Senior IAM Engineer - (Entra ID/AD)

CliftonLarsonAllen LLP
Dallas, TX, United States
14 days ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Active Directory Domain Controllers Application Services Authentication Protocols Microsoft Azure Bash Shell Cloud Computing Domain Name System (DNS) Identity and Access Management Python (Programming Language) OAuth Windows PowerShell
+11 more
Role-Based Access Control Openid Connect Azure Active Directory Security Assertion Markup Language (SAML) Systems Integration User Provisioning Software Enterprise Software Applications Infrastructure as Code (IaC) Infrastructure Automation Frameworks Information Technology Terraform

Job description

The Identity & Access Management (IAM) Senior Engineer will be responsible for planning and executing programs both in the cloud and on premises

How you’ll create opportunities in this Identity & Access Management (IAM) Senior Engineer position

  • Execute the implementation and maintenance of complex Identity & Access Management (IAM) infrastructure.
  • Plan and execute IAM projects and programs, ensuring alignment with business requirements, security standards, and delivery timelines.
  • Automate and optimize identity lifecycle management processes, access provisioning, and governance controls.
  • Integrate Entra ID with enterprise systems, cloud platforms, and third-party applications.
  • Collaborate with cross-functional teams to support and drive IAM program goals and enterprise security initiatives.
  • Monitor, troubleshoot, and maintain IAM infrastructure, ensuring optimal performance, reliability, and security.
  • Document and maintain comprehensive IAM architecture, workflows, standards, and operating procedures.
  • Implement and enforce IAM security, compliance, governance, and risk management best practices.
  • Provide technical leadership and mentorship to junior team members.
  • Participate in an on-call rotation supporting critical IAM systems and services.

Identity Governance & Access Management:

  • Design and support Role-Based Access Control (RBAC) models and access governance frameworks.
  • Manage Privileged Identity Management (PIM) processes and privileged access controls.
  • Implement and support passwordless authentication, managed identities, and modern identity security practices.
  • Develop and maintain identity lifecycle processes, including onboarding, transfers, and offboarding.
  • Ensure access controls comply with regulatory, audit, and security requirements.
  • Support Identity Governance and Administration (IGA) capabilities and access certification processes.

Identity Architecture & Platform Administration:

  • Administer and support Microsoft Entra ID, Active Directory, and hybrid identity environments.
  • Manage on-premises Active Directory infrastructure, including Domain Controllers, organizational units, and directory services.
  • Design, maintain, and enforce Group Policy Objects (GPOs) to support enterprise security and operational requirements.
  • Design, implement, and maintain identity federation and authentication solutions.
  • Support SAML, OAuth, and OpenID Connect integrations across enterprise applications.
  • Implement and maintain Entra B2B, Entra External Identity, and Conditional Access Policies.
  • Partner with business and technical teams to evaluate identity and access requirements for new systems and applications.
  • Develop scalable and secure identity solutions that support cloud and hybrid environments.

Infrastructure Automation & Engineering:

  • Develop and maintain Infrastructure as Code (IaC) solutions utilizing Terraform and related automation frameworks.
  • Create and support automation solutions using PowerShell, Python, and Bash scripting.
  • Improve operational efficiency through automation and process standardization.
  • Support Active Directory, Group Policy, DNS, Entra ID, and Azure identity services across the enterprise.
  • Continuously evaluate and implement improvements to IAM infrastructure and operational processes.

Requirements

  • Strong hands-on experience administering Active Directory, Domain Controllers, Group Policy Objects (GPO), and DNS services.
  • Strong hands-on experience with Microsoft Entra ID administration and identity lifecycle management.
  • Advanced PowerShell scripting and automation experience.
  • Experience designing and managing Conditional Access Policies.
  • Experience with Identity Governance and Administration (IGA) platforms and controls.
  • Knowledge of SAML, OAuth, OpenID Connect, and modern authentication protocols.
  • Experience with RBAC, PIM, passwordless authentication, managed identities, and identity governance technologies.
  • Experience with Terraform, Infrastructure as Code (IaC), and automation frameworks.
  • Experience supporting cloud, hybrid, and enterprise IAM environments.
  • Experience with PingOne is preferred.

As our ideal candidate, you have:

Experience:

  • 4+ years of experience required
  • Experience managing hybrid identity environments across Microsoft Entra ID and Active Directory.
  • Experience administering Domain Controllers, Group Policy, DNS, and enterprise authentication services.
  • Experience implementing Conditional Access, RBAC, PIM, and identity governance solutions.
  • Experience developing PowerShell automations and Infrastructure as Code solutions.
  • Experience integrating enterprise applications using SAML, OAuth, and OpenID Connect., * Experience with PingOne and other enterprise identity platforms.
  • Experience with Entra B2B and Entra External Identity.
  • Experience supporting identity governance, access certification, and compliance programs.
  • Relevant Microsoft, Security, Identity, or Cloud certifications preferred.

Education:

*Bachelor’s degree is required. Combination of relevant experience, education, and training may be accepted in lieu of degree.

  • Degrees in Computer Science, Information Technology, or a related field are preferred.

About the company

CLA is a top 10 national professional services firm where our purpose is to create opportunities every day, for our clients, our people, and our communities through industry-focused wealth advisory, digital, audit, tax, consulting, and outsourcing services. Even with more than 8,500 people, 130 U.S. locations, and a global reach, we promise to know you and help you.

CLA is dedicated to building a culture that invites different beliefs and perspectives to the table, so we can truly know and help our clients, communities, and each other.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · World Congress 2022

1:31 min

Integrating edge environments with enterprise identity and authorization platforms

Christian Koep Christian Koep · World Congress 2025

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney Dan Cranney +2 · LIVE

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

Videos

See all

Related articles

See all