IAM Engineer

American Heart Association

Dallas, Northern (TX, KY)

Hybrid

USD 105,000 - 115,000

Full time

25 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Tuition Assistance
Employee Wellness Program
Telemedicine
PTO 16 days first year
12 paid holidays

Job summary

American Heart Association seeks an IAM Engineer to design and operate enterprise identity and access management across cloud and on‑prem environments. You will enable lifecycle management, provide secure authentication, and support role-based access controls with automation using PowerShell and Microsoft Graph.

You will collaborate with Cybersecurity, HR, and infrastructure teams to ensure compliant, reliable, and user‑friendly identity solutions aligned with policy and audits.

Qualifications

  • Bachelor’s degree or equivalent experience.
  • 3 years of relevant experience.
  • 3+ years in identity and access management or related role.
  • Hands-on experience with Microsoft Entra ID and Active Directory in enterprise environments.
  • Experience with identity lifecycle management, automated provisioning, access governance, and RBAC.
  • Knowledge of SAML, OAuth 2.0, OpenID Connect, and SCIM.
  • Experience with MFA, Conditional Access, SSO, and privileged access controls.
  • Experience with PowerShell, Microsoft Graph, REST APIs, or related scripting technologies.

Responsibilities

  • Design, implement, and maintain identity lifecycle processes for employees, contractors, partners, and service identities.
  • Engineer automated joiner/mover/leaver workflows using authoritative identity sources.
  • Configure and support Microsoft Entra ID, Active Directory, hybrid identity synchronization, and directory-integrated apps.
  • Develop and maintain RBAC, group-based access, entitlements, and access packages.
  • Create automation using PowerShell, Microsoft Graph, APIs, and workflow tools to improve accuracy and speed.
  • Implement and support single sign-on, MFA, passwordless authentication, Conditional Access, and risk-based access controls.
  • Configure and troubleshoot SAML, OAuth 2.0, OpenID Connect, SCIM, and related protocols.
  • Integrate enterprise apps with identity providers and secure provisioning patterns.
  • Support privileged identity and access management controls, incl. JIT access and governance.
  • Monitor IAM service health, provisioning, sync, authentication, and integration failures.
  • Troubleshoot complex access issues and perform root-cause analysis across directories and apps.
  • Participate in incident response, change management, and on-call rotation.

Skills

Microsoft Entra ID
Active Directory
Identity lifecycle management
Automation
PowerShell
Microsoft Graph
REST APIs
SAML
OAuth 2.0
Conditional Access

Education

Bachelor’s degree or equivalent experience

Tools

PowerShell
Microsoft Graph
REST APIs
SAML
OAuth 2.0
SCIM

Job description

Overview

Since our founding in 1924, we've cut cardiovascular disease deaths in half, but there is still so much more to do. To overcome today’s biggest health challenges and accelerate this progress, we need passionate individuals like you. Join our movement, be part of the progress, and help ensure a healthier future for all. You matter, and so does the impact you can make with us.

We are seeking a skilled and motivated IAM Engineer to join our Business Technology team. In this role, you will be responsible for engineering, operating, and continuously improving enterprise identity and access management services across cloud and on-premises environments. You will support identity lifecycle management, authentication, authorization, access governance, directory services, federation, and privileged access capabilities.

The ideal candidate is a detail-oriented engineer with hands‑on experience in Microsoft Entra ID, Active Directory, identity governance, automation, and modern authentication. You will collaborate with Cybersecurity, Human Resources, application owners, infrastructure teams, and business stakeholders to deliver secure, reliable, and user‑friendly identity solutions aligned with organizational policy, audit requirements, and business objectives.

The Association offers many resources to help you maintain work‑life harmonization through your changing needs and life situations. To help you be successful, you will have access to Heart U, our award‑winning corporate university, as well as additional training and support, locally.

