> Markdown version of [/jobs/ext/2296477-senior-identity-access-management-engineer](https://www.wearedevelopers.com/jobs/ext/2296477-senior-identity-access-management-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Identity & Access Management Engineer - **Company:** Uber - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $131,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, JIRA, Bash Shell, Software Debugging, Identity and Access Management, Python (Programming Language), OAuth, OpenID, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Security Assertion Markup Language (SAML), User Environment Management, User Provisioning Software, Web Applications, SSL Certificate Management, Scripting, Identity Services Engine, Google Cloud, Enterprise Software Applications, Okta, Cyberark, Microsoft InTune, Oracle Cloud Infrastructure - **Published:** August 29, 2026 - **Apply:** https://www.jofdav.com/jobs/59449308-senior-identity-access-management-engineer ## About the Role * 5+ years of hands-on IAM experience in a medium-to-large enterprise environment. * Bachelor's degree in CS, IT, or equivalent practical experience. * Deep expertise in identity platforms: JumpCloud, Entra ID (Azure AD), Okta, and Active Directory. * Hands-on scripting proficiency in PowerShell, Bash, or Python to automate identity workflows. * Deep knowledge of federated protocols (SAML 2.0, OIDC, OAuth 2.0) with the ability to read raw assertions and debug ACS URL mismatches., * Relevant industry certifications (e.g., JumpCloud, Microsoft, or CISSP). * Hands-on experience with Microsoft Intune, CyberArk (PAM/EPM), CrowdStrike Falcon, or Cisco ISE. * Background managing access controls for Oracle Cloud Infrastructure or Google Cloud Directory. ## Description We are looking for a Senior Identity & Access Management (IAM) Engineer to build, support, and scale superior identity services. If you are an experienced identity professional with strong technical skills, solid business acumen, and project management capabilities, we want to meet you. In this role, you will start by diving into our immediate operational challenges - accelerating our Entra ID to JumpCloud migration, managing the current ticket backlog, and establishing the Standard Operating Procedures (SOPs) required to eventually offload routine tasks through automation or to our End User Computing (EUC) team. As a senior resource, you will look beyond the daily queue to identify systemic inefficiencies, automate workflows, and optimize our identity ecosystem. Your strategic input and ability to own complex technical tracks will directly allow our Infrastructure Architect to focus on long-term architecture and high-level strategy. What the candidate will do * Execute & Optimize the Identity Migration: Drive the execution of migrating ~175 enterprise applications and directory sync architectures from Okta and Entra ID to JumpCloud. Resolve ongoing migration friction and manage the migration backlog efficiently. * Automation & Process Improvement: Actively identify manual steps within the identity lifecycle and migration pipelines. Author scripts in PowerShell, Bash, or Python to scale identity provisioning, expand automated requests, and build frictionless, self-healing solutions. * Architectural Support: Partner with and alleviate the Identity Architect by taking ownership of complex technical sub-projects, analyzing infrastructure dependencies, and ensuring identity solutions align with our 99.99% reliability goals. * Stakeholder Engagement & Project Management: Actively engage with internal business partners and application owners to gather requirements. Follow up assertively to ensure stakeholder availability, coordinate testing windows, and drive tasks to completion despite communication roadblocks. * SOP Development & Knowledge Transfer: Author comprehensive, clear Standard Operating Procedures (SOPs), technical manuals, and knowledge base articles. Define and document identity processes to seamlessly train, mentor, and eventually offload key KTLO (Keep the Lights On) activities to the EUC team. * Design & Implement Identity Platforms: Participate in the design, implementation, and support of identity, authentication, authorization, and certificate management platforms. Design reusable SAML/OIDC integration patterns across multiple environments. * User Lifecycle & Access Control: Own user provisioning, deprovisioning, role changes, and Role-Based Access Control (RBAC), ensuring onboarding access posture is consistent and secure across the organization. * MDM & Conditional Access: Execute MDM rollout plans, maintain device compliance baselines (Intune/JumpCloud), and configure complex Conditional Access policies to meet strict security and business requirements. * Operational Excellence & Troubleshooting: Diagnose and resolve complex TechConnect (Jira Service Management) tickets. Review logs, filter past noise, and perform remote troubleshooting for both legacy and web-based applications. * Change Management: Prepare, risk-assess, and represent Change Requests (CRs) through the Change Advisory Board (CAB) following established control processes. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) ## Related Articles - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift)