> Markdown version of [/jobs/ext/606434-identity-and-access-management-architect](https://www.wearedevelopers.com/jobs/ext/606434-identity-and-access-management-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity and Access Management Architect - **Company:** Open Dealer Exchange - **Location:** Southfield, MI, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Active Directory, Application Programming Interfaces (APIs), Microsoft Azure, Cyber Security, Information Systems, Data Security, Human Resources Information System (HRIS), Identity and Access Management, OAuth, OpenID, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Security Assertion Markup Language (SAML), Session Management, Microsoft Power Automate, HR Software, Information Technology, SailPoint, Serverless Computing, Workday - **Published:** June 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=162c890bb17a180d ## About the Role Do you have experience in Technical documentation?, Do you have a Bachelor's degree?, * 5+ years of hands-on IAM engineering experience, with at least 3 years focused on Entra ID (Azure AD) in enterprise environments. * Deep working knowledge of Active Directory, including group policy, OU design, domain trust models, and hybrid identity patterns. * Demonstrated experience designing and implementing RBAC models at scale in complex or legacy environments. * Hands-on experience with Entra ID Governance, including access reviews, entitlement management, lifecycle workflows, and Privileged Identity Management (PIM). * Strong working knowledge of OAuth 2.0, OIDC, and SAML, sufficient to review developer implementations and identify security risk. * Practical experience automating identity lifecycle events using Logic Apps, Azure Functions, PowerShell, or the Microsoft Graph API. * Ability to communicate risk clearly to non-technical stakeholders and produce compliance-ready documentation. * Will accept any suitable combination of education, training, or experience. Preferred Skills & Experience * Experience in regulated industries such as financial services, fintech, or automotive with access control obligations. * Familiarity with FTC Safeguards Rule requirements or equivalent data security regulatory frameworks. * Prior experience integrating an HRIS platform (Workday, BambooHR, UKG, or similar) with Entra ID via SCIM or custom connector. * Exposure to IGA platforms such as SailPoint, Saviynt, or Omada. * Experience advising development teams on token validation, scope design, role claims, and secure session management. * Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent professional experience. * Relevant certifications: SC-300 (Microsoft Identity and Access Administrator), AZ-500 (Microsoft Azure Security Technologies), or equivalent ## Description * Design and implement enterprise RBAC: Build a cohesive role-based access control model across Entra ID, Active Directory, and Entra External ID, replacing ad hoc access grants with governed, role-aligned entitlements. * Lead identity lifecycle automation: Integrate the HR system with Entra ID to automate provisioning and deprovisioning, ensuring access changes are event-driven and auditable at the point of hire, transfer, and termination. * Govern directory structure and access hygiene: Define and enforce naming conventions, group structures, and access review cadences across all directory platforms. * Manage non-human identities: Govern service accounts, including managed identities, service principals, and app registrations, enforcing least privilege and credential hygiene across all environments. * Advise development teams on identity security: Provide architectural guidance on token handling, session management, and federation patterns for teams building or maintaining identity adjacent systems. * Drive Conditional Access and PIM: Lead Conditional Access policy design and own Privileged Identity Management configuration and the privileged access model for admin roles across Azure and M365. * Support Entra External ID governance: Advise teams on External ID tenant configuration, custom policy, user flows, and external identity federation. * Produce compliance-ready documentation: Maintain IAM documentation including access control matrices, provisioning runbooks, and audit-ready entitlement inventories supporting FCRA and FTC Safeguards Rule obligations. * Collaborate across the security program: Align IAM initiatives with the broader security roadmap and participate in change management and architecture review processes alongside security engineers and the Cybersecurity Manager. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Destigmatizing the Workplace: Building Real Inclusion](https://www.wearedevelopers.com/videos/1492-destigmatizing-the-workplace-building-real-inclusion) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026)