Cybersecurity IAM Engineer

Upbound Group Inc.

Plano (TX)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Upbound Group Inc. in Plano, TX is seeking a Cybersecurity IAM Engineer to secure and scale our enterprise identity platform.

You will apply deep Microsoft Entra ID expertise, build automation pipelines, and partner with Engineering, IT, and Compliance to align identity solutions with security standards. The role covers provisioning, access governance, RBAC, SSO integrations, and cross-cloud identity across on-prem and cloud.

Qualifications

  • Bachelor’s degree in computer science, cybersecurity, information systems, or related field—or equivalent professional experience.

Responsibilities

  • Design, implement, and manage Microsoft Entra ID (Azure AD) environments, including Conditional Access, MFA, and passwordless authentication.
  • Automate user provisioning/deprovisioning workflows via Entra ID, SCIM, and custom pipelines.
  • Govern privileged access with PIM, just-in-time access, and RBAC across Azure subscriptions and resources.
  • Contribute to identity governance programs, entitlement management, access reviews, and dynamic group policies.
  • Integrate enterprise SSO using SAML, OAuth 2.0, and OpenID Connect for SaaS and on‑prem apps.
  • Support hybrid identity including Azure AD Connect/Cloud Sync, LDAP, and federated-to-managed domains.
  • Monitor identity security, configure logging, alerts, and continuous sign-in/audit monitoring.
  • Develop and maintain IAM provisioning code and platform services using Go and React for HRIS integrations.
  • Maintain IaC with Terraform to provision and manage Azure resources and identity infrastructure.
  • Utilize GitHub Actions for CI/CD pipelines and secure IAM provisioning workflows.
  • Script in Bash/PowerShell/Python and write SQL as needed.
  • Create runbooks, diagrams, security standards, and operational procedures.
  • Collaborate with Engineering, IT, Compliance, and business units on IAM decisions.
  • Contribute to security incident response related to identity compromise.

Skills

Azure AD
Go
React.js
RBAC
SAML/OIDC
PIM
SCIM
GitHub Actions
Terraform
CI/CD
Zero Trust

Education

Bachelor's degree in Computer Science or related field

Tools

Terraform
GitHub
Azure
Azure Container Apps
REST/JSON/XML
Go
React

Job description

Cybersecurity IAM Engineer
Who We Are

At Upbound Group, we are committed to elevating financial opportunity for all through innovative, inclusive, and technology-driven financial solutions that address the evolving needs and aspirations of consumers. The Company’s customer-facing operating units include industry-leading brands such as Rent-A-Center, Acima and Brigit that facilitate consumer transactions across a wide range of store-based and digital retail channels, including over 2,400 company-branded retail units across the United States, Mexico, New York and Puerto Rico. Upbound Group, Inc. is headquartered in Plano, Texas.

Role Summary

The Cybersecurity Identity & Access Management Engineer is a senior technical contributor on a dedicated IAM team charged with securing and scaling Upbound Group's enterprise identity platform. In this role, the engineer applies deep Microsoft Entra ID expertise and Zero Trust principles to advance identity governance, privileged access management, and entitlement controls across both on-premises and cloud environments - partnering closely with Engineering, IT, and Compliance to align identity solutions with organizational security standards. The engineer also contributes to the design and delivery of custom IAM provisioning solutions, building automation pipelines that seamlessly connect identity infrastructure with critical business applications, cloud platforms, and HRIS systems.

Key Responsibilities
  • Assist in designing, implementing, and managing Microsoft Entra ID (Azure AD) environments, including tenant architecture, Conditional Access policies, MFA, passwordless authentication (FIDO2, Windows Hello), and Identity Protection
  • Participate in identity lifecycle management: automate user provisioning and deprovisioning workflows via Entra ID, SCIM-based integrations, and custom automation pipelines
  • Implement and govern privileged access using Privileged Identity Management (PIM), just-in-time access controls, and least-privilege RBAC models across Azure subscriptions and resources
  • Participate in access governance programs including entitlement management, access reviews, dynamic group policies, and Administrative Units
  • Integrate enterprise SSO using SAML, OAuth 2.0, and OpenID Connect protocols for SaaS and on-premises applications
  • Support hybrid identity environments including Azure AD Connect / Cloud Sync, LDAP integrations, and federated-to-managed domain transitions
  • Monitor and respond to identity-related threats by configuring identity logging, security alerting, and continuous monitoring of sign-in and audit logs
  • Assist in securing Azure Container Apps environments, including ingress controls, managed identity configuration, secrets management, network isolation, and Dapr integration security
  • Evaluate and assist with hardening IAM functions for cloud-native infrastructure across Azure, AWS and GCP ensuring compliance with Zero Trust principles and organizational security policies.
  • Develop and maintain custom IAM provisioning code and internal platform services using Go (Golang) for backend services and React.js for frontend integrations with HRIS platforms
  • Partner with Platform Engineering teams to maintain IAM Infrastructure as Code (IaC) using Terraform to provision, configure, and manage Azure resources, identity infrastructure, and security controls in a repeatable, auditable manner
  • Utilize and maintain CI/CD security pipelines using GitHub Actions, including automated IAM provisioning workflows to Azure Container Apps environment
  • Manage IAM provisioning source code, branching strategies, and code reviews in GitHub, championing secure development best practices across the team
  • Automate, code or script (Bash, PowerShell, RegEx and Python) as well as write SQL to query databases as needed
  • Develop and maintain documentation including runbooks, architecture diagrams, security standards, and operational procedures
  • Collaborate with peers to provide direction on IAM and cloud identity security, advising cross-functional teams (Engineering, IT, Compliance, and Business units) on identity architecture decisions
  • Contribute to security incident response related to identity compromise, credential theft, or access control failures
  • Evaluate emerging IAM technologies and trends, providing recommendations to leadership on platform enhancements and modernization initiatives
  • Integrate AI‑driventools into daily engineering work to enhance decision‑making quality and accelerate innovation across deliverables
Required Qualifications
  • Bachelor’s degree in computer science, Cybersecurity, Information Systems, or a related field—or equivalent professional experience
  • 5+ years of progressive experience in cybersecurity, with at least 2-3 years focused on Identity & Access Management.
  • Deep, hands‑on expertise with Microsoft Entra ID (Azure AD), including Conditional Access, Identity Protection, PIM, RBAC, application registrations, and hybrid identity (AD Connect / Cloud Sync)
  • Strong experience with Azure Container Apps or similar Azure container services (AKS, Azure Container Instances), including managed identity integration and secrets management and Cosmos DB for logic and translation rules
  • Strong experience with Go (Golang) for building backend services, APIs, and automated IAM provisioning workflows
  • Strong experience with React.js for building modern web-based administrative interfaces and integrations with leading HRIS platforms
  • Strong experience with REST API, JSON, XML, C#
  • Proficiency with Terraform for provisioning and managing cloud infrastructure as code
  • Strong use of GitHub and GitHub Actions for source control management, CI/CD pipeline development, automated testing, and deployment workflows
  • Solid understanding of authentication and authorization protocols: SAML 2.0, OAuth 2.0, OpenID Connect, SCIM, and FIDO2
  • Working knowledge of Zero Trust architecture principles and their application to identity and network security
  • Proficient in modern AI‑driven security, spanning LLMs, MCP, RAG, model architectures, and enterprise‑grade security controls
  • Excellent communication skills with the ability to translate complex technical security topics for diverse stakeholders
Preferred Qualifications
  • Microsoft certifications: SC-300 (Identity and Access Administrator), AZ-500 (Azure Security Engineer), SC-100 (Cybersecurity Architect)
  • Industry certifications: CISSP, CCSP, CIAM (Certified Identity and Access Manager), or CompTIA Security+/CySA+
  • Experience with additional IdP platforms such as Okta, Ping Identity, or SailPoint alongside Microsoft Entra
  • Experience with Workday HRIS platform using RaaS data integrations
  • Familiarity with SIEM/SOAR platforms (Microsoft Sentinel, Rapid 7) for identity threat detection and automated response
  • Knowledge of compliance frameworks such as NIST CSF, NIST AI RMF, or PCI DSS, as they relate to identity and access controls
  • Experience with PKI infrastructure, certificate-based authentication, and credential lifecycle management
  • Prior experience in multi-tenant or multi-entity Azure environments with cross-tenant federation and B2B collaboration
Work Location

Ability to work in the Plano, Texas office, Monday through Friday.

Sponsorship

Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment visa at this time.

Equal Opportunity Employer

Upbound Group is an equal opportunity employer committed to ensuring all employment decisions are made on a non-discriminatory basis in accordance with applicable federal, state, and local laws.

This job description is not intended to be all-inclusive. Coworker may perform other related duties as negotiated to meet the ongoing needs of the organization.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity IAM Engineer
Cybersecurity IAM Engineer

Upbound Group • Plano (TX)

On-site
USD 110,000 - 140,000
Cybersecurity IAM Engineer
Cybersecurity IAM Engineer

Upbound Field Support Center Rent A Center Texas LP • United States

On-site
USD 100,000 - 130,000
Equal Opportunity Employer
Inclusive environment commitment
Microsoft Entra ID Architect
Microsoft Entra ID Architect

KeyData Cyber • United States

Remote
USD 124,000 - 207,000
Associate Enterprise Security Architect
Associate Enterprise Security Architect

Upbound Field Support Center Rent A Center Texas LP • United States

On-site
USD 100,000 - 130,000
Identity and Access Management Leader
Identity and Access Management Leader

Collective Insights Careers • Atlanta (GA)

On-site
USD 150,000 - 190,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000
Associate Enterprise Security Architect
Associate Enterprise Security Architect

Upbound Group Inc. • Plano (TX)

On-site
USD 100,000 - 130,000
IAM Architect (Entra ID-Focused) Hybrid in Plano
IAM Architect (Entra ID-Focused) Hybrid in Plano

NTT America, Inc. • Plano (TX)

On-site
USD 130,000 - 160,000
Enterprise IAM Operations Engineer with Entra ID, RBAC, and Application Integration
Enterprise IAM Operations Engineer with Entra ID, RBAC, and Application Integration

Neweratech • New York (NY)

Hybrid
USD 140,000 - 190,000
Systems Engineer, Infrastructure
Systems Engineer, Infrastructure

HCC Service Company, Inc. • Houston (TX)

Hybrid
USD 85,000 - 115,000
Competitive salary
Comprehensive medical, vision, and dental benefits
401(k) plan with 6% company match
+1