#TheAHALife is more than a company culture; it is our way of life. It embodies our commitment to work‑life harmonization and is guided by our core values where our employees can thrive both personally and professionally. Discover why you will Be Seen. Be Heard. Be Valued at the American Heart Association by following us on LinkedIn, Instagram, Facebook, X, and at heart.jobs.

Responsibilities
Identity Engineering and Lifecycle Management
  • Design, implement, and maintain identity lifecycle processes for employees, contractors, partners, and service identities
  • Engineer automated joiner, mover, and leaver workflows using authoritative identity sources and policy‑based provisioning
  • Configure and support Microsoft Entra ID, Active Directory, hybrid identity synchronization, and directory‑integrated applications
  • Develop and maintain role‑based access control, group‑based access, entitlement structures, and access packages
  • Create automation using PowerShell, Microsoft Graph, APIs, and workflow tools to improve accuracy, consistency, and speed
Authentication, Federation, and Access Controls
  • Implement and support single sign‑on, multifactor authentication, passwordless authentication, Conditional Access, and risk‑based access controls
  • Configure and troubleshoot SAML, OAuth 2.0, OpenID Connect, SCIM, and related identity protocols
  • Integrate enterprise applications with identity providers and establish secure authentication and provisioning patterns
  • Support privileged identity and access management controls, including just‑in‑time access and administrative role governance
Identity Governance, Compliance, and Security
  • Implement access reviews, separation‑of‑duties controls, certification campaigns, and governance reporting Partner with Cybersecurity, Internal Audit, Legal, and application owners to address identity risks and control requirements
  • Monitor identity‑related events, investigate anomalous access, and support security incident response activities
  • Maintain evidence, documentation, and control records that support audits and compliance assessments
  • Operations, Support, and Continuous Improvement
  • Monitor IAM service health, provisioning performance, synchronization, authentication, and integration failures
  • Troubleshoot complex access issues and perform root‑cause analysis across directories, applications, and identity platforms
  • Participate in incident response, change management, problem management, and an on‑call rotation as required
  • Maintain technical designs, operational procedures, support documentation, and troubleshooting guides
  • Evaluate emerging identity capabilities and recommend improvements that strengthen security and user experience
Qualifications
  • Bachelor’s degree or equivalent experience
  • 3 years of relevant experience
  • 3+ years of experience in identity and access management, directory services, cybersecurity engineering, or a related technical role
  • Hands‑on experience with Microsoft Entra ID and Active Directory in enterprise environments
  • Experience with identity lifecycle management, automated provisioning and deprovisioning, access governance, and role‑based access control
  • Knowledge of modern authentication and federation standards, including SAML, OAuth 2.0, OpenID Connect, and SCIM
  • Experience configuring multifactor authentication, Conditional Access, single sign‑on, and privileged access controls
  • Experience with PowerShell, Microsoft Graph, REST APIs, or comparable scripting and integration technologies
  • Understanding of least privilege, zero trust, separation of duties, and identity‑related security controls
Preferred Qualifications
  • Experience integrating IAM platforms with human resources systems and enterprise applications
  • Experience with Microsoft Entra ID Governance, Privileged Identity Management, entitlement management, and access reviews
  • Knowledge of privileged access management platforms and service account governance
  • Experience with identity monitoring, logging, reporting, and security incident investigation
  • Familiarity with IT service management, change control, audit evidence, and compliance frameworks
  • Identity and security certifications such as:
  • Microsoft Certified: Identity and Access Administrator Associate (SC‑300)
  • Microsoft Certified: Cybersecurity Architect Expert (SC‑100)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Identity platform or privileged access management certifications relevant to the enterprise environment
Compensation & Benefits

Expected pay range will be $105,000 - $115,000. Pay is commensurate with experience; geographic differentials to the pay range may apply. The American Heart Association reserves the right to pay more or less than the posted range.

The American Heart Association invests in its people. Here are the main components of our total rewards package. Visit Rewards & Benefits to see more details.

