IAM Engineer

Hydrogen UK Ltd

Denver (CO)

Hybrid

USD 90,000 - 96,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Hydrogen UK Ltd. is seeking an IAM Engineer in Denver, CO for a 12-month contract. The role focuses on designing, implementing, and supporting enterprise IAM services including Entra ID, AD, SailPoint, and PAM.

You will handle JML workflows, ticket management, and drive automation to reduce manual effort and improve security. The position requires strong technical IAM expertise, collaboration across security, HR, and infrastructure, and a commitment to least privilege and Zero Trust principles.

Qualifications

  • Strong IAM engineering experience with enterprise-scale identity platforms.
  • Experience designing and operating Active Directory in hybrid/on-prem environments.
  • Hands-on with RBAC/ABAC, SSO, and PAM controls; familiar with audit evidence collection.

Responsibilities

  • Design, implement, and support IAM solutions (Entra/AD, SailPoint, PAM).
  • Lead or support onboarding of applications into IAM platforms.
  • Manage Joiner/Mover/Leaver processes and ticket queues to meet SLAs.
  • Identify automation opportunities and drive standardization across identity lifecycle workflows.
  • Collaborate with HR, IT, and audit teams to ensure compliance and governance.

Skills

IAM engineering
Microsoft Entra ID
Azure AD
Active Directory
SailPoint IdentityIQ/Identity Security
ServiceNow IAM workflows
SSO protocols
PAM concepts
JML lifecycle

Tools

ServiceNow
SailPoint

Job description

IAM Engineer

Denver, CO (Hybrid)

Duration: initial 12-month contract

Pay: $65-70/hr

The IAM Engineer is responsible for designing, implementing, and supporting enterprise Identity and Access Management (IAM) services. This role combines hands-on engineering with operational execution, including active participation in Joiner, Mover, Leaver (JML) ticket processing. The engineer will also drive automation, standardization, and continuous improvement across identity lifecycle processes.

This role partners closely with Identity Governance, Security, Infrastructure, and HR teams to ensure identity services are secure, scalable, and audit-compliant, aligned with least privilege and Zero Trust principles.

Key Responsibilities
IAM Engineering & Platform Ownership
  • Design, implement, and support IAM solutions across:
  • Microsoft Entra ID (SSO, MFA, Conditional Access)
  • Active Directory (on-premises and hybrid environments)
  • SailPoint (IdentityIQ / Identity Security Cloud)
  • ServiceNow (access request and fulfillment workflows)
  • Privileged Access Management (PAM) solutions
  • Lead or support:
  • Application onboarding into IAM platforms
  • Identity lifecycle design and provisioning standards
  • Integration patterns for new applications (APIs, connectors, etc.)
  • Troubleshoot and resolve:
  • Provisioning and synchronization failures
  • Authentication and access issues
  • Identity-related integration defects
JML Operations & Ticket Management
  • Actively manage IAM ticket queues, including:
  • Access requests and modifications
  • Joiner, mover, and leaver processing
  • Exceptions and escalations
  • Ensure:
  • Service Level Agreements (SLAs) are consistently met
  • Accurate execution and complete audit documentation
  • Proper approvals are captured for all access changes
  • Identify recurring operational issues and:
  • Escalate upstream process gaps (HR, application owners)
  • Recommend and support process improvements
  • Identify automation opportunities within workflows
Automation & Process Improvement
  • Support redesign and automation of JML workflows to reduce manual effort and error rates
  • Eliminate manual steps identified through operational ticket handling
  • Contribute to development of:
  • Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) models
  • Standardized access patterns and birthright access frameworks
  • Partner with HR/People teams to:
  • Improve identity data quality
  • Enable HR-driven lifecycle automation and integrations
Security, Controls & Compliance
  • Ensure IAM processes align with regulatory and audit requirements, including:
  • SOX, ISO 27001, SOC 2, and ISAE standards
  • Enforce:
  • Least privilege access principles
  • Timely deprovisioning and access revocation
  • Strong identity lifecycle controls
  • Support audit requests with accurate and complete evidence
Collaboration & Governance
  • Partner with:
  • Application Owners for access models and onboarding
  • Infrastructure teams for directory and platform dependencies
  • HR/People teams for identity lifecycle triggers
  • Audit and Compliance teams for control design and remediation
  • Reinforce governance model:
  • IAM enables enforcement of access controls
  • Business/application owners remain accountable for access approvals
Required Skills & Experience
Technical
  • Strong IAM engineering experience with:
  • Microsoft Entra ID / Azure AD
  • Active Directory (hybrid and on-prem)
  • SailPoint IdentityIQ or Identity Security Cloud
  • ServiceNow IAM workflows and integrations
  • Solid understanding of:
  • SSO protocols (SAML, OpenID Connect)
  • Identity lifecycle management and provisioning models
  • Privileged Access Management (PAM) concepts and controls
Functional
  • Experience in IAM operational environments with ticket-based workflows
  • Strong understanding of:
  • Joiner/Mover/Leaver (JML) lifecycle processes
  • Access request and fulfillment processes
  • Identity governance frameworks (RBAC, ABAC)
Soft Skills
  • Strong attention to detail and execution discipline
  • Ability to balance:
  • Operational workload (ticket queue management)
  • Strategic improvement (automation and standardization)
  • Strong communication skills across technical and business stakeholders
What Success Looks Like
  • IAM ticket queue is stable, controlled, and consistently meeting SLA targets
  • JML processes are standardized, predictable, and increasingly automated
  • Reduced manual IAM effort through automation and process optimization
  • Improved audit outcomes and stronger compliance posture
  • Consistent access control enforcement across enterprise applications

...

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IAM Engineer
IAM Engineer

The Clearing House • Liberty Township (OH)

Hybrid
USD 100,000 - 140,000
IAM Engineer
IAM Engineer

Applied IAM • Northern (KY)

Hybrid
USD 70,000 - 110,000
IAM Engineer
IAM Engineer

The Clearing House • United States

Hybrid
USD 110,000 - 140,000
IAM (Sailpoint) Architect (REMOTE)
IAM (Sailpoint) Architect (REMOTE)

Conexess Group • Livonia (MI)

On-site
USD 90,000 - 130,000
IAM Engineer
IAM Engineer

Tata Consultancy Services • Sunnyvale (CA)

On-site
USD 80,000 - 104,000
IAM Engineer
IAM Engineer

Veriipro • Sunnyvale (CA)

On-site
USD 120,000 - 180,000
IAM Engineer
IAM Engineer

Jobtailor • Alabama

On-site
USD 90,000 - 130,000
IAM Engineer
IAM Engineer

Ampcus Inc • Gaithersburg (MD)

On-site
USD 80,000 - 120,000
Sr. IAM Engineer
Sr. IAM Engineer

IDMWORKS • Oregon (WI)

Hybrid
USD 115,000 - 160,000
IAM Operations Analyst
IAM Operations Analyst

Farm Credit Bank of Texas • Austin (TX)

On-site
USD 75,000 - 95,000
Flexible health‑and‑wellness benefits
401(k) plan with immediate vesting
Long‑term disability and life insurance
+2