> Markdown version of [/jobs/ext/471513-identity-and-access-management-consultant](https://www.wearedevelopers.com/jobs/ext/471513-identity-and-access-management-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity and Access Management Consultant - **Company:** Collective Insights - **Location:** Atlanta, GA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Adobe InDesign, Application Programming Interfaces (APIs), Automation of Tests, Microsoft Azure, Software as a Service, Code Review, Cyber Security, Continuous Integration, Software Debugging, Human Resources Information System (HRIS), Github, Identity and Access Management, Issue Tracking Systems, Python (Programming Language), Key Management, Lightweight Directory Access Protocols (LDAP), Log Analysis, OpenID, PCI Data Security Standards, Performance Tuning, Ping (Networking Utility), Windows PowerShell, Azure Active Directory, Kusto Query Language, Security Assertion Markup Language (SAML), Simple Object Access Protocol (SOAP), Extensible Markup Language (XML), Policy as Code, Okta, Cyberark, Microsoft Power Automate, Siteminder, Information Technology, Deployment Automation, Sentry, Bicep, Hashicorp, Graphql, SailPoint, Terraform, Key Vault - **Published:** June 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=da7dfd029865b134 ## About the Role Do you have experience in XML?, Do you have a Bachelor's degree?, * Experience: 2-5+ years implementing IAM across at least two areas (SSO/MFA, IGA, PAM/EPM, machine identity), including scripting and CI/CD. * Education: Bachelor's in Computer Science, Information Security, or related field-or equivalent practical experience. * Technical Expertise: Hands-on with Entra ID (Conditional Access, PIM, B2B/B2C/External ID), Okta/Ping; SailPoint or Saviynt; CyberArk/BeyondTrust/Delinea EPM; Azure Key Vault, managed identity, AKS federation; APIs/Graph; Terraform/Bicep; PowerShell/Python; CI/CD with Azure DevOps/GitHub Actions; observability (KQL/Log Analytics). Development of scripts using tools like powershell/python/javascript/Logic Apps/Power Automate/Flow/Automation Accounts utilizing APIs including Graph API/Rest/SOAP/XML. * Solution Design and Implementation Experience: Ability to translate architecture into secure, testable designs with clear acceptance criteria and rollback plans. Track record of integrating HRIS/AD/LDAP/SaaS, migrating legacy WAM, and delivering high-quality builds with automated testing and code review discipline. * Problem-Solving & Communication: Strong debugging, performance tuning, and root-cause analysis; bias for automation and simplification. Concise documentation and status reporting; ability to explain technical decisions to mixed audiences. * Industry Knowledge: Appreciation of regulated-industry expectations and common audit asks for identity controls and evidence. * Client-Facing Skills: Comfortable leading working sessions, Knowledge Transfer, and UAT support; proactive in surfacing risks/assumptions. * Demonstrated Passion: Contributions to scripts/modules, community forums, or knowledge sharing; stays current on passkeys, tenant isolation, and identity threat defenses. * Certifications (highly desirable): Microsoft SC-300, AZ-500; Okta, Ping, SailPoint, Saviynt; CyberArk Defender/Sentry; BeyondTrust/Delinea; HashiCorp Terraform Associate; AZ-104. Additional Requirements: Availability for periodic client travel and professional engagements. Commitment to continuous learning and keeping pace with evolving identity platforms, patterns, and threats. **Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future. ## Description Job Description: As an Identity and Access Management Consultant, you will build and integrate identity solutions across Identity & Access Management, Identity Governance & Administration, Privileged Access Management and machine identity/secrets. You will configure platforms, engineer policies and connectors, automate deployments (IaC/CI-CD), and validate end-to-end flows with high quality and documentation. Primary platforms include Microsoft Entra ID & Entra ID Governance (primary), Okta, Ping, SiteMinder/OAM, SailPoint/Saviynt, CyberArk/BeyondTrust/Delinea EPM, and Azure Key Vault / Entra workload identity federation. What You Will Be Doing: * Solution Design: Configure OIDC/SAML apps, Conditional Access, device trust, FIDO2/Passkeys, step-up auth; implement lifecycle workflows (joiner/mover/leaver), access packages, access reviews, SCIM connectors; onboard privileged accounts/secrets, session recording, JIT elevation, endpoint privilege controls; implement Key Vault/managed identity, AKS federation, certificate enrollment/renewal, and secret rotation automation. * Client Engagement: Translate architecture into build tasks and acceptance criteria; communicate trade-offs and impacts in clear, actionable terms. * Implementation: Automate with Terraform/Bicep, PowerShell/Python, and CI/CD (Azure DevOps/GitHub Actions); enforce policy-as-code, testing (unit/integration), linting, and code reviews; execute cutovers, blue-green/rollback, and performance tuning. * Compliance & Risk Management: Implement controls that satisfy regulatory and security requirements (e.g., NIST 800-63, ISO 27001, HIPAA/HITRUST, PCI-DSS, SOX, FedRAMP, NYDFS 500). Ensure privileged access, secrets, and logs meet auditability and SoD expectations. * Technical Leadership: Demonstrate technical depth, mentor other resources, and contribute scripts, modules, and how-tos; participate in design and threat-model reviews. * Documentation & Reporting: Maintain as-built docs, config baselines, runbooks, and knowledge transfer materials; provide status, risk/issue tracking, and metrics (e.g., MFA coverage, JML SLAs, privileged onboarding). * Continuous Improvement: Instrument monitoring/alerting (Log Analytics/KQL), validate DR/backups, and tune policies for usability and security; contribute accelerators that reduce delivery time/cost. * Practice Development: Support demonstrations, POCs, and SoW inputs (effort estimates, assumptions, dependencies). ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From Doubt to Confidence: How Sentry Uses Verdaccio to Bulletproof SDK Releases](https://www.wearedevelopers.com/videos/739-from-doubt-to-confidence-how-sentry-uses-verdaccio-to-bulletproof-sdk-releases) - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)