
Enterprise IAM Operations Engineer, Entra ID, RBAC, Application Integration
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Design, sustain, and enhance Azure RBAC across subscriptions, management groups, resource groups, and various Azure services.
• Establish an enterprise role taxonomy and execute governed access through groups, roles, and authorized assignments.
• Manage Microsoft Entra ID/Azure AD, on-premises Active Directory, hybrid identity, and identities for workforce, partners, guests, services, and applications.
• Implement Microsoft Entra PIM, Just-in-Time privileged access, MFA, Conditional Access, break-glass procedures, privileged access monitoring, and audit evidence.
• Design, implement, and troubleshoot SAML, OIDC, OAuth, Entra SSO, enterprise applications, app registrations, service principals, claims, groups, and application roles.
• Advocate for managed identities, oversee service principals, facilitate credential rotation, and enhance CI/CD secret management.
• Assist in the Saviynt-to-SailPoint transition and related identity, entitlement, role, certification, policy, procedure, and control documentation.
• Support IAM monitoring, logging, alerting, investigation, and ITDR use cases utilizing Azure-native tools and Splunk.
• Provide support for AWS IAM, GCP IAM, and multi-cloud identity governance as necessary.
• Assist with FedRAMP-relevant access controls, configuration baselines, change control, audit readiness, and privileged access governance.
• Develop automation and scripting solutions to enhance IAM workflows, reporting, documentation, access reviews, runbooks, and operational efficiency.
• Identify potential applications of AI tools for IAM analysis, reporting, documentation, and workflow optimization.
• Collaborate with stakeholders from Information Security, infrastructure, cloud, application, DevOps, audit, and other technical domains.
• Practical experience with enterprise application federation and SSO is essential.
• Bachelor’s degree in Information Security, Computer Science, Information Technology, or equivalent practical experience is required.
• Extensive hands-on experience with Microsoft Entra ID/Azure AD administration is necessary.
• Solid understanding of Azure RBAC, security groups, role assignments, management groups, subscriptions, and resource-level access.
• Familiarity with Microsoft Entra PIM, JIT privileged access, MFA, Conditional Access, and privileged authentication.
• Strong grasp of Active Directory and hybrid identity.
• Enterprise-level experience with SAML, OIDC, OAuth, SSO, Entra Enterprise Applications, app registrations, managed identities, service principals, claims, and application roles.
• Experience with least-privilege access design, access reviews, access certification, identity/entitlement inventory, credential management, and secret hygiene.
• Experience with Azure monitoring/logging and Splunk or similar SIEM platforms.
• Understanding of Identity Threat Detection and Response (ITDR) is preferred.
• Experience with IAM automation/scripting and CI/CD identity controls.
• Strong documentation skills in IAM, including policies, standards, procedures, runbooks, and audit evidence.
• Preferred: 7+ years of experience in Identity and Access Management.
• Preferred: 4+ years of experience with Microsoft Entra ID/Azure AD.
• Preferred: 3+ years of experience with Azure RBAC, privileged access, or cloud access governance.
• Experience in financial services, banking, or regulated enterprises is strongly preferred.
• Strong understanding and practical implementation of RBAC and least-privilege access at an enterprise scale.
• Excellent troubleshooting skills for authentication, federation, SSO, privileged access, and identity monitoring.
• Ability to collaborate across IAM, Security, Cloud, Infrastructure, Applications, DevOps, and Audit teams.
• Strong communication, documentation, analytical, and problem-solving abilities.
• Capable of working within change control, audit, compliance, and operational stability environments.
• Ability to balance security requirements with both technical and business needs.
• Ongoing training opportunities.
• Competitive benefits package.
• Opportunities for personal and professional development.
• A team-oriented, collaborative, and inclusive culture.
Sedgwick
Shadeform
CVS Health
Get handpicked remote jobs straight to your inbox weekly.