
Workforce IAM Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Develop, test, implement, and sustain persona-based RBAC roles and access policies.
• Create scalable application logic and automations.
• Establish and manage integrations and workflows for Microsoft Entra ID and Okta, covering application onboarding and SSO/SCIM setup.
• Streamline role assignment, access provisioning, and reporting through scripts and tools like PowerShell.
• Update and maintain RBAC roles as organizational structures, entitlements, and applications evolve.
• Write, test, and document code while conducting code reviews.
• Oversee the enterprise password management system, including vault structure, policies, provisioning, onboarding/offboarding, and updates.
• Manage the lifecycle of hardware security keys, including provisioning, enrollment, replacements, PIN resets, and recovery.
• Coordinate the shipping and reclamation of hardware security keys with Asset Management.
• Monitor platform health, implement updates, and liaise with vendors.
• Produce runbooks, documentation, and knowledge base articles.
• Assess requirements and pinpoint design considerations.
• Analyze authentication, authorization, and access data for troubleshooting, audits, and enhancements.
• Resolve application access problems, authentication errors, and integration issues.
• Assist end users and partner teams with identity-related requests and RBAC inquiries.
• Engage in the on-call rotation and address identity platform incidents.
• A minimum of 3 years of experience in IT engineering.
• At least 1 year of experience managing an enterprise password management platform, with a preference for 1Password, and consideration for Keeper and Bitwarden.
• Practical experience with Active Directory, Microsoft Entra ID, and Okta, particularly in application onboarding and SSO/SCIM configuration.
• Solid understanding of hardware security tokens like YubiKey, Google Titan, and Feitian.
• Familiarity with RBAC, SSO, SAML/OIDC, and MFA.
• Proficient in scripting with PowerShell, Python, or both, ideally including Microsoft Graph API and Entra ID app registrations.
• Working knowledge of ITIL or similar change management frameworks, including change requests, incident management, and release processes.
• Experience with cloud platforms, with Azure required and AWS strongly preferred.
• Familiarity with Git, CI/CD, and code review practices.
• Exposure to PAM platforms like CyberArk is strongly preferred.
• A proactive, self-driven approach with the ability to identify areas for improvement.
• A passion for learning new technologies; enterprise security certifications or coursework such as CISSP, CISA, SC-300, AZ-900, Security+, or AI governance completed or in progress is ideal.
• Strong decision-making skills and commitment to thorough documentation.
• Authorization to work in the United States for any employer.
• Excellent written and verbal communication skills that are clear and concise.
• A learner's mindset and dedication to personal growth.
• A drive for impact and excellence.
• A collaborative and empathetic approach.
• Fully remote or hybrid working options for candidates residing near College Board offices (in-office on Tuesday and Wednesday).
• A meaningful career within a supportive team.
• A comprehensive compensation and benefits package.
• Salaries adjusted based on location.
• Open discussions regarding compensation and benefits.
• Occasional business travel for in-person meetings.
Muon Space
Anduril Industries
Siemens Healthineers
Get handpicked remote jobs straight to your inbox weekly.