Identity Governance & Access Management (IGA/IAM) Engineer

Ledgent Technology

Denver (CO)

Hybrid

USD 214,906,000 - 272,214,000

Full time

33 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hospital indemnity plans
Dental coverage
Vision coverage
Life insurance
Short-term disability

Job summary

Ledgent Technology is seeking an Identity Governance & Access Management Engineer in Denver to design and oversee IAM/RBAC frameworks across the enterprise. The role includes leading IGA initiatives, administering Entra ID and Active Directory, and supporting Intune-based endpoint management in a hybrid environment.

You will drive least-privilege access models, perform access reviews, and manage lifecycle workflows while collaborating with security, IT ops, and application teams to ensure

Qualifications

  • 3+ years of IAM/IGA experience or equivalent.
  • Hands-on with least-privilege access and entitlement management.
  • Experience administering Microsoft Entra ID, Azure AD, or hybrid identities.
  • Knowledge of SSO, MFA, and Conditional Access.

Responsibilities

  • Design, implement, and maintain RBAC frameworks and access policies across the enterprise.
  • Lead Identity Governance and Administration initiatives and platform optimization.
  • Develop provisioning and deprovisioning workflows; support joiner/mower/leaver processes.
  • Administer Microsoft Entra ID and Active Directory in hybrid environments.
  • Support audit, SOX controls, and access certification programs.

Skills

IAM
RBAC
Entra ID (Azure AD)
Microsoft Intune
Hybrid identity
SOX compliance
PIM
SSO
Access governance
Identity lifecycle management

Tools

PowerShell
Microsoft Graph API
SailPoint
Saviynt
Entra ID Governance

Job description

Identity Governance & Access Management (IGA/IAM) Engineer (JN -092026-430839) Denver, Colorado

Salary: USD75 - USD95 per hour

Location: Downtown Denver

Schedule: Hybrid (3 days onsite)
Employment Type: W2 - Long-Term Contract (6-12 months)
Compensation: Flexible depending on level of experience

**We are unable to partner with third-party vendors or engage in Corp-to-Corp (C2C) arrangements.**

Overview

We are seeking an experienced IAM / RBAC Engineer to lead the design, implementation, and ongoing management of Identity and Access Management (IAM) and Role-Based Access Control (RBAC) initiatives across the enterprise. This role will be responsible for establishing and maintaining scalable access governance frameworks, enforcing least-privilege principles, and supporting identity lifecycle management processes.

In addition to IAM responsibilities, this position will provide administration and support for Microsoft Intune, ensuring secure and compliant endpoint management across the organization. The ideal candidate will have strong experience with identity governance, access controls, Microsoft Entra ID, Active Directory, and endpoint management technologies.

