Enterprise IAM Operations Engineer with Entra ID, RBAC, and Application Integration
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+18 more
Job description
- Design, maintain, and optimize Azure RBAC across subscriptions, management groups, resource groups, and Azure services.
- Define enterprise role taxonomy and implement governed access using groups, roles, and approved assignments.
- Administer Microsoft Entra ID/Azure AD, on-premises Active Directory, hybrid identity, and workforce, partner, guest, service, and application identities.
- Implement Microsoft Entra PIM, Just-in-Time (JIT) privileged access, MFA, Conditional Access, break-glass procedures, privileged access monitoring, and audit evidence.
- Design, implement, and troubleshoot SAML, OIDC, OAuth, Entra SSO, enterprise applications, app registrations, service principals, claims, groups, and application roles.
- Promote managed identities, govern service principals, support credential rotation, and improve CI/CD secret management.
- Support the Saviynt-to-SailPoint transition, including identity, entitlement, role, certification, policy, procedure, and control documentation.
- Support IAM monitoring, logging, alerting, investigation, and ITDR use cases using Azure-native tools and Splunk.
- Support AWS IAM, GCP IAM, and multi-cloud identity governance where required.
- Support FedRAMP-relevant access controls, configuration baselines, change control, audit readiness, and privileged access governance.
- Develop automation and scripting to improve IAM workflows, reporting, documentation, access reviews, runbooks, and operational efficiency.
- Identify opportunities to responsibly use AI tools for IAM analysis, reporting, documentation, and workflow optimization.
- Collaborate with Information Security, infrastructure, cloud, application, DevOps, audit, and other technical stakeholders.
Requirements
The ideal candidate will have strong hands-on experience with Microsoft Entra ID/Azure AD, Azure RBAC, Privileged Identity Management (PIM), application federation/SSO, least-privilege access, IAM operations, automation, Splunk-based identity monitoring, and Identity Threat Detection and Response (ITDR)., * Strong hands-on experience with Microsoft Entra ID/Azure AD administration.
- Strong knowledge of Azure RBAC, security groups, role assignments, management groups, subscriptions, and resource-level access.
- Experience with Microsoft Entra PIM, JIT privileged access, MFA, Conditional Access, and privileged authentication.
- Strong understanding of Active Directory and hybrid identity.
- Enterprise experience with SAML, OIDC, OAuth, SSO, Entra Enterprise Applications, app registrations, managed identities, service principals, claims, and application roles.
- Experience with least-privilege access design, access reviews, access certification, identity/entitlement inventory, credential management, and secret hygiene.
- Experience with Azure monitoring/logging and Splunk or comparable SIEM platforms.
- Understanding of Identity Threat Detection and Response (ITDR).
- Experience with IAM automation/scripting and CI/CD identity controls.
- Strong IAM documentation skills, including policies, standards, procedures, runbooks, and audit evidence.
Preferred Skills
- SailPoint Identity IQ or Identity Now experience.
- Experience supporting Saviynt-to-SailPoint migrations.
- Broadcom/Symantec PAM or comparable PAM platforms such as CyberArk, Beyond Trust, or Delinea.
- Cisco Splunk detection content or dashboard development.
- AWS IAM, GCP IAM, workload identity governance, and multi-cloud IAM.
- FedRAMP control support or audit readiness.
- Experience in financial services, banking, or other highly regulated enterprise environments.
- DevOps, CI/CD, SDLC identity controls, application resiliency, IAM dependency management, and vulnerability management integration.
- AI-assisted workflow automation, reporting, documentation, and operational analysis., * 7+ years of Identity and Access Management experience preferred.
- 4+ years of Microsoft Entra ID/Azure AD experience preferred.
- 3+ years of Azure RBAC, privileged access, or cloud access governance experience preferred.
- Hands-on enterprise application federation and SSO experience required.
- Financial services, banking, or regulated enterprise experience strongly preferred.
- Bachelor’s degree in Information Security, Computer Science, Information Technology, or equivalent practical experience., * Strong understanding and practical implementation of RBAC and least-privilege access at enterprise scale.
- Strong troubleshooting skills for authentication, federation, SSO, privileged access, and identity monitoring.
- Ability to work effectively across IAM, Security, Cloud, Infrastructure, Applications, DevOps, and Audit teams.
- Strong communication, documentation, analytical, and problem-solving skills.
- Ability to work within disciplined change control, audit, compliance, and operational stability environments.
- Strong ownership, accountability, initiative, and delivery focus.
- Ability to balance security requirements with technical and business needs., * Regular use of a computer, keyboard, mouse, and standard office equipment.
- Ability to work for extended periods using computer screens and participate in remote meetings.
- Ability to communicate effectively through phone and video conferencing.
Benefits & conditions
- Engagement: Full-time, 12-month staff augmentation contractor
- Work Schedule: Standard full-time hours; weekend work may be required for scheduled change management activities.
- Environment: Hybrid identity, multi-cloud, enterprise SSO, PAM, IGA, SIEM, regulated financial services environment.
About the company
Join New Era Technology, where People First is at the heart of everything we do. With a global team of over 3,000 professionals, we’re committed to creating a workplace where everyone feels valued, empowered, and inspired to grow. Our mission is to securely connect people, places, and information with end-to-end technology solutions at scale.
At New Era, you’ll join a team-oriented culture that prioritizes your personal and professional development. Work alongside industry-certified experts, access continuous training, and enjoy competitive benefits. Guided by our core attributes - putting people first, embracing continuous learning, and thriving through collaboration and inclusion - we nurture our people to deliver exceptional customer service.
If you want to make an impact in a supportive, growth-oriented environment, New Era is the place for you. Apply today and help us shape the future of work-together
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Fully Remote Software Engineer Jobs
Is Software Engineering Over-Saturated?