IAM) Engineer

Jobot
Houston, United States
20 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$130,000.0 - $160,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Microsoft Windows Active Directory Application Programming Interfaces (APIs) Artificial Intelligence Data Analysis Microsoft Azure Microsoft Online Services Domainkeys Identified Mail Domain-Based Message Authentication Reporting and Conformance (DMARC) Multi-Factor Authentication Identity and Access Management
+17 more
Microsoft Security Essentials Microsoft Visio OAuth OpenID Windows PowerShell Role-Based Access Control Openid Connect Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Single Sign-On User Provisioning Software Enterprise Software Applications Microsoft Power Automate Deployment Automation IronPort Cisco

Job description

As our Microsoft Entra ID (IAM) Engineer, you will serve as the organization’s primary technical expert for Microsoft Entra ID (formerly Azure Active Directory). You will lead the administration, optimization, automation, and modernization of our enterprise identity platform while supporting Active Directory, Microsoft 365, Exchange Online, and identity governance initiatives. This role is ideal for someone who enjoys designing secure identity architectures, solving complex authentication challenges, automating identity operations, and leveraging AI to improve enterprise security and operational efficiency.

Responsibilities Microsoft Entra ID Leadership

  • Serve as the organization’s subject matter expert for Microsoft Entra ID.
  • Design, administer, and optimize enterprise Microsoft Entra ID environments.
  • Lead enterprise identity modernization initiatives.
  • Design secure authentication and authorization architectures.
  • Administer Enterprise Applications within Entra ID.
  • Manage identity lifecycle processes including Joiners, Movers, and Leavers.
  • Design and implement Role-Based Access Control (RBAC).
  • Administer Privileged Identity Management (PIM).
  • Configure and optimize:

o Conditional Access o Multi-Factor Authentication (MFA) o Identity Protection o Identity Governance o Access Reviews o Lifecycle Workflows

  • Support hybrid identity and directory synchronization.

Identity & Access Management

  • Configure and manage Single Sign-On using:

o SAML o OAuth o OpenID Connect (OIDC)

  • Troubleshoot authentication, federation, and directory issues.
  • Partner with application owners to integrate secure authentication solutions.
  • Implement Zero Trust identity strategies.
  • Maintain least-privilege access across enterprise systems.

Microsoft 365 & Messaging

  • Support Microsoft 365 identity services.
  • Administer Exchange Online.
  • Support Exchange Hybrid environments.
  • Troubleshoot authentication and mail flow issues.
  • Support secure email technologies including:

o SPF o DKIM o DMARC

  • Maintain awareness of secure email gateway technologies such as Cisco IronPort.

AI & Automation

  • Utilize Microsoft Copilot to improve operational efficiency.
  • Develop PowerShell automation for identity administration.
  • Automate provisioning, deprovisioning, and identity governance.
  • Evaluate Microsoft Graph API capabilities.
  • Use AI-driven tools for troubleshooting, analytics, and operational improvements.
  • Identify opportunities to automate repetitive IAM processes.

Security & Compliance

  • Apply Zero Trust principles throughout the enterprise.
  • Monitor identity-related threats and security events.
  • Support identity governance initiatives.
  • Conduct access reviews and certification campaigns.
  • Partner with Security teams on audits and compliance initiatives.
  • Improve enterprise security posture through continuous optimization.

Documentation & Architecture

  • Maintain technical documentation and operational runbooks.
  • Create architecture diagrams using Microsoft Visio.
  • Document identity architectures and operational procedures.
  • Develop standards and best practices for enterprise identity management.

Collaboration

  • Partner with Infrastructure, Security, Messaging, and Application teams.
  • Recommend improvements to enterprise identity architecture.
  • Participate in enterprise technology initiatives.
  • Participate in an on-call rotation as needed.

Requirements

  • Bachelor’s degree or equivalent experience.
  • 5+ years of enterprise Microsoft Entra ID administration.
  • Expert-level knowledge of Microsoft Entra ID (Azure AD).
  • Extensive experience designing enterprise identity solutions.
  • Deep expertise with:

o Conditional Access o Identity Protection o Enterprise Applications o Single Sign-On (SSO) o Multi-Factor Authentication (MFA) o Privileged Identity Management (PIM) o Identity Governance o Lifecycle Workflows o Role-Based Access Control (RBAC)

  • Strong Active Directory administration experience.
  • Experience supporting hybrid identity environments.
  • Experience administering Microsoft 365 and Exchange Online.
  • Strong PowerShell scripting and automation experience.
  • Experience with Microsoft Graph API.
  • Strong understanding of Zero Trust architecture.
  • Experience troubleshooting enterprise authentication issues.
  • Knowledge of email authentication technologies:

o SPF o DKIM o DMARC

  • Excellent communication and collaboration skills., * Microsoft Certified: Identity and Access Administrator Associate (SC-300).
  • Microsoft Azure certifications.
  • Microsoft 365 certifications.
  • Microsoft Security certifications.
  • Experience with Microsoft Copilot.
  • Experience implementing AI-powered operational improvements.
  • Experience with Cisco IronPort or similar secure email gateway technologies.
  • Microsoft Visio experience.
  • Experience supporting large enterprise environments.
  • Passion for automation and continuous improvement.

Benefits & conditions

  • Competitive compensation and comprehensive benefits package
  • Generous PTO and vacation program
  • Ongoing training and professional development
  • Opportunity to influence enterprise security strategy
  • Collaborative culture focused on innovation and continuous improvement
  • Long-term career growth within a global organization

About the company

We are a globally recognized real estate investment and development organization known for innovation, operational excellence, and investing in leading-edge technology. Our enterprise technology organization supports a large, complex global environment where security, automation, and scalability are foundational to everything we do.

We’re looking for a Microsoft Entra ID (IAM) Engineer who wants to own and evolve our enterprise identity platform. This is an opportunity to become one of our organization’s technical leaders for Microsoft Entra ID while partnering with Infrastructure, Security, Messaging, and Application teams to modernize identity, strengthen security, and leverage AI-powered automation across the enterprise.

If you’re passionate about Microsoft identity technologies, Zero Trust security, automation, and solving complex enterprise challenges, this is an opportunity to make a lasting impact.

Why join us?

  • Join one of the world’s premier real estate investment and development firms
  • Work with modern Microsoft cloud technologies and AI-powered solutions

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all