  • Compensation – Our goal is to ensure you have a competitive base salary. That’s why we regularly review the market value of jobs and make adjustments, as needed.
  • Performance and Recognition – You are rewarded for achieving success through annual salary planning and incentive programs; based on the type of position
  • Benefits – We offer a wide array of benefits including medical, dental, vision, disability, and life insurance, along with a robust retirement program that includes an employer match and automatic contribution. As a mark of our commitment to employee well‑being, we also offer an employee assistance program, employee wellness program and telemedicine, and medical consultation.
  • Professional Development – You can join one of our many Employee Resource Groups (ERG) or be a mentor/mentee in our professional mentoring program. Heart U is the Association’s national online university, with more than 100,000 resources designed to meet your needs and busy schedule.
  • Work-Life Harmonization – The Association offers Paid Time Off (PTO) at a minimum of 16 days per year for new employees. The number of days will increase based on seniority level. You will also have a total of 12 paid holidays off each year, which includes several days off at the end of the year.
  • Tuition Assistance - We support the career development of all employees. This program provides financial assistance to employees who wish to further their education and career in relation to their current duties and responsibilities, or for potential future positions in the organization.

The American Heart Association’s 2028 Goal: Building on over 100 years of trusted leadership in cardiovascular and brain health, by 2028 the Association will drive breakthroughs and implement proven solutions in science, policy, and care for healthier people and communities. The greatest discoveries in health must reach everyone where they are.

At American Heart Association | American Stroke Association, our mission is to be a relentless force for a world of longer, healthier lives, regardless of race, ethnicity, gender, gender identity, religion, age, language, sexual orientation, national origin and physical or cognitive abilities.

In accordance with local and state laws where applicable, qualified applicants with arrest or conviction records will be considered for employment.

EOE/Protected Veterans/Persons with Disabilities

Hybrid

Default: Location : Location

US‑TX‑Dallas

Position Type

Full Time

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IAM Engineer
IAM Engineer

RiseMe • Dallas (TX)

On-site
USD 105,000 - 115,000
Sr. Systems Engineer
Sr. Systems Engineer

American Heart Association • Dallas (TX)

On-site
USD 90,000 - 120,000
Medical, dental, vision, disability, and life insurance
Retirement program with employer match
Paid Time Off (minimum of 16 days per year)
+4
Cybersecurity Engineer
Cybersecurity Engineer

American Heart Association • Dallas (TX), Northern (KY)

Hybrid
USD 95,000 - 135,000
Medical insurance
Dental insurance
Vision insurance
+6
Identity & Access Engineer — Entra ID Specialist
Identity & Access Engineer — Entra ID Specialist

RiseMe • Dallas (TX)

On-site
USD 105,000 - 115,000
Sr. Digital Developer
Sr. Digital Developer

American Heart Association • Bakersfield (CA)

On-site
USD 115,000 - 125,000
Medical, dental, vision insurance
Disability and life insurance
Employer retirement match
+4
Data Processing Coordinator
Data Processing Coordinator

American Heart Association • Dallas (TX), Northern (KY)

On-site
USD 50,000 - 58,000
Medical, dental, vision
Tuition assistance
PTO & holidays
Senior Identity Application Architect, CIAM/IAM
Senior Identity Application Architect, CIAM/IAM

AHEAD • Chicago (IL)

On-site
USD 140,000 - 200,000
Medical Insurance
Dental Insurance
Vision Insurance
+4
Identity Architect
Identity Architect

Finance of America Holdings • United States

On-site
USD 120,000 - 140,000
Health, dental, vision insurance
401(k) with employer match
ESP P باز? ESPP
Identity and Access Management Engineer (Authentication)
Identity and Access Management Engineer (Authentication)

RiseMe • Illinois

Hybrid
USD 92,000 - 130,000
401(k) plan
Employee stock purchase plan
Medical, dental, vision insurance
+6
Sr. Manager, Identity and Access Management Platform
Sr. Manager, Identity and Access Management Platform

Hyundai Capital • Plano (TX)

Hybrid
USD 130,000 - 170,000
Hybrid flexibility
Vehicle allowance
Health coverage
+6