Senior IAM Engineer - Entra ID

RELEX Solutions

Helsinki

On-site

EUR 110,000 - 140,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

RELEX Solutions in Helsinki, Finland, is seeking a Senior IAM Engineer specializing in Entra ID to own design, implementation, and operation of our Azure AD environment, ensuring secure identity services across the organization. The role emphasizes automation, governance, and integration with the broader Azure stack.

You will drive proactive security, auditability, and scalable identity workflows using Graph API, Logic Apps, and Functions, partnering with Security and Infrastructure teams,

Qualifications

  • 7+ years in Identity and Access Management.
  • Deep expertise in Microsoft Entra ID (Azure AD).
  • Strong Azure infrastructure experience with a DevOps mindset.
  • Experience automating monitoring, management, and governance of Entra ID.
  • Familiarity with Graph API, Logic Apps, Functions.
  • Proven ownership of IAM domain and governance metrics.

Responsibilities

  • Own Entra ID design, implementation, and operational health.
  • Ensure security, availability, and compliance of Entra ID.
  • Automate identity governance, monitoring, and reporting.
  • Maintain audit trails and remediation workflows for identity changes.
  • Collaborate with Security and Infrastructure leadership on governance KPIs.
  • Design and manage SSO, RBAC, PIM, and access reviews.
  • Build CI/CD and IaC for identity configurations.

Skills

Entra ID / Azure AD
IAM / Identity & Access Management
DevOps mindset
Automation / Scripting (PowerShell)
Microsoft Graph API
Azure Logic Apps / Functions
CI/CD pipelines
Infrastructure as Code (Bicep/TF/ARM)
Security & Compliance (Zero Trust/SOC2
Ownership / leadership

Education

Bachelor's or Master's in CS/IT/Engineering

Tools

Microsoft Graph API
Azure Logic Apps
Azure Functions
PowerShell/Graph SDK
Event Grid
Key Vault
Bicep/Terraform/ARM

Job description

RELEX is looking for a Senior IAM Engineer, specializing in Entra ID, to join our Identity & Access Management (IAM) and Security team. This role owns the design, implementation, and ongoing operation of our Microsoft Entra ID (Azure AD) environment, ensuring secure, scalable, and automated identity solutions across the organization. The ideal candidate combines deep Entra ID and IAM expertise with broader Azure infrastructure knowledge and a DevOps mindset, automating the monitoring, management, and governance of Entra ID resources through Microsoft Graph API, Azure Logic Apps, and Azure Functions.

Technical Role Accountability
  • Act as the technical owner and escalation point for the Entra ID environment: architecture decisions, configuration changes, and operational health.
  • Accountable for the security, availability, and compliance posture of Entra ID and related Azure identity infrastructure, including sign-off on changes with security or governance impact.
  • Drive continuous improvement of identity governance by automating monitoring, alerting, and reporting on Entra ID resources (users, groups, apps, roles, policies) rather than relying on manual reviews.
  • Own the audit trail for identity changes: ensure automated logging, alerting, and remediation workflows are in place to catch drift, misconfigurations, or policy violations early.
  • Partner with Security and Infrastructure leadership to define governance KPIs (e.g., access review completion, stale account cleanup, privileged role usage) and report on them.
Key Responsibilities
  • Design, configure, and maintain Microsoft Entra ID (Azure AD), including conditional access policies, identity governance, PIM, and access reviews.
  • Own end-to-end identity and access management processes: user lifecycle management, role-based access control (RBAC), single sign-on (SSO), and multi-factor authentication (MFA).
  • Automate the monitoring and management of Entra ID resources (users, groups, app registrations, roles, licenses, policies) for stronger governance, using Microsoft Graph API, Azure Logic Apps, and Azure Functions to detect drift, enforce policy, and trigger remediation.
  • Develop and maintain automation for identity operations using Microsoft Graph API, Azure Logic Apps, Azure Functions, and PowerShell/Graph SDK.
  • Build event-driven automation (e.g., Event Grid triggers, scheduled/Timer-triggered Functions, Automation Account runbooks) to react to identity events in near real time rather than relying on periodic manual checks.
  • Apply security best practices and compliance standards (Zero Trust, least privilege, SOC2/ISO 27001) across the identity landscape.
  • Integrate Entra ID with enterprise applications (SAML, OIDC, OAuth2, SCIM provisioning).
  • Work across the broader Azure infrastructure stack (subscriptions, resource groups, networking, Key Vault, storage, monitoring/Log Analytics) to ensure identity controls are properly integrated with the underlying cloud environment.
  • Build and maintain CI/CD pipelines and infrastructure-as-code for identity configuration changes (DevOps practices applied to IAM).
  • Monitor, audit, and respond to identity-related security incidents; support investigations and threat detection.
  • Collaborate with Security, Infrastructure, and Application teams to embed identity security into broader IT and DevOps workflows.
  • Document architecture, processes, and runbooks, and mentor junior team members on IAM and Entra ID practices.
Required Qualifications
  • 7+ years of experience in Identity and Access Management, with strong hands‑on expertise in Microsoft Entra ID (Azure AD).
  • Proven experience with IAM concepts: RBAC, SSO, MFA, conditional access, privileged identity management (PIM), and identity governance.
  • Strong background in IT/cloud security, including familiarity with Zero Trust architecture and common compliance frameworks.
  • Practical experience automating monitoring, management, and governance of Entra ID resources using Microsoft Graph API, Azure Logic Apps, and Azure Functions.
  • Familiarity with related Azure automation/integration services such as Event Grid, Azure Automation Accounts/runbooks, and Key Vault for secrets used by automation.
  • Broad working knowledge of Azure infrastructure in general (subscriptions/management groups, networking, Key Vault, storage, Log Analytics/Monitor, RBAC at the Azure resource level), beyond just the identity layer.
  • DevOps experience: CI/CD pipelines, infrastructure-as-code (e.g., Bicep, Terraform, or ARM templates), and version-controlled automation.
  • Scripting proficiency in PowerShell and/or the Microsoft Graph SDK.
  • Solid understanding of authentication/authorization protocols: SAML, OAuth2, OIDC, SCIM.
  • Demonstrated ownership/accountability for a technical domain, comfortable being the go‑to escalation point and decision‑maker on identity and governance matters.
  • Strong troubleshooting, documentation, and cross‑team collaboration skills.
Education
  • Bachelor's or Master's degree in Computer Science, Information Technology, Software/Computer Engineering, or a related engineering discipline (or equivalent practical experience).
Nice to Have
  • Microsoft certifications such as SC-300 (Identity and Access Administrator) or SC-100 (Cybersecurity Architect).
  • Experience with hybrid identity (Entra Connect/Azure AD Connect) and on‑prem Active Directory integration.
  • Familiarity with Microsoft Sentinel or other SIEM tools for identity threat detection.
  • Experience working in a regulated or enterprise SaaS environment.
What We Offer
  • The opportunity to shape and modernize enterprise identity architecture at scale.
  • A collaborative, security‑focused team culture with strong engineering practices.
  • Ownership of automation and DevOps initiatives within the IAM domain.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Entra ID IAM Engineer - Automation & Governance
Senior Entra ID IAM Engineer - Automation & Governance

RELEX Solutions • Helsinki

On-site
EUR 110,000 - 140,000
Senior IAM Architect / Consultant
Senior IAM Architect / Consultant

Jobtailor • Helsinki

On-site
EUR 90,000 - 120,000
Senior IAM Architect — Entra ID & AI-Driven Identity
Senior IAM Architect — Entra ID & AI-Driven Identity

Jobtailor • Helsinki

On-site
EUR 90,000 - 120,000
Senior Software Engineer (Identity and Access Management system)
Senior Software Engineer (Identity and Access Management system)

Smartly • Helsinki

On-site
EUR 55,000 - 75,000
Generous healthcare packages
Equity options
Paid holidays and family leave
+1
Senior IT Security Engineer
Senior IT Security Engineer

RELEX Solutions • Helsinki

On-site
EUR 90,000 - 130,000
Genuine build freedom
International career
Flexible work location
+3
Senior Software Engineer (Identity and Access Management system)
Senior Software Engineer (Identity and Access Management system)

Smartly.io • Helsinki

On-site
EUR 55,000 - 75,000
Generous healthcare packages
Mental health services
Paid holidays and family leave
+2
Entra ID Solution Architect for IAM Security
Entra ID Solution Architect for IAM Security

Nordea • Helsinki

Hybrid
EUR 90,000 - 120,000
Hybrid working model
Diversity and inclusion
Azure Cloud Architect
Azure Cloud Architect

Evitec • Espoo

On-site
EUR 90,000 - 140,000
Lead Security Engineer
Lead Security Engineer

RELEX Solutions • Helsingin seutukunta

On-site
EUR 120,000 - 190,000
Remote Microsoft Intune Specialist — Endpoint & Security
Remote Microsoft Intune Specialist — Endpoint & Security

Modirum Platforms • Finland

Remote
USD 80,000 - 120,000
Flexible work environment
Access to latest Microsoft technologies
Professional growth opportunities