Microsoft IAM Engineer

Resource Innovations
Denver, CO, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$75,000.0 - $115,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Application Programming Interfaces (APIs) User Authentication Microsoft Azure Software as a Service Cloud Engineering Cloud Foundry Cyber Security Multi-Factor Authentication Identity and Access Management Issue Tracking Systems
+17 more
OAuth Windows PowerShell Role-Based Access Control Openid Connect Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Single Sign-On Systems Integration Virtual Machines Azure Automation Enterprise Software Applications Information Technology Serverless Computing Workday Key Vault Servicenow

Job description

Resource Innovations is seeking a highly skilled and motivated Microsoft IAM Engineer to join our growing team. We are seeking an experienced Microsoft IAM Engineer to lead the administration, governance, security, and operational maturity of our enterprise identity and access management environment. This role will serve as a technical leader responsible for Microsoft Entra ID (formerly Azure Active Directory), identity lifecycle management, authentication services, access governance, and enterprise application integrations.

A key focus of this role is the integration and synchronization between Microsoft Entra and Workday, ensuring accurate and automated identity provisioning, role assignment, and deprovisioning processes across the organization. This role will also support cloud identity and access governance initiatives across Microsoft Azure environments, helping secure enterprise infrastructure, SaaS applications, and cloud-native services. The ideal candidate combines deep technical expertise in identity management with strong operational discipline, automation capabilities, and cross-functional collaboration skills.

Resource Innovations (RI) is a women-led energy transformation firm focused on impact. Building on our expertise in energy efficiency, we’re constantly expanding our portfolio of clean energy solutions to guide utilities through increasingly complex, connected challenges. Load flexibility. Electrification. Carbon reduction. With every step, we’re leading the charge to power change.

Duties and Responsibilities

  • Administer and support enterprise identity and access management services across Microsoft Entra ID, Azure environments, and on premises Active Directory environment.

  • Manage user lifecycle processes including onboarding, transfers, role changes, and offboarding.
  • Configure and maintain authentication and access controls including Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, passwordless authentication, self-service password reset (SSPR), Role-Based Access Control (RBAC), Privileged Identity Management (PIM), and Managed Identities.
  • Manage enterprise applications, application registrations, API permissions, and federated authentication integrations utilizing SAML, OAuth, OpenID Connect, and SCIM provisioning.
  • Administer privileged access controls and role-based security models while supporting least-privilege and Zero Trust security principles.
  • Support identity governance initiatives including access reviews, entitlement management, administrative role governance, and identity-based access policies.
  • Manage identity integrations and access controls for cloud-native, SaaS, and Microsoft 365 platforms.
  • Support Azure tenant governance including subscriptions, management groups, administrative roles, and security policies.
  • Monitor and optimize identity security posture across Microsoft Azure, Microsoft Entra ID, and Microsoft 365 environments.
  • Assist with governance and operational oversight of Azure Virtual Machines, Storage, Networking integrations, Key Vault, and Platform-as-a-Service (PaaS) resources.
  • Partner with Security Operations, Infrastructure, and Cloud Engineering teams to support secure cloud adoption, modernization, and operational excellence initiatives.
  • Develop automation solutions and operational efficiencies utilizing PowerShell, Microsoft Graph API, Azure Automation, and Infrastructure-as-Code methodologies.
  • Participate in incident response, troubleshooting, root cause analysis, and operational escalations.
  • Other duties as assigned.

Requirements

  • Bachelor’s degree in Information Technology, Computer Science, or related field (or equivalent experience).

  • At least 3+ years of experience in Identity and Access Management (IAM) administration required; 5 years preferred
  • At least 3+ years of hands-on experience administering Microsoft Entra / AD required; 5 years preferred
  • Experience integrating and supporting Workday with identity platforms
  • Experience supporting and administering Microsoft Azure environments
  • Strong understanding of identity lifecycle management, SSO and federation technologies, Conditional Access, MFA, Role-Based Access Control (RBAC), and Privileged Identity Management (PIM)
  • Experience with hybrid identity environments and Active Directory synchronization
  • Advanced PowerShell scripting and automation experience
  • Experience supporting enterprise-scale identity operations
  • ServiceNow or other ticketing system experience and ability to work from a queue

Benefits & conditions

Parental leave, Health insurance, 401(k) matching, Vision insurance, Dental insurance, Employee assistance program, Commuter assistance, Paid holidays Full-time Hybrid work in Denver, CO, Resource Innovations offers competitive salaries based on a candidate’s skills, experience and qualifications for the position. The compensation range for the base salary for this position is $75,000-$115,000. In addition to base pay, employees may be eligible for a discretionary annual bonus. The stated salary represents the expected compensation for this position. Final compensation will be determined based on factors such as the candidate’s experience, education and location.

At Resource Innovations, we believe supporting our people is essential to delivering impact. We offer a comprehensive benefits package designed to promote health, financial security, and work-life balance. This includes three weeks of paid vacation annually, paid holidays, a 401(k) retirement plan with employer match, medical, dental and vision coverage, parental leave, an employee assistance program, commuter benefits, and additional supplemental offerings.

About the company

Resource Innovations (RI) is a women-led energy transformation firm focused on impact. Building on our expertise in energy efficiency, we’re constantly expanding our portfolio of clean energy solutions to guide utilities through increasingly complex, connected challenges. Load flexibility. Electrification. Carbon reduction. With every step, we’re leading the charge to power change.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

6:22 min

Eliminating HR bureaucracy and trusting employees

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

4:55 min

Centralizing credentials management using Azure Key Vault resource integration

Marcel Lupo · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

Videos

See all

Related articles

See all