Key Responsibilities
Identity & Access Management (Primary Focus)
  • Design, implement, and maintain enterprise RBAC frameworks, including roles, entitlements, and access policies.
  • Lead or support Identity Governance and Administration (IGA) initiatives, including platform implementation and optimization.
  • Develop and maintain least-privilege access models across applications and infrastructure.
  • Perform access analysis, entitlement reviews, and ongoing role optimization.
  • Manage user lifecycle processes, including Joiner, Mover, and Leaver workflows.
  • Administer and support access certification campaigns, periodic access reviews, and governance processes.
  • Design and maintain provisioning and deprovisioning workflows to ensure timely and secure access changes.
  • Partner with application owners, security teams, and business stakeholders to map job functions to appropriate access models.
  • Support audit, compliance, and regulatory requirements, including SOX controls, segregation of duties, and access certification activities.
  • Create and maintain documentation for access governance standards, procedures, and controls.
  • Administer Microsoft Entra ID (Azure AD), Active Directory, and hybrid identity environments.
  • Manage groups, role assignments, and access delegation strategies.
  • Configure and support Privileged Identity Management (PIM).
  • Implement and maintain Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Conditional Access policies.
  • Support identity-related security initiatives and incident resolution.
Microsoft Intune Administration (20-30% of Role)
  • Administer Microsoft Intune for endpoint and device management.
  • Manage Windows device enrollment and provisioning, including Windows Autopilot.
  • Configure and maintain compliance policies, configuration profiles, and endpoint security policies.
  • Deploy and manage applications across enterprise devices.
  • Support software deployment, patch management, and device lifecycle activities.
  • Monitor and maintain endpoint compliance and security posture.
Required Qualifications
  • 3+ years of experience in Identity and Access Management (IAM), Identity Governance, or Access Management.
  • Hands-on experience with least-privilege access controls and entitlement management.
  • Strong understanding of identity governance processes, including:
  • Joiner, Mover, and Leaver processes
  • Access reviews and certifications
  • Provisioning and deprovisioning workflows
  • Experience administering Microsoft Entra ID (Azure AD), Active Directory, or hybrid identity environments.
  • Knowledge of:
  • Role assignments and security groups
  • Privileged Identity Management (PIM)
  • Single Sign-On (SSO)
  • Conditional Access
  • Experience with Microsoft Intune or similar MDM/UEM platforms.
  • Understanding of segregation of duties (SoD), access governance, and security best practices.
  • Strong documentation, communication, and stakeholder management skills.
Preferred Qualifications
  • Experience with Identity Governance and Administration (IGA) platforms such as SailPoint, Saviynt, or Entra ID Governance.
  • Experience automating IAM processes using PowerShell, Microsoft Graph API, or similar tools.
  • Experience supporting SOX compliance, access audits, or governance programs.
  • Knowledge of endpoint security and modern device management best practices.
  • Relevant certifications such as:
  • Microsoft Identity and Access Administrator
  • Security+
  • Other IAM or cybersecurity-related certifications
Ideal Candidate

The ideal candidate has successfully built or redesigned RBAC frameworks, implemented identity governance processes, and administered Microsoft Entra ID in complex enterprise environments. They possess a strong understanding of access controls, governance, and compliance requirements while also being comfortable managing Microsoft Intune for endpoint administration. This individual will be a hands-on contributor who can partner effectively with Security, IT Operations, and application teams to drive mature access management practices across the organization.

At Ledgent Technology/Roth Staffing, we prioritize our contractors, whom we proudly call Ambassadors. Our commitment to you is demonstrated through a comprehensive benefits program that stands out in the temporary staffing industry. We annually review and update our vendor relationships to ensure we provide the most cost-effective benefits options. Our Ambassadors are eligible for a wide range of benefits, including:

  • Basic and enhanced hospital indemnity plans
  • Dental and vision coverage
  • Accident and critical illness plans
  • Term life insurance
  • Short-term disability plan
  • Training and coaching
  • Specialized recognition programs
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Identity and Access Management Engineer
Identity and Access Management Engineer

Princeton IT Services, Inc • New York (NY)

Hybrid
USD 96,000 - 179,000
Senior IAM Engineer #3285
Senior IAM Engineer #3285

Genius Road, LLC • Austin (TX)

On-site
USD 120,000 - 150,000
Contract IAM & RBAC Engineer — Hybrid (Denver)
Contract IAM & RBAC Engineer — Hybrid (Denver)

Ledgent Technology • Denver (CO)

Hybrid
USD 214,906,000 - 272,214,000
Hospital indemnity plans
Dental coverage
Vision coverage
+2
IAM & Security Engineer: Entra ID, AD, RBAC
IAM & Security Engineer: Entra ID, AD, RBAC

Cypress HCM • Cincinnati (OH)

On-site
USD 70,000 - 90,000
Senior Identity & Access Management (IAM) Engineer
Senior Identity & Access Management (IAM) Engineer

SRG • United States

Hybrid
USD 120,000 - 160,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000
Cybersecurity Engineer
Cybersecurity Engineer

SSA Marine • Seattle (WA)

Hybrid
USD 130,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+11
Senior IAM Engineer
Senior IAM Engineer

Total Quality Logistics • Cincinnati (OH)

Hybrid
USD 120,000 - 180,000
Hybrid work model
Relocation assistance
Health, dental, vision
Identity and Access Management (IAM) Onsite Lead
Identity and Access Management (IAM) Onsite Lead

Randstad Digital Americas • Houston (TX)

On-site
USD 105,000 - 110,000
Identity and Access Management Consultant
Identity and Access Management Consultant

Collective Insights • Atlanta (GA)

Hybrid
USD 110,000 - 150,000