Description
Hybrid 4 days onsite in either Pittsburgh, PA or NYC, NY or Remote
Our client seeks an IAM/RBAC Engineer with deep experience in Microsoft Entra ID and Azure RBAC. The contractor will design, implement, and administer access controls, enforce least-privilege, and support secure, auditable access for privileged and non-privileged users. The role emphasizes scalable identity solutions, strong authenticator management, and consistent access governance and monitoring.
This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $80.00 to $90.00/hr. w2
JN -082026-108173
Responsibilities
- Define and maintain an enterprise role taxonomy across Azure resources.
- Map permissions to roles and enforce least-privilege access via security groups and role assignments.
- Prohibit broad, direct privilege assignments and document role-to-permission mappings and changes.
- Implement JIT workflows for elevated access with approvals and time-bound permissions.
- Establish usage restrictions and configuration norms for VPN, jump hosts, and privileged sessions.
- Define and oversee emergency access procedures, incident notification, and review.
- Configure MFA for privileged roles using strong authenticators such as smartcards or security keys.
- Provision Azure AD administrator roles for services such as SQL where applicable.
- Enforce managed identities for applications and reduce reliance on local service keys.
- Ensure authorized users safeguard issued authenticators and follow secret hygiene.
- Prevent unencrypted, embedded static credentials in code, images, and configurations.
- Author and maintain policies, standards, and operating procedures for access controls.
- Conduct periodic access reviews and support audit evidence collection.
- Maintain inventories of assets and data with baseline configurations per configuration management practices.
- Configure Azure-native monitoring and logging for identity and access events.
- Route alerts to service owners and security teams and support audit readiness.
- Validate use of emergency access through incident workflows and post-event reviews.
Experience Requirements
- Advanced knowledge of Microsoft Entra ID, Azure RBAC, security groups, PIM, and JIT access workflows.
- Hands-on experience with Azure Policy and resource configurations, including managed identities and Azure AD admin role provisioning.
- Familiarity with Azure monitoring and logging, AAA concepts, and integration with approval workflow tools.
- Strong understanding of least-privilege access design and access control best practices in Azure.
- Competence in baseline configuration management and accurate asset and data inventories.
- Demonstrated experience implementing least-privilege at scale and articulating Azure RBAC rationale.
- Ability to author and maintain IAM policies and procedures, perform access reviews, and support audits.
- Proven capability to implement and govern remote and elevated access and emergency access processes.
- Strong communication and documentation skills for technical writing and stakeholder coordination.
- Ability to collaborate across engineering, security, and operations teams for compliant access practices.
- Nice-to-have: Experience integrating identity workflows with approval systems and ticketing processes.
- Nice-to-have: Exposure to application identity design patterns and CI/CD secret management controls.
- Nice-to-have: Background in supporting audit readiness for access controls in cloud environments.