> Markdown version of [/jobs/ext/2540404-enterprise-iam-operations-engineer-with-entra-id-rbac-and-application-integration](https://www.wearedevelopers.com/jobs/ext/2540404-enterprise-iam-operations-engineer-with-entra-id-rbac-and-application-integration). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Enterprise IAM Operations Engineer with Entra ID, RBAC, and Application Integration - **Company:** New Era Technology - **Location:** Lake Mary, FL, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Artificial Intelligence, Application Integration Architecture, Microsoft Azure, Cloud Computing, Cyber Security, Continuous Integration, DevOps, Identity and Access Management, Intrusion Detection and Prevention, OAuth, OpenID, Systems Development Life Cycle, Role-Based Access Control, Azure Active Directory, Broadcom, Runbook, Security Assertion Markup Language (SAML), Security Information and Event Management, Single Sign-On, Software Vulnerability Management, Symantec, Data Logging, Enterprise Software Applications, Cyberark, Multi-Cloud, Information Technology, SailPoint, Splunk, Cisco - **Published:** August 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=34187c7f1ed48c53 ## About the Role The ideal candidate will have strong hands-on experience with Microsoft Entra ID/Azure AD, Azure RBAC, Privileged Identity Management (PIM), application federation/SSO, least-privilege access, IAM operations, automation, Splunk-based identity monitoring, and Identity Threat Detection and Response (ITDR)., * Strong hands-on experience with Microsoft Entra ID/Azure AD administration. * Strong knowledge of Azure RBAC, security groups, role assignments, management groups, subscriptions, and resource-level access. * Experience with Microsoft Entra PIM, JIT privileged access, MFA, Conditional Access, and privileged authentication. * Strong understanding of Active Directory and hybrid identity. * Enterprise experience with SAML, OIDC, OAuth, SSO, Entra Enterprise Applications, app registrations, managed identities, service principals, claims, and application roles. * Experience with least-privilege access design, access reviews, access certification, identity/entitlement inventory, credential management, and secret hygiene. * Experience with Azure monitoring/logging and Splunk or comparable SIEM platforms. * Understanding of Identity Threat Detection and Response (ITDR). * Experience with IAM automation/scripting and CI/CD identity controls. * Strong IAM documentation skills, including policies, standards, procedures, runbooks, and audit evidence. Preferred Skills * SailPoint Identity IQ or Identity Now experience. * Experience supporting Saviynt-to-SailPoint migrations. * Broadcom/Symantec PAM or comparable PAM platforms such as CyberArk, Beyond Trust, or Delinea. * Cisco Splunk detection content or dashboard development. * AWS IAM, GCP IAM, workload identity governance, and multi-cloud IAM. * FedRAMP control support or audit readiness. * Experience in financial services, banking, or other highly regulated enterprise environments. * DevOps, CI/CD, SDLC identity controls, application resiliency, IAM dependency management, and vulnerability management integration. * AI-assisted workflow automation, reporting, documentation, and operational analysis., * 7+ years of Identity and Access Management experience preferred. * 4+ years of Microsoft Entra ID/Azure AD experience preferred. * 3+ years of Azure RBAC, privileged access, or cloud access governance experience preferred. * Hands-on enterprise application federation and SSO experience required. * Financial services, banking, or regulated enterprise experience strongly preferred. * Bachelor's degree in Information Security, Computer Science, Information Technology, or equivalent practical experience., * Strong understanding and practical implementation of RBAC and least-privilege access at enterprise scale. * Strong troubleshooting skills for authentication, federation, SSO, privileged access, and identity monitoring. * Ability to work effectively across IAM, Security, Cloud, Infrastructure, Applications, DevOps, and Audit teams. * Strong communication, documentation, analytical, and problem-solving skills. * Ability to work within disciplined change control, audit, compliance, and operational stability environments. * Strong ownership, accountability, initiative, and delivery focus. * Ability to balance security requirements with technical and business needs., * Regular use of a computer, keyboard, mouse, and standard office equipment. * Ability to work for extended periods using computer screens and participate in remote meetings. * Ability to communicate effectively through phone and video conferencing. ## Description * Design, maintain, and optimize Azure RBAC across subscriptions, management groups, resource groups, and Azure services. * Define enterprise role taxonomy and implement governed access using groups, roles, and approved assignments. * Administer Microsoft Entra ID/Azure AD, on-premises Active Directory, hybrid identity, and workforce, partner, guest, service, and application identities. * Implement Microsoft Entra PIM, Just-in-Time (JIT) privileged access, MFA, Conditional Access, break-glass procedures, privileged access monitoring, and audit evidence. * Design, implement, and troubleshoot SAML, OIDC, OAuth, Entra SSO, enterprise applications, app registrations, service principals, claims, groups, and application roles. * Promote managed identities, govern service principals, support credential rotation, and improve CI/CD secret management. * Support the Saviynt-to-SailPoint transition, including identity, entitlement, role, certification, policy, procedure, and control documentation. * Support IAM monitoring, logging, alerting, investigation, and ITDR use cases using Azure-native tools and Splunk. * Support AWS IAM, GCP IAM, and multi-cloud identity governance where required. * Support FedRAMP-relevant access controls, configuration baselines, change control, audit readiness, and privileged access governance. * Develop automation and scripting to improve IAM workflows, reporting, documentation, access reviews, runbooks, and operational efficiency. * Identify opportunities to responsibly use AI tools for IAM analysis, reporting, documentation, and workflow optimization. * Collaborate with Information Security, infrastructure, cloud, application, DevOps, audit, and other technical stakeholders. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)