IAM/RBAC Engineer

Eliassen Group

Pittsburgh (Allegheny County)

Hybrid

Confidential

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, Vision benefits
401k with company matching
Life insurance

Job summary

Eliassen Group is seeking an IAM/RBAC Engineer to design, implement, and govern access controls across Azure Entra ID environments. The role emphasizes least-privilege, JIT access, MFA for privileged roles, and auditable access management in hybrid deployments.

The contract-to-hire opportunity offers W-2 benefits and competitive hourly compensation in the Pittsburgh/NYC vicinity with remote options.

Qualifications

  • Advanced knowledge of Microsoft Entra ID and Azure RBAC.
  • Hands-on with Azure Policy and managed identities.
  • Familiarity with Azure monitoring and logging and AAA concepts.
  • Strong least-privilege access design in Azure.
  • Experience authoring IAM policies and conducting access reviews.

Responsibilities

  • Define and maintain an enterprise role taxonomy across Azure resources.
  • Map permissions to roles and enforce least-privilege access.
  • Configure MFA for privileged roles using strong authenticators.
  • Establish emergency access procedures and incident notification.
  • Conduct periodic access reviews and support audit evidence collection.

Skills

Microsoft Entra ID
Azure RBAC
Least-privilege design
Access governance
Communication & documentation
Audit readiness

Tools

Azure Policy
Azure Monitor
Managed identities
Approval workflow tools

Job description

Description

Hybrid 4 days onsite in either Pittsburgh, PA or NYC, NY or Remote


Our client seeks an IAM/RBAC Engineer with deep experience in Microsoft Entra ID and Azure RBAC. The contractor will design, implement, and administer access controls, enforce least-privilege, and support secure, auditable access for privileged and non-privileged users. The role emphasizes scalable identity solutions, strong authenticator management, and consistent access governance and monitoring.


This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.


Rate: $80.00 to $90.00/hr. w2


JN -082026-108173


Responsibilities


  • Define and maintain an enterprise role taxonomy across Azure resources.

  • Map permissions to roles and enforce least-privilege access via security groups and role assignments.

  • Prohibit broad, direct privilege assignments and document role-to-permission mappings and changes.

  • Implement JIT workflows for elevated access with approvals and time-bound permissions.

  • Establish usage restrictions and configuration norms for VPN, jump hosts, and privileged sessions.

  • Define and oversee emergency access procedures, incident notification, and review.

  • Configure MFA for privileged roles using strong authenticators such as smartcards or security keys.

  • Provision Azure AD administrator roles for services such as SQL where applicable.

  • Enforce managed identities for applications and reduce reliance on local service keys.

  • Ensure authorized users safeguard issued authenticators and follow secret hygiene.

  • Prevent unencrypted, embedded static credentials in code, images, and configurations.

  • Author and maintain policies, standards, and operating procedures for access controls.

  • Conduct periodic access reviews and support audit evidence collection.

  • Maintain inventories of assets and data with baseline configurations per configuration management practices.

  • Configure Azure-native monitoring and logging for identity and access events.

  • Route alerts to service owners and security teams and support audit readiness.

  • Validate use of emergency access through incident workflows and post-event reviews.


Experience Requirements


  • Advanced knowledge of Microsoft Entra ID, Azure RBAC, security groups, PIM, and JIT access workflows.

  • Hands-on experience with Azure Policy and resource configurations, including managed identities and Azure AD admin role provisioning.

  • Familiarity with Azure monitoring and logging, AAA concepts, and integration with approval workflow tools.

  • Strong understanding of least-privilege access design and access control best practices in Azure.

  • Competence in baseline configuration management and accurate asset and data inventories.

  • Demonstrated experience implementing least-privilege at scale and articulating Azure RBAC rationale.

  • Ability to author and maintain IAM policies and procedures, perform access reviews, and support audits.

  • Proven capability to implement and govern remote and elevated access and emergency access processes.

  • Strong communication and documentation skills for technical writing and stakeholder coordination.

  • Ability to collaborate across engineering, security, and operations teams for compliant access practices.

  • Nice-to-have: Experience integrating identity workflows with approval systems and ticketing processes.

  • Nice-to-have: Exposure to application identity design patterns and CI/CD secret management controls.

  • Nice-to-have: Background in supporting audit readiness for access controls in cloud environments.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IAM Engineer
IAM Engineer

IntePros • Pittsburgh

On-site
USD 110,000 - 170,000
IAM/RBAC Engineer
IAM/RBAC Engineer

慨正橡扯 • Pittsburgh

On-site
USD 90,000 - 120,000
Flexible global resources and tools
Generous paid leaves including volunteer time
Azure IAM & RBAC Engineer | Hybrid/Remote
Azure IAM & RBAC Engineer | Hybrid/Remote

Eliassen Group • Pittsburgh

Hybrid
Confidential
Medical, Dental, Vision benefits
401k with company matching
Life insurance
Identity & Access Management (IAM) Consultant
Identity & Access Management (IAM) Consultant

Veriipro • Pittsburgh

On-site
USD 120,000 - 150,000
Identity and Access Management (IAM) Engineer
Identity and Access Management (IAM) Engineer

Universal Technologies • United States

Hybrid
USD 120,000 - 180,000
Competitive Compensation
Health, Dental, Vision Benefits
401k Retirement Plan
+2
IAM & Security Engineer: Entra ID, AD, RBAC
IAM & Security Engineer: Entra ID, AD, RBAC

Cypress HCM • Cincinnati (OH)

On-site
USD 70,000 - 90,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000
Azure IAM & RBAC Engineer – JIT Access Specialist
Azure IAM & RBAC Engineer – JIT Access Specialist

IntePros • Pittsburgh

On-site
USD 110,000 - 170,000
Senior IAM Engineer
Senior IAM Engineer

Overture Partners • Bridgeport (CT)

On-site
USD 100,000 - 130,000
IAM Security Engineer
IAM Security Engineer

JMS Technical Solutions • Seattle (WA)

Hybrid
USD 53,726 - 89,544