Identity and Access Management Engineer

Open Dealer Exchange

Southfield (MI)

Hybrid

USD 120,000 - 150,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Competitive compensation package

Job summary

Open Dealer Exchange is seeking an Identity and Access Management Engineer to mature our RBAC program and govern access across Entra ID, Active Directory, and external identities. You will automate lifecycle events, define naming and group structures, and advise on token handling and federation patterns.

The role emphasizes governance, compliance documentation, and collaboration with security engineers to strengthen our enterprise identity posture in a hybrid environment.

Qualifications

  • 5+ years IAM engineering experience with at least 3 years on Entra ID in enterprise environments.
  • Deep AD knowledge including group policy, OU design, domain trust, and hybrid identity.
  • Experience designing scalable RBAC models in complex or legacy environments.
  • Hands-on Entra ID Governance: access reviews, entitlement management, lifecycle workflows, PIM.
  • Strong knowledge of OAuth 2.0, OIDC, and SAML for secure integrations.
  • Experience automating identity lifecycle events using Logic Apps, Azure Functions, PowerShell, or Graph API.
  • Ability to communicate risk to non-technical stakeholders and produce compliance-ready docs.

Responsibilities

  • Design and implement enterprise RBAC across Entra ID, AD, and Entra External ID.
  • Lead identity lifecycle automation from HR system to provisioning/deprovisioning.
  • Govern directory structure, naming conventions, and access review cadences.
  • Govern service accounts and app registrations with least-privilege controls.
  • Advise development teams on token handling, sessions, and federation patterns.
  • Design and own Conditional Access and Privileged Identity Management.
  • Support External ID governance, tenant config, policies, and user flows.
  • Produce audit-ready entitlement inventories and runbooks.

Skills

IAM engineering
Entra ID (Azure AD)
Active Directory
RBAC design
Identity lifecycle automation
OAuth 2.0 / OIDC / SAML
PowerShell / Graph API
Governance & compliance
3+ years Entra ID Governance

Education

Bachelor's degree in CS or related field

Tools

Logic Apps
Azure Functions
Microsoft Graph API

Job description

Description
Identity and Access Management Engineer

Open Dealer Exchange (ODE), is seeking an Identity and Access Management (IAM) Engineer to support its workforce in Southfield, MI. As an IAM Engineer, you will own and mature our identity security posture across a complex, multi-platform environment, serving as the primary driver of a structured role based access control (RBAC) program and a trusted technical advisor across infrastructure, IT, and development teams. The ideal candidate will have deep experience with Entra ID, Active Directory, identity lifecycle automation, and governing access in regulated enterprise environments. Open Dealer Exchange is a dynamic, exciting place to work. Open Dealer Exchange offers a hybrid work model as well as an excellent compensation/benefit package.

Responsibilities
  • Design and implement enterprise RBAC: Build a cohesive role-based access control model across Entra ID, Active Directory, and Entra External ID, replacing ad hoc access grants with governed, role-aligned entitlements.
  • Lead identity lifecycle automation: Integrate the HR system with Entra ID to automate provisioning and deprovisioning, ensuring access changes are event-driven and auditable at the point of hire, transfer, and termination.
  • Govern directory structure and access hygiene: Define and enforce naming conventions, group structures, and access review cadences across all directory platforms.
  • Manage non-human identities: Govern service accounts, including managed identities, service principals, and app registrations, enforcing least privilege and credential hygiene across all environments.
  • Advise development teams on identity security: Provide architectural guidance on token handling, session management, and federation patterns for teams building or maintaining identity adjacent systems.
  • Drive Conditional Access and PIM: Lead Conditional Access policy design and own Privileged Identity Management configuration and the privileged access model for admin roles across Azure and M365.
  • Support Entra External ID governance: Advise teams on External ID tenant configuration, custom policy, user flows, and external identity federation.
  • Produce compliance-ready documentation: Maintain IAM documentation including access control matrices, provisioning runbooks, and audit-ready entitlement inventories supporting FCRA and FTC Safeguards Rule obligations.
  • Collaborate across the security program: Align IAM initiatives with the broader security roadmap and participate in change management and architecture review processes alongside security engineers and the Cybersecurity Manager.
Requirements
Required Skills & Experience
  • 5+ years of hands-on IAM engineering experience, with at least 3 years focused on Entra ID (Azure AD) in enterprise environments.
  • Deep working knowledge of Active Directory, including group policy, OU design, domain trust models, and hybrid identity patterns.
  • Demonstrated experience designing and implementing RBAC models at scale in complex or legacy environments.
  • Hands-on experience with Entra ID Governance, including access reviews, entitlement management, lifecycle workflows, and Privileged Identity Management (PIM).
  • Strong working knowledge of OAuth 2.0, OIDC, and SAML, sufficient to review developer implementations and identify security risk.
  • Practical experience automating identity lifecycle events using Logic Apps, Azure Functions, PowerShell, or the Microsoft Graph API.
  • Ability to communicate risk clearly to non-technical stakeholders and produce compliance-ready documentation.
  • Will accept any suitable combination of education, training, or experience.
Preferred Skills & Experience
  • Experience in regulated industries such as financial services, fintech, or automotive with access control obligations.
  • Familiarity with FTC Safeguards Rule requirements or equivalent data security regulatory frameworks.
  • Prior experience integrating an HRIS platform (Workday, BambooHR, UKG, or similar) with Entra ID via SCIM or custom connector.
  • Exposure to IGA platforms such as SailPoint, Saviynt, or Omada.
  • Experience advising development teams on token validation, scope design, role claims, and secure session management.
  • Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent professional experience.
  • Relevant certifications: SC-300 (Microsoft Identity and Access Administrator), AZ-500 (Microsoft Azure Security Technologies), or equivalent
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Engineer (Identity and Access Management)
Senior Cybersecurity Engineer (Identity and Access Management)

Open Dealer Exchange • Southfield (MI)

Hybrid
USD 150,000 - 190,000
Hybrid work model
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Open Dealer Exchange • Southfield (MI)

Hybrid
USD 140,000 - 190,000
Hybrid work model
Enterprise Identity Architect
Enterprise Identity Architect

Open Dealer Exchange • Southfield (MI)

Hybrid
USD 100,000 - 130,000
Identity and Access Management Architect
Identity and Access Management Architect

Deal Exchange, LLC • Southfield (MI)

Hybrid
USD 110,000 - 140,000
IAM Architect
IAM Architect

Conexess Group • Farmington Hills (MI)

On-site
USD 130,000 - 170,000
Senior IAM Engineer — RBAC & Entra ID Architect
Senior IAM Engineer — RBAC & Entra ID Architect

Open Dealer Exchange • Southfield (MI)

Hybrid
USD 150,000 - 190,000
Hybrid work model
Identity and Access Management Engineer
Identity and Access Management Engineer

Princeton IT Services, Inc • New York (NY)

Hybrid
USD 96,000 - 179,000
IAM & Security Engineer: Entra ID, AD, RBAC
IAM & Security Engineer: Entra ID, AD, RBAC

Cypress HCM • Cincinnati (OH)

On-site
USD 70,000 - 90,000
Sr. IAM Engineer, Infrastructure Services
Sr. IAM Engineer, Infrastructure Services

Scorpion Therapeutics • Bridgewater (MA)

On-site
USD 120,000 - 180,000
Infrastructure Engineer
Infrastructure Engineer

Huxley • Boston (MA)

On-site
USD 120,000 - 150,000