> Markdown version of [/jobs/ext/628973-identity-and-access-management-iam-engineer](https://www.wearedevelopers.com/jobs/ext/628973-identity-and-access-management-iam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity and Access Management (IAM) Engineer - **Company:** Acrisure LLC - **Location:** Valhalla, NY, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Federated Identity Management, Identity and Access Management, Python (Programming Language), OAuth, OpenID, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, Azure Automation, Okta, Cyberark, Software Security, Mttr, Multi-Cloud, HR Software, Deployment Automation, CIS Benchmarks, Api Design, SailPoint, Terraform - **Published:** June 24, 2026 - **Apply:** https://www.dice.com/job-detail/f0c6dff8-3ec2-4e3d-85cb-56b68ba1972a ## About the Role * 5+ years of experience in Identity and Access Management engineering, including multi-cloud and hybrid enterprise environments. * Strong knowledge of Azure AD / Entra ID, AWS IAM, and SAML / OIDC / OAuth2 / SCIM protocols. * Proficiency with identity automation using PowerShell, Python, Terraform, or APIs. * Experience with PAM platforms (CyberArk, BeyondTrust, or Azure PIM) and IGA tools (SailPoint, Saviynt, or Okta). * Familiarity with conditional access, MFA enforcement, and passwordless authentication in large-scale environments. * Understanding of zero trust architecture, least privilege design, and role-based access control (RBAC)principles. * Proven ability to interpret business access needs and translate them into secure, scalable IAM solutions. Preferred Qualifications * Exposure to NIST 800-63, CIS Controls, Zero Trust Maturity Model, and NIST CSF. * Experience integrating IAM data with SIEM (e.g. Sentinel) and SOAR workflows. * Relevant certifications such as CISSP, CISM, Azure Security Engineer Associate, AWS Security - Specialty, or Okta Certified Professional. Behavioral Competencies * Enablement first: You design access patterns that simplify compliance and make the secure option the default. * Automation mindset: You codify identity logic and guardrails, reducing manual effort and human error. * System thinker: You see identity as the connective tissue between applications, infrastructure, and users. * Risk translator: You clearly articulate the business impact of over-privilege and authentication weaknesses. #Auris Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership. ## Description You will be a hands-on IAM engineer who designs, automates, and scales secure identity and access controls across cloud and enterprise environments. You'll build paved-road patterns for identity federation, least privilege, and just-in-time access - ensuring that authentication and authorization boundaries are strong, measurable, and frictionless. Success in this role means turning identity into an enabler: making secure access seamless for users, applications, and services while maintaining the highest standards of governance and compliance. What You'll Do (Core Responsibilities) Architect and Automate Identity Foundations * Design and maintain secure-by-default IAM architectures across Azure AD / Entra ID, AWS IAM, and hybrid enterprise systems. * Develop paved road templates for access control patterns (e.g., federated access, role assumption, service accounts, workload identity). * Automate provisioning and deprovisioning pipelines using identity APIs, SCIM, and workflow orchestration tools (e.g., SailPoint, Okta Workflows, Azure Automation, or Terraform). * Implement policy-as-code for IAM guardrails (e.g., least-privilege enforcement, conditional access, MFA requirements, privilege expiration). Access Control, Federation, and Governance * Engineer federated identity solutions for users, applications, and partners using SAML, OIDC, and OAuth2. * Manage conditional access policies, adaptive authentication, and passwordless strategies to balance security with user experience. * Define and enforce least privilege for human and machine identities across AWS, Azure, and SaaS platforms. * Integrate IAM governance with enterprise GRC systems to ensure traceability and audit readiness. * Partner with AppSec and Cloud teams to secure authn/z boundaries across applications, APIs, and services. Privileged Access Management (PAM) * Implement and maintain privileged access vaulting and session control using platforms like CyberArk, BeyondTrust, Delinea, or Azure PIM. * Automate just-in-time elevation for administrative roles and enforce time-bound access approvals. * Continuously monitor and remediate excessive privileges across cloud and on-prem accounts. * Integrate PAM telemetry with SIEM/SOAR for threat detection and behavioral analytics. Lifecycle and Risk Management * Automate joiner/mover/leaver processes and identity lifecycle events through API-driven workflows and HR system integrations. * Conduct periodic access reviews and certifications; deliver evidence for SOC2, PCI, and ISO audits. * Develop and maintain dashboards for leading indicators (automated provisioning rate, MFA coverage, stale accounts) and lagging indicators (MTTR for access removal, orphaned identities, failed recertifications). * Prioritize remediation through risk scoring (criticality exposure privilege depth) and ensure compliance with internal SLAs. Detection and Response Integration * Collaborate with Security Operations to define identity-related detections (impossible travel, lateral movement, privilege abuse). * Correlate identity events with endpoint and cloud telemetry to identify compromised accounts. * Assist in incident response for identity-based breaches, credential theft, and access abuse. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Get security done: streamlining application security with Aikido](https://www.wearedevelopers.com/videos/1638-get-security-done-streamlining-application-security-with-aikido) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere)