> Markdown version of [/jobs/ext/2865863-iam-engineer](https://www.wearedevelopers.com/jobs/ext/2865863-iam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Engineer - **Company:** Intersources Inc. - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $26,000.0 - **Contract:** Temporary contract - **Skills:** Microsoft Access, Application Programming Interfaces (APIs), Application Integration Architecture, User Authentication, Microsoft Azure, Microsoft Online Services, Software as a Service, Cyber Security, Identity and Access Management, OAuth, Windows PowerShell, Role-Based Access Control, Openid Connect, Azure Active Directory, Phishing, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, Systems Integration, Enterprise Software Applications, Information Technology, Api Management - **Published:** September 12, 2026 - **Apply:** https://www2.jobdiva.com/portal/?a=62jdnw10t7d77ytz0lbaey9qxonk3b05a9tqw96rb7z6hlfo7xj79l9g6mp6aj2o&compid=0/jobs/33085293#/jobs/33085293 ## About the Role * 5+ years of identity and access-management experience, including 3+ years administering or engineering Microsoft Entra ID. * Hands-on experience with SSO, MFA, Conditional Access, PIM, RBAC, identity governance, access reviews, and identity lifecycle management. * Experience automating identity processes with PowerShell, Microsoft Graph, APIs, or comparable integration methods. * Experience troubleshooting authentication, federation, authorization, provisioning, claims, group membership, and access issues. * Experience supporting Microsoft Azure and SaaS environments and understanding the distinction between Entra roles, Azure resource roles, and application-specific authorization. * Experience governing privileged accounts and non-human identities such as service principals, managed identities, and service accounts. * Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, or equivalent relevant experience., * Microsoft Certified: Identity and Access Administrator Associate (SC-300) or comparable demonstrated expertise. * Experience with Microsoft Entra ID Governance, access packages, Lifecycle Workflows, automated provisioning, or IGA capabilities. * Experience with enterprise IGA, PAM, or identity platforms beyond Microsoft Entra ID. * Healthcare, HIPAA-regulated, or other regulated-industry experience. * Experience implementing Zero Trust identity patterns and phishing-resistant authentication. * Security or cloud certifications such as CISSP, Security+, or Azure Administrator Associate. ## Description Client is seeking an experienced Identity & Access Management (IAM) Engineer to design, implement, operate, automate, and continuously improve enterprise identity and access management capabilities across cloud and SaaS environments. The IAM Engineer is the hands-on engineering owner for Microsoft Entra ID identity lifecycle management, authentication, authorization, Single Sign-On, Conditional Access, Privileged Identity Management, access reviews, identity governance, application provisioning, identity automation, and non-human identity governance. A primary objective of this role is to replace repetitive manual identity processes with governed, automated, auditable workflows while enabling the service desk, managers, system owners, HR, Security, and Compliance to perform their responsibilities consistently. What This Role Owns * Microsoft Entra ID identity engineering, governance, authentication, Conditional Access, and privileged access management. * Joiner, mover, and leaver lifecycle engineering and automation for employees, contractors, vendors, and other workforce identities. * SSO, application provisioning, identity federation, access packages, entitlement management, and access-review capabilities. * RBAC and least-privilege models, access certification, and auditable identity-control evidence. * Governance of service accounts, service principals, managed identities, application registrations, workload identities, and related credentials. * IAM automation, standards, procedures, dashboards, integrations, and senior escalation for complex identity and access problems. Key Responsibilities Identity Platform Engineering * Administer and continuously improve Microsoft Entra ID and related identity governance capabilities. * Develop identity architecture standards, operational procedures, ownership models, and reusable engineering patterns. * Engineer authentication, authorization, directory, federation, and external identity integrations. * Serve as the senior escalation point for complex sign-in, federation, provisioning, entitlement, and access issues. Identity Lifecycle & Access Management * Design and automate joiner, mover, and leaver workflows for hires, transfers, role changes, contractors, leaves, reactivations, and terminations. * Integrate identity lifecycle controls with authoritative HR data, ticketing processes, cloud platforms, and connected applications. * Define and maintain RBAC models, standard access profiles, birthright access, least-privilege patterns, and exception paths. * Implement automated provisioning and deprovisioning using supported connectors, Microsoft Graph, APIs, SCIM, groups, access packages, or other approved methods. * Establish reconciliation and exception handling to identify stale, orphaned, excessive, duplicate, or inappropriate access. * Apply effective dates and expiration controls for temporary, contractor, vendor, guest, and partner access where appropriate. Privileged Access & Strong Authentication * Own technical engineering and administration of Microsoft Entra Privileged Identity Management for Entra roles, Azure resource roles, and supported groups. * Implement just-in-time privileged access, approvals, activation controls, time limits, evidence, and emergency/break-glass patterns. * Engineer and maintain Conditional Access policies, MFA requirements, authentication-strength controls, risk-based protections, controlled exclusions, and phishing-resistant authentication strategies. * Reduce standing privileges and validate that temporary privileged access expires as intended. * Partner with Security Operations on risky sign-ins, suspicious privileged activity, and identity-related incidents. SSO, Application Integration & Identity Governance * Lead the identity side of SSO integrations using SAML, OpenID Connect, OAuth, and other approved authentication methods. * Configure enterprise applications, application registrations, claims, identity mappings, group or role assignments, and supported automated provisioning. * Implement and maintain access packages, entitlement-management workflows, approvals, assignment duration, renewal, and separation-of-duties controls where appropriate. * Run periodic access reviews and certifications for privileged roles, sensitive groups, enterprise applications, access packages, guests, and partner access. * Partner with application and data owners to maintain role definitions and ensure business owners remain responsible for approving business need. Non-Human Identity Management * Govern service accounts, application registrations, service principals, managed identities, APIs, automation identities, and workload identities. * Maintain ownership, purpose, permissions, environment, credential type, and lifecycle information for non-human identities. * Reduce reliance on long-lived client secrets and user-based service execution by expanding managed identities, workload identity federation, certificates, or other approved methods where supported. * Track credential and certificate expiration, remove inactive identities and permissions, and establish rotation and compromise-response procedures. * Review high-privilege Microsoft Graph and Azure API permissions and support appropriate admin-consent governance. Automation, Evidence & Compliance * Automate identity administration and governance using PowerShell, Microsoft Graph, APIs, and platform native workflow capabilities. * Build dashboards, reports, and evidence showing identities, entitlements, privileged access, access reviews, provisioning outcomes, and exceptions. * Support technical evidence requirements for HIPAA, SOC 2, URAC, internal security standards, client requirements, and authorized audits. * Maintain IAM standards, procedures, technical documentation, support guidance, and automation so routine work can be delegated safely. * Continuously reduce repetitive manual provisioning and access-request work through controlled automation and self-service. Role Boundaries * Design and automate identity services rather than serving as the primary Tier 1 resource for routine password resets or standard account-provisioning tickets. * Enable the service desk to resolve routine, documented identity requests while taking complex escalations and engineering improvements. * Do not act as the business approver for application access; managers, application owners, data owners, and other authorized approvers retain business-need decisions. * Do not own HR source data, Azure network architecture, endpoint management, or every application's internal authorization model. * Build workflows, standards, integrations, automation, and delegated controls so IAM does not become a manual bottleneck. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [From APIs to MCP: Enterprise Governance, Registry, and Controls](https://www.wearedevelopers.com/videos/100336-from-apis-to-mcp-enterprise-governance-registry-and-controls) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Why make use of an integration platform in today's software developments and infrastructure?](https://www.wearedevelopers.com/videos/758-why-make-use-of-an-integration-platform-in-today-s-software-developments-and-infrastructure) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)