Identity and Access Management (IAM) Engineer

Paramint LLC
New York, NY, United States
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$156,000.0 - $176,800.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Microsoft Azure Cyber Security Identity and Access Management Lightweight Directory Access Protocols (LDAP) OAuth Windows PowerShell Role-Based Access Control Azure Active Directory Security Assertion Markup Language (SAML) System Availability ManageEngine

Job description

Paramint LLC is seeking a highly experienced Identity and Access Management (IAM) Engineer (Specialist 3) to support the Infrastructure Resilience Identity and Access Management team for a major New York City government agency.

This role will provide engineering, administration, and operational support for highly critical systems and infrastructure supporting multiple city agencies, including 24x7 operational environments such as NYC 311. The selected candidate will work across cloud and on-premises identity platforms, ensuring secure, resilient, and scalable access management solutions.

The IAM Engineer will serve as a senior technical resource responsible for Active Directory, Microsoft Entra ID, ManageEngine solutions, IAM operations, and Tier 2/3 support activities., Identity & Access Management Engineering

  • Design, implement, maintain, and optimize enterprise IAM solutions
  • Develop and manage role-based access control (RBAC) models
  • Translate business and security requirements into IAM technical solutions
  • Support enterprise authentication, authorization, and identity governance initiatives

Active Directory Engineering & Administration (30%)

  • Administer and maintain Active Directory environments
  • Design and implement directory services enhancements
  • Troubleshoot complex AD issues and perform root cause analysis
  • Support hybrid identity and synchronization solutions

Microsoft Entra ID Engineering & Administration (40%)

  • Administer Microsoft Entra ID (formerly Azure Active Directory)
  • Manage authentication, federation, conditional access, and identity lifecycle processes
  • Support SAML, OAuth, and LDAP integrations
  • Implement identity security best practices and governance controls

ManageEngine BSP Engineering & Operations (20%)

  • Administer and support ManageEngine identity and security solutions
  • Perform configuration, troubleshooting, and operational support activities
  • Support ongoing enhancements and maintenance initiatives

IAM Tier 2/3 Support (10%)

  • Provide advanced troubleshooting and incident resolution
  • Participate in after-hours support activities as required
  • Support critical systems requiring high availability and 24x7 operational coverage
  • Assist with escalation management and service restoration efforts

Requirements

Do you have experience in SSO?, * Minimum 12 years of hands-on experience designing, implementing, and supporting Identity and Access Management (IAM) solutions

  • Extensive experience with: Active Directory / Microsoft Entra ID (Azure AD) / LDAP / SAML / OAuth
  • Demonstrated experience delivering complex enterprise IAM projects
  • Strong knowledge of Role-Based Access Control (RBAC) methodologies
  • Exceptional analytical, troubleshooting, and problem-solving skills
  • Ability to translate business requirements into secure technical solutions
  • Strong written and verbal communication skills
  • Experience collaborating with technical and business stakeholders across large organizations

Desirable Skills / Experience

  • PowerShell scripting and automation
  • Microsoft Azure administration
  • Advanced Active Directory architecture and design
  • Browser security and browser control technologies
  • Experience supporting highly available, mission-critical environments
  • Government or public sector experience, Confirmation of ability to work in the required hybrid schedule, * Are you willing to work under a W2 Contract? (This is NOT available for C2C, C2H or 1099, and NO sponsorship)

Benefits & conditions

$75 - $85 an hour - Full-time, Contract

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

Videos

See all

Related articles

See all