
Senior Identity & Access Management Engineer
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Massachusetts.
• Take charge of the administration, engineering, governance, and ongoing enhancement of enterprise identity and access management services.
• Act as the primary technical authority for Microsoft Entra ID and associated identity platforms.
• Design, implement, and support authentication and authorization solutions for both cloud and on-premises environments.
• Manage and maintain Conditional Access policies, Multi-Factor Authentication (MFA), Identity Protection, passwordless authentication, and contemporary access management solutions.
• Create and support Single Sign-On (SSO) integrations using SAML, OAuth, OpenID Connect, LDAP, Kerberos, and SCIM technologies.
• Oversee enterprise application onboarding, identity integrations, access provisioning, and entitlement management processes.
• Collaborate with HR, Infrastructure, and application owners to design and automate Joiner, Mover, and Leaver (JML) processes.
• Establish and uphold role-based access controls (RBAC), access governance standards, segregation of duties, and least-privilege access models.
• Manage Privileged Identity Management (PIM), privileged access controls, privileged account governance, and delegated administration models.
• Conduct access reviews, entitlement assessments, and certification activities to ensure appropriate access to systems and applications.
• Oversee and maintain enterprise Public Key Infrastructure (PKI), including certificate authorities, certificate lifecycle management, issuance, renewal, revocation, and governance.
• Manage digital certificates for users, devices, applications, servers, network infrastructure, and cloud services.
• Support certificate-based authentication, passwordless authentication, and device trust technologies across enterprise platforms.
• Collaborate with Network Engineering teams to facilitate secure wired, wireless, VPN, remote access, and device authentication services.
• Monitor the health of identity, authentication, PKI, and NAC platforms while proactively identifying and addressing operational issues.
• Develop automation solutions using PowerShell, Microsoft Graph, and related technologies to enhance provisioning, governance, monitoring, and reporting processes.
• Build and maintain operational dashboards, metrics, and reporting related to identity health, access governance, compliance, and platform performance.
• Support compliance, audit, and regulatory requirements through evidence collection, reporting, and control validation.
• Partner with Cybersecurity teams to implement secure identity controls that align with Zero Trust principles and enterprise security standards.
• Engage in incident response, root cause analysis, and remediation activities associated with identity, authentication, and access management services.
• Create and maintain technical documentation, architecture diagrams, operational runbooks, and support procedures.
• Assess emerging identity, authentication, PKI, and access management technologies and suggest improvements that enhance security, scalability, and user experience.
• Provide technical guidance and mentorship to IT teams and application owners regarding best practices in identity and access management.
• Bachelor's degree in Information Technology, Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent experience.
• At least 7 years of hands-on experience with Identity and Access Management technologies in a medium to large enterprise environment.
• Extensive expertise with Microsoft Entra ID, including Conditional Access, Identity Protection, Multi-Factor Authentication, Identity Governance, and access lifecycle management.
• Significant experience in implementing and supporting Single Sign-On technologies, including SAML, OAuth, OpenID Connect, LDAP, Kerberos, and SCIM provisioning.
• Experience in designing and supporting automated Joiner, Mover, and Leaver (JML) processes and identity lifecycle management workflows.
• Practical experience with Privileged Identity Management (PIM), role-based access controls, access reviews, entitlement management, and access certification processes.
• Familiarity with integrating enterprise SaaS platforms such as Microsoft 365, ServiceNow, Workday, SAP, Concur, Salesforce, MasterControl, and similar business applications.
• Strong experience with Microsoft Active Directory and hybrid identity environments.
• Experience in administering enterprise Public Key Infrastructure (PKI), including Microsoft Active Directory Certificate Services (AD CS), certificate lifecycle management, and certificate-based authentication.
• Experience supporting modern identity security platforms such as Beyond Identity, Okta, Duo, Ping Identity, CyberArk, SailPoint, Saviynt, or similar technologies is highly preferred.
• Solid understanding of modern identity architecture, authentication protocols, Zero Trust principles, passwordless authentication, device trust, and identity-centric security models.
• Proficient in PowerShell scripting and automation.
• Experience utilizing Microsoft Graph API and related automation frameworks for identity administration and governance.
• Working knowledge of compliance controls, audit requirements, and identity governance best practices.
• Strong analytical, troubleshooting, communication, and documentation skills.
• Experience supporting global and geographically distributed organizations.
• Microsoft certifications such as SC-300 (Identity and Access Administrator), SC-100 (Cybersecurity Architect), or equivalent certifications are highly preferred.
• Paid time off
• Health/dental/vision
• Retirement benefits
• Flexible spending accounts
VetsEZ
Prewave
By Light Professional IT Services
EZCORP
Get handpicked remote jobs straight to your inbox weekly.