> Markdown version of [/jobs/ext/659907-identity-access-management-engineer](https://www.wearedevelopers.com/jobs/ext/659907-identity-access-management-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity Access Management Engineer - **Company:** Roku, Inc. - **Location:** Boston, MA, United States (Remote available) - **Experience:** Expert - **Salary:** $158,000.0 - $279,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Microsoft Azure, Microsoft Online Services, Cloud Computing, Cyber Security, DevOps, Domain Name System (DNS), Multi-Factor Authentication, Identity and Access Management, Key Management, OAuth, Windows PowerShell, Role-Based Access Control, Openid Connect, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, Backup and Restore, Policy as Code, Data Logging, Scripting, Enterprise Software Applications, Data Classification, Cyberark, Microsoft Power Automate, Azure Powershell, Microsoft InTune, Information Technology, Google Cloud Functions, Atlassian Tools, Hashicorp - **Published:** June 26, 2026 - **Apply:** https://www.weareroku.com/jobs/senior-identity-access-management-engineer-boston-massachusetts-united-states-e753585d-49d1-4bb6-b161-f1d0a64e82aa ## About the Role * 8+ years of hands-on experience with identity and access management and automating cloud technologies, particularly within the Microsoft ecosystem. * Strong analytical skills and attention to detail, with the ability to troubleshoot complex infrastructure and identity-related issues. * Excellent communication skills, with the ability to clearly explain technical concepts to both technical and non-technical stakeholders. * Deep experience with Microsoft Entra ID, including Conditional Access, Identity Governance, and Privileged Identity Management. * Familiarity with Microsoft 365 services: Exchange Online, Defender, Purview, Sentinel, Intune, and related platforms. * Automation and scripting skills using PowerShell, Azure CLI, and Microsoft Graph API; working knowledge of Azure services such as Function Apps and Logic Apps. * Experience in onboarding and managing enterprise applications in Azure Entra ID. * Advanced knowledge of Azure Single Sign-On (SSO) login methods, including OAuth2, OpenID Connect, and SAML, and their integration with enterprise applications. * Knowledge of privileged access tools (Azure PIM, CyberArk, etc), secrets management (HashiCorp or Azure Key Vault), and workload identity patterns SPIFEE & SPIRE. * Familiarity with NHI governance concepts for service accounts and AI agents, and exposure to OPA / Rego or similar policy-as-code frameworks. * Good to have familiarity with Microsoft Purview for DLP and data classification. * Strong understanding of multi-factor authentication and FIDO2. * Familiarity with IT security frameworks and compliance standards. * Knowledge of logging, monitoring, and alerting practices for identity and access events. * Basic understanding of email security and DNS. * Experience with backup and recovery strategies for identity-related services. * Understanding of Zero Trust Architecture principles. * Familiarity with Jira and Confluence. * B.S. in Computer Science, Information Technology, Engineering, or equivalent experience. ## Description Roku is seeking a senior-level Identity Engineer to enhance its Zero-Trust architecture, drive standardization initiatives, and optimize its Microsoft-centric identity platform for a geographically distributed workforce. The ideal candidate has hands-on experience in identity and access management (IAM) and securing cloud environments within the Microsoft ecosystem, with deep expertise in Azure Entra ID. Equally important is a strong automation mindset-designing, scripting, and building repeatable workflows. The role also requires the ability to communicate complex technical concepts clearly to both technical and non-technical audiences., * Lead enterprise-wide IAM standardization, including identity lifecycle, access governance, and policy enforcement across global regions. * Drive automation across IAM to streamline administration and deliver a smoother user experience. * Support enterprise applications onboarding into Azure Entra ID, including SSO, Conditional Access, and role-based access control (RBAC). * Enhance privileged access management and implement scalable monitoring, alerting, and auditability solutions to support a secure, geographically distributed workforce. * Collaborate with IT, Networking, and Security teams to troubleshoot identity-related issues and support global infrastructure initiatives. * Advance Zero Trust Identity Fabric principles like continuous verification, least-privilege access, and identity-aware policy enforcement across users, devices, workloads, and non-human identities. * Build identity automation with a DevOps mindset, writing scripts, developing pipelines, and engineering tooling from scratch rather than just configuring them. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)