Workforce IAM Engineer

Jobgether SRL

United States

On-site

USD 110,000 - 140,000

Full time

10 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Jobgether SRL is seeking a Workforce IAM Engineer in the United States to design and maintain persona-based RBAC across hybrid environments. You will work with Microsoft Entra ID, Okta, and password management platforms to secure access and support Zero Trust initiatives.

You will develop automation using PowerShell or Python, implement onboarding, SSO, and SCIM workflows, and help ensure operational readiness through monitoring and documentation.

Qualifications

  • 3+ years of IT engineering experience.
  • Experience with enterprise password management platform (1Password preferred; Keeper or Bitwarden relevant).
  • Hands-on experience with Active Directory, Microsoft Entra ID, and Okta.
  • Strong understanding of IAM concepts (RBAC, SSO, SAML, OIDC, MFA, authentication, authorization, access governance).
  • Practical experience with hardware security tokens (YubiKey, Google Titan, Feitian).
  • Scripting experience (PowerShell, Python).
  • Knowledge of ITIL/change-management and release processes.
  • Experience with Azure and AWS; familiarity with Git, CI/CD, code reviews.

Responsibilities

  • Design, build, test, deploy, and maintain persona-based RBAC roles and access policies as applications and workforce personas are onboarded.
  • Develop scalable automation, integrations, and workflows across Microsoft Entra ID and Okta.
  • Configure onboarding, SSO, SCIM, and identity automation using Microsoft Graph and Okta APIs.
  • Develop PowerShell and/or Python scripts to automate provisioning, reporting, and identity workflows.
  • Maintain RBAC implementations as org structures and access requirements evolve.
  • Assist with runbooks, knowledge articles, and documentation to improve team efficiency.
  • Manage the enterprise password management platform, including vaults, policies, and provisioning workflows.
  • Coordinate with asset management on security-key distribution and offboarding logistics.
  • Monitor identity platform health and coordinate with vendors on issue resolution.

Job description

Our partner is looking for a Workforce IAM Engineer based in the United States. This role sits at the center of enterprise identity and access management, helping secure how employees access applications, systems, and data. You'll take a hands-on role in designing and maintaining persona-based RBAC across cloud and hybrid environments. The position combines engineering, automation, platform administration, troubleshooting, and security operations at enterprise scale. You'll work extensively with Microsoft Entra ID, Active Directory, Okta, password management platforms, and hardware security keys. Your work will directly support Zero Trust initiatives while improving reliability and reducing friction for end users. You'll collaborate with senior engineers, security architects, application teams, and business partners in a highly collaborative environment. This is an opportunity to make meaningful improvements to identity infrastructure while developing expertise across modern security technologies.

Accountabilities
  • Design, build, test, deploy, and maintain persona-based RBAC roles and access policies as applications and workforce personas are onboarded.
  • Develop scalable application logic, automation, integrations, and workflows across Microsoft Entra ID and Okta.
  • Configure and maintain application onboarding, SSO, SCIM, and identity automation using Microsoft Graph, Okta APIs, and related technologies.
  • Develop PowerShell and/or Python scripts and tooling to automate role assignment, provisioning, reporting, and identity workflows.
  • Maintain RBAC implementations as organizational structures, entitlements, applications, and access requirements evolve.
  • Write, test, document, and review code in accordance with engineering standards, including appropriate unit testing and version control practices.
  • Administer the enterprise password management platform, including vault structures, policies, group and SCIM provisioning, onboarding, offboarding, and upgrades.
  • Manage the lifecycle of hardware security keys, including enrollment, provisioning, replacements, PIN resets, and recovery of lost or damaged devices.
  • Coordinate with asset management teams on security-key distribution, reclamation, replacement, and offboarding logistics.
  • Monitor identity platform health, apply updates, work with vendors to resolve issues, and maintain operational readiness.
  • Analyze authentication, authorization, and access data to support troubleshooting, audits, and continuous improvement.
  • Investigate and resolve application access problems, authentication errors, and integration failures, escalating issues when appropriate.
  • Support end users and partner teams with identity-related requests, RBAC questions, and platform capabilities.
  • Participate in on-call rotations and respond to identity platform incidents according to established escalation procedures.
  • Contribute to runbooks, knowledge articles, and technical documentation that improve team efficiency and reduce recurring issues.
Requirements
  • 3+ years of IT engineering experience, including at least 1 year administering an enterprise password management platform; experience with 1Password is preferred, while Keeper or Bitwarden experience is also relevant.
  • Hands-on experience with Active Directory, Microsoft Entra ID, and Okta, including application onboarding and SSO/SCIM configuration.
  • Strong understanding of IAM concepts such as RBAC, SSO, SAML, OIDC, MFA, authentication, authorization, and access governance.
  • Practical experience with hardware security tokens such as YubiKey, Google Titan, or Feitian.
  • Scripting experience with PowerShell, Python, or both, ideally including Microsoft Graph automation and Entra ID application registrations.
  • Working knowledge of ITIL or comparable change-management practices, including change requests, incident management, and release processes.
  • Experience with cloud platforms, with Azure required and AWS strongly preferred.
  • Familiarity with Git, CI/CD, code reviews, and modern software development practices.
  • Exposure to privileged access management platforms such as CyberArk is strongly preferred.
  • Strong troubleshooting, analytical, and practical decision-making abilities, with a proactive approach to identifying and resolving problems.
  • Strong written and verbal communication skills, with the ability
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

ZR_2927_JOB
ZR_2927_JOB

Zohorecruit • New York (NY)

On-site
USD 150,000 - 190,000
IAM Engineer (REMOTE)
IAM Engineer (REMOTE)

Conexess Group • Livonia (MI)

On-site
USD 100,000 - 140,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000
Workforce IAM Engineer: RBAC, Zero Trust & Automation
Workforce IAM Engineer: RBAC, Zero Trust & Automation

Jobgether SRL • United States

On-site
USD 110,000 - 140,000
Identity and Access Management Engineer
Identity and Access Management Engineer

Princeton IT Services, Inc • New York (NY)

On-site
USD 96,000 - 179,000
Senior IT Security Analyst
Senior IT Security Analyst

Cybersecurity Jobs • Denver (CO)

On-site
USD 140,000 - 190,000
Medical benefits
401(k) match
Paid time off
+1
Infrastructure Engineer
Infrastructure Engineer

Huxley • Boston (MA)

On-site
USD 120,000 - 150,000
Identity & Access Management (IAM)- Senior Engineer - Microsoft Entra
Identity & Access Management (IAM)- Senior Engineer - Microsoft Entra

ARK Infotech Spectrum India Pvt. Ltd • Dallas (TX)

Hybrid
USD 110,000 - 150,000
Hybrid work arrangement
Information Security Identity and Access Engineer
Information Security Identity and Access Engineer

PSECU • Harrisburg

Hybrid
USD 100,000 - 140,000
IAM & Security Engineer: Entra ID, AD, RBAC
IAM & Security Engineer: Entra ID, AD, RBAC

Cypress HCM • Cincinnati (OH)

On-site
USD 70,000 - 90,000
Benefits
Community Involvement
PTO
+2