core focus is Entra ID, SSO integrations for SaaS applications, and IAM automation - with secondary coverage for network infrastructure to support a distributed Infrastructure team. This is an individual contributor role based in Chicago, working closely with colleagues in Belfast, London, and Bangalore. iM Responsible For… * Owning IAM infrastructure across the iManage environment: identity federation, SSO, directory services, and PAM via CyberArk. * Designing and maintaining SSO integrations for SaaS applications using SAML 2.0, OAuth 2.0, OIDC, and SCIM. * Administering Entra ID as the primary identity provider: user lifecycle, group management, app registrations, and conditional access. * Configuring and maintaining Entra ID PIM, Identity Protection, entitlement management, and access reviews. * Automating user lifecycle management (provisioning, deprovisioning, access reviews) via PowerShell, Graph API, and Entra ID Governance. * Enforcing zero-trust principles, least-privilege access, and RBAC policies across the environment. * Monitoring sign-in activity, risky users, and identity alerts; remediating in line with internal SLAs. * Managing MFA policies including Conditional Access controls, authentication methods, and exception handling. * Governing service account lifecycle: creation standards, CyberArk vaulting, credential rotation, and decommissioning. * Maintaining documentation for IAM configurations, access policies, runbooks, and SOPs. * Leading IAM incident response, performing root cause analysis, and implementing preventive controls. * Owning stale account detection and remediation, drawing on Dayforce and Active Directory lifecycle signals. * Supporting JML automation in partnership with Dayforce to ensure timely access changes across the employee lifecycle. * Managing break-glass accounts including regular review, audit logging, and alerting. * Providing on-call coverage for identity incidents and participating in scheduled IAM maintenance windows. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)