IAM Engineer

IntePros

Pittsburgh (Allegheny County)

On-site

USD 110,000 - 170,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

IntePros is seeking an IAM/RBAC Engineer with deep hands-on experience in Microsoft Entra ID and Azure RBAC. This role designs, implements, and governs secure, scalable access controls across Azure environments while enforcing least-privilege principles and maintaining audit-ready identity operations.

You will build an enterprise-wide role taxonomy, map permissions to roles, implement Just-in-Time access, manage Privileged Identity Management, enforce MFA, and drive ongoing access reviews and

Qualifications

  • Experience implementing least-privilege RBAC at scale.
  • Ability to develop IAM policies and procedures and lead access governance reviews.
  • Experience governing remote, elevated, and emergency access processes.
  • Strong technical writing, documentation, and stakeholder communication skills.

Responsibilities

  • Define and maintain an enterprise-wide Azure role taxonomy.
  • Map permissions to roles and enforce least-privilege access via security groups and role assignments.
  • Eliminate broad or direct privilege assignments.
  • Document role-to-permission mappings and track changes.
  • Implement Just-in-Time (JIT) access workflows with approval and time-bound permissions.
  • Configure and govern Privileged Identity Management (PIM) processes.
  • Establish standards for VPN, jump host, and privileged session usage.
  • Define and oversee emergency "break-glass" access procedures, including incident notification and review.
  • Configure Azure-native monitoring and logging for identity and access events.
  • Route alerts to service owners and security teams.
  • Validate emergency access usage through incident workflows and post-event review.
  • Support audit readiness across access-related controls.

Skills

Entra ID
Azure RBAC
Least privilege
JIT access
PIM
MFA enforcement
Audit readiness
Technical writing

Tools

Azure Policy
Managed identities
Azure Monitor
Security groups

Job description

We are seeking an IAM/RBAC Engineer with deep hands-on experience in Microsoft Entra ID and Azure Role-Based Access Control (RBAC). This role is responsible for designing, implementing, and governing secure, scalable access controls across Azure environments while enforcing least-privilege principles and maintaining audit-ready identity operations.

Key Responsibilities
RBAC Design and Administration
  • Define and maintain an enterprise-wide Azure role taxonomy
  • Map permissions to roles and enforce least-privilege access via security groups and role assignments
  • Eliminate broad or direct privilege assignments
  • Document role-to-permission mappings and track changes
Remote and Privileged Access Governance
  • Implement Just-in-Time (JIT) access workflows with approval and time-bound permissions
  • Configure and govern Privileged Identity Management (PIM) processes
  • Establish standards for VPN, jump host, and privileged session usage
  • Define and oversee emergency "break-glass" access procedures, including incident notification and review
Identification and Authentication
  • Configure and enforce MFA for privileged roles using strong authenticators (e.g., smartcards, security keys)
  • Provision Microsoft Entra ID administrator roles for Azure services (e.g., SQL)
  • Enforce managed identities for applications such as App Services and Function Apps
  • Centralize identity controls to reduce reliance on local service keys
Authenticator Protection and Secret Hygiene
  • Ensure secure handling and protection of issued authenticators
  • Prevent unencrypted or embedded static credentials in code, images, and configurations
  • Enforce enterprise password and secret management standards
Access Governance and Documentation
  • Author and maintain IAM policies, standards, and operating procedures
  • Conduct periodic access reviews and remediate findings
  • Support audit evidence collection and control testing
  • Maintain asset and data inventories aligned with configuration management standards
Monitoring and Audit Readiness
  • Configure Azure-native monitoring and logging for identity and access events
  • Route alerts to service owners and security teams
  • Validate emergency access usage through incident workflows and post-event review
  • Support audit readiness across access-related controls
Required Technical Skills
  • Advanced knowledge of Microsoft Entra ID (Azure AD), Azure RBAC, security groups, PIM, and JIT workflows
  • Hands-on experience with Azure Policy and resource configurations
  • Experience enabling managed identities and minimizing local credential usage
  • Familiarity with Azure monitoring/logging, AAA concepts (authentication, authorization, accounting), and approval workflow integrations
  • Strong understanding of least-privilege access design in Azure
  • Experience maintaining configuration baselines and accurate asset/data inventories
Qualifications
  • Proven experience implementing least-privilege RBAC design at scale
  • Ability to develop IAM policies and procedures and lead access governance reviews
  • Experience governing remote, elevated, and emergency access processes
  • Strong technical writing, documentation, and stakeholder communication skills
  • Ability to collaborate across engineering, security, and operations teams
Nice to Have
  • Experience integrating identity workflows with enterprise approval and ticketing systems
  • Exposure to application identity patterns and CI/CD secret management controls
  • Background supporting audit readiness for cloud access controls
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IAM/RBAC Engineer
IAM/RBAC Engineer

Eliassen Group • Pittsburgh

Hybrid
Confidential
Medical, Dental, Vision benefits
401k with company matching
Life insurance
Identity & Access Management (IAM) Consultant
Identity & Access Management (IAM) Consultant

Veriipro • Pittsburgh

On-site
USD 120,000 - 150,000
IAM Architect
IAM Architect

Conexess Group • Farmington Hills (MI)

On-site
USD 130,000 - 170,000
Identity Management Consultant
Identity Management Consultant

VBeyond Corporation • Berlin (CT)

On-site
USD 140,000 - 170,000
IAM Engineer
IAM Engineer

TechDigital Group • Bellevue (WA)

On-site
USD 60,000 - 100,000
Senior Azure Entra ID / IAM Subject Matter Expert
Senior Azure Entra ID / IAM Subject Matter Expert

VBeyond Corporation • Connecticut

On-site
USD 150,000 - 190,000
Senior IAM Engineer: Azure Entra ID, RBAC & SSO Expert
Senior IAM Engineer: Azure Entra ID, RBAC & SSO Expert

New Era Technology, Inc. • United States

Hybrid
USD 140,000 - 190,000
Competitive benefits
Hybrid work model
Senior IAM Engineer: Entra ID, Azure AD & RBAC
Senior IAM Engineer: Entra ID, Azure AD & RBAC

NEW ERA TECHNOLOGY • Town of Florida (NY)

Hybrid
USD 130,000 - 170,000
Azure IAM & RBAC Engineer – JIT Access Specialist
Azure IAM & RBAC Engineer – JIT Access Specialist

IntePros • Pittsburgh

On-site
USD 110,000 - 170,000
Systems Engineer
Systems Engineer

Insight Global • Houston (TX)

On-site
USD 120,000 - 150,000