New York, United States | Posted on 06/01/2026
Key Responsibilities
- Design, develop,and maintain IAM solutions and automation across enterprise multi-cloudenvironments (Azure, AWS, GCP).
- Build andenhance automation for identity provisioning, access governance,privileged access workflows, and authentication integrations usingPowerShell, Python, and Microsoft Graph / Entra APIs.
- Administer andsupport Active Directory and Microsoft Entra ID environments, includinghybrid identity operations, Conditional Access, MFA, Identity Protection,PIM, app registrations, and service principal governance.
- Develop andmaintain application integrations using SAML, OIDC, OAuth2, LDAP, and SCIMprovisioning — including end-to-end configuration, attribute mapping,token validation, and troubleshooting.
- Build andsupport SCIM-based auto-provisioning workflows for enterprise applicationonboarding, ensuring consistent identity lifecycle management acrossplatforms.
- Engineeridentity solutions aligned with multi-cloud identity strategies —including cross-tenant configurations, cloud-native IAM services, andfederated identity architectures.
- Partner withinfrastructure, security, and application teams to implement secure accesscontrols, identity governance models, and enterprise identity standards.
- Contribute tothe design of secure identity architecture; document technical designs,integration patterns, and operational procedures.
- Troubleshoot andresolve complex IAM issues across authentication, authorization,federation, provisioning, and directory services.
- Supportgovernance, audit, and compliance activities related to identity andaccess controls.
Required Skills & Experience
- 8+ years ofexperience in identity and access management with a strong development andautomation background.
- Demonstratedability to write production-quality automation in PowerShell and Python.
- Strong hands-onexperience with Active Directory and hybrid identity as a foundation forcloud identity work.
- Deep experiencewith Microsoft Entra ID including Conditional Access, MFA, IdentityProtection, PIM, app registrations, service principal governance, andMicrosoft Graph API.
- Hands-onexperience integrating enterprise applications using SAML, OIDC, OAuth2,and SCIM provisioning — including end-to-end configuration, attributemapping, token validation, and federation troubleshooting.
- Multi-cloudidentity experience across at least two of: Azure Entra ID, AWS IAM / IAMIdentity Center, GCP Identity and Access Management.
- Experience withfederated identity architectures, cross-tenant configurations, andcloud-native IAM services.
- Proficiency withMicrosoft Graph API and Entra APIs for automation, governance, andintegration development.
- Familiarity withenterprise IAM and PAM platforms such as SailPoint, Okta, and CyberArk.
Strong understanding ofidentity protocols and standards: Kerberos, NTLM, LDAP, SAML, OIDC, OAuth2, andSCIM