2h ago
New
USD 128000-139000/yr

Workforce IAM Engineer

United StatesUnited StatesRemoteFull-timemid
OtherIam Engineer
0 views0 saves0 applied

Quick Summary

Overview

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Workforce IAM Engineer based in the United States.

Technical Tools
OtherIam Engineer

This role sits at the center of enterprise identity and access management, helping secure how employees access applications, systems, and data. You’ll take a hands-on role in designing and maintaining persona-based RBAC across cloud and hybrid environments. The position combines engineering, automation, platform administration, troubleshooting, and security operations at enterprise scale. You’ll work extensively with Microsoft Entra ID, Active Directory, Okta, password management platforms, and hardware security keys. Your work will directly support Zero Trust initiatives while improving reliability and reducing friction for end users. You’ll collaborate with senior engineers, security architects, application teams, and business partners in a highly collaborative environment. This is an opportunity to make meaningful improvements to identity infrastructure while developing expertise across modern security technologies.

  • Design, build, test, deploy, and maintain persona-based RBAC roles and access policies as applications and workforce personas are onboarded.
  • Develop scalable application logic, automation, integrations, and workflows across Microsoft Entra ID and Okta.
  • Configure and maintain application onboarding, SSO, SCIM, and identity automation using Microsoft Graph, Okta APIs, and related technologies.
  • Develop PowerShell and/or Python scripts and tooling to automate role assignment, provisioning, reporting, and identity workflows.
  • Maintain RBAC implementations as organizational structures, entitlements, applications, and access requirements evolve.
  • Write, test, document, and review code in accordance with engineering standards, including appropriate unit testing and version control practices.
  • Administer the enterprise password management platform, including vault structures, policies, group and SCIM provisioning, onboarding, offboarding, and upgrades.
  • Manage the lifecycle of hardware security keys, including enrollment, provisioning, replacements, PIN resets, and recovery of lost or damaged devices.
  • Coordinate with asset management teams on security-key distribution, reclamation, replacement, and offboarding logistics.
  • Monitor identity platform health, apply updates, work with vendors to resolve issues, and maintain operational readiness.
  • Analyze authentication, authorization, