> Markdown version of [/jobs/ext/514390-iam-engineer](https://www.wearedevelopers.com/jobs/ext/514390-iam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Engineer - **Company:** Colorado School of Mines - **Location:** Golden, CO, United States - **Experience:** Experienced - **Salary:** $101,050.0 - $112,285.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Application Programming Interfaces (APIs), Application Integration Architecture, User Authentication, Cyber Security, System Configuration, Multi-Factor Authentication, Identity and Access Management, Lightweight Directory Access Protocols (LDAP), Modular Design, OAuth, Ping (Networking Utility), Openid Connect, Security Assertion Markup Language (SAML), Single Sign-On, Systems Integration, User Provisioning Software, Enterprise Application Integration, Scripting, Okta, Software Troubleshooting, Technical Debt, Information Technology, SailPoint - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=105def2c09edb831 ## About the Role Do you have experience in Security technology solutions implementations?, Do you have a Master's degree in cybersecurity?, * Bachelor's degree in computer science, information technology, cybersecurity, or a closely related field, or an equivalent combination of education and directly related experience. * 5+ years of progressively responsible experience in information technology, cybersecurity, or identity and access management, including areas such as IAM engineering, systems administration, enterprise application integration, directory services, or authentication services. * 4+ years of hands-on experience implementing, configuring, and supporting enterprise IAM platforms and related services, including single sign-on (SSO), multifactor authentication (MFA), directory integrations, and application onboarding. * Experience with scripting, APIs, or automation tools used to support integrations, workflow automation, and operational efficiency. * Hands-on experience with enterprise IAM technologies and protocols such as Okta, SailPoint, Ping Identity, Active Directory, LDAP, SAML, OAuth, OpenID Connect, or similar tools and standards. * Working knowledge of IAM architecture and core identity services, including single sign-on (SSO), multifactor authentication (MFA), directory services, role-based access, provisioning, and deprovisioning. * Knowledge of information security principles and access governance practices, including least privilege, role governance, secure authentication, and audit readiness. * Ability to troubleshoot complex technical issues, evaluate solution options, and implement sustainable improvements in a dynamic environment. * Ability to communicate technical concepts clearly and effectively with technical teams, support staff, vendors, and business stakeholders., * Master's degree in computer science, information technology, cybersecurity, or a closely related field. * Direct hands-on experience with Okta administration, configuration, and application integration is strongly preferred. * Experience designing and supporting IAM workflows, automation, and identity lifecycle processes in a complex enterprise environment. * Experience leading or supporting implementation of a new IAM platform, major IAM enhancement, or modernization initiative. * Experience with access governance, role design, provisioning and deprovisioning, application onboarding, and automated access controls in a complex enterprise environment. * Relevant industry certifications such as CISSP, CISM, or IAM-related certifications., Successful completion of a background investigation is required for this position. ## Description The Identity Access Management (IAM) Engineer designs, implements, and supports enterprise identity services that enable secure, reliable access to university systems, data, and applications. This role engineers and administers IAM solutions across the institution, including single sign-on (SSO) integrations for applications at Mines, authentication services, directory integrations, and identity lifecycle processes. The IAM Engineer advances identity services through automation, scalable design, and continuous improvement, and partners with stakeholders across IT and the institution to deliver solutions aligned with security, compliance, and operational best practices. This position currently operates in a hybrid work model with regular campus presence required. Work arrangements are subject to change based on institutional needs. The successful candidate must be able to commute to campus in Golden, Colorado. Primary Responsibilities IDENTITY SYSTEM ADMINISTRATION * Design, implement, administer, and continuously improve enterprise IAM services and integrations that protect institutional systems, data, and applications. * Configure and maintain IAM platforms, authentication services, directory services, and related integrations, including documentation, configuration standards, and operational procedures. * Lead and support single sign-on (SSO) and multifactor authentication (MFA) integrations for applications at Mines through the university's enterprise identity platform, Okta, in partnership with vendors and campus stakeholders. * Troubleshoot and resolve IAM-related issues, implement enhancements, and optimize services to improve reliability, performance, and user experience while minimizing technical debt. * Create and maintain technical documentation, knowledge base content, and operational guidance, and provide knowledge transfer and training to support staff, system administrators, and other IT partners. * Collaborate with teams across IT and institutional stakeholders to ensure identity services align with security, infrastructure, application, compliance, and business requirements. STRATEGY DEVELOPMENT * Plan, design, and enhance IAM solutions, workflows, and automation that support scalable, consistent, and secure service delivery. * Develop and refine role-based access models, identity lifecycle standards, and access governance practices that support appropriate access and operational efficiency. * Evaluate current-state services and authentication patterns to identify modernization opportunities, improve usability, and strengthen long-term sustainability. OUTREACH AND COMMUNICATIONS * Provide guidance and training to support staff and partners to strengthen understanding of IAM services, support processes, and common user issues. * Communicate planned maintenance, service disruptions, and other service impacts to appropriate stakeholders and support teams. * Engage with campus partners and the broader professional community to understand identity-related needs, share knowledge, and support service improvement. * Participate in relevant working groups, communities of practice, and institutional initiatives related to IAM and supporting technologies., It is the intent of Mines to comply with the applicable requirements of the Americans with Disabilities Act and the Americans with Disabilities Act Amendments Act of 2008, and their implementation rules and regulations, in support of equal opportunities for qualified applicants with disabilities. To meet this goal, Mines will make reasonable accommodations during the employment selection process and within our working environment. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [No More Post-its: Boost your login security with APIs](https://www.wearedevelopers.com/videos/1043-no-more-post-its-boost-your-login-security-with-apis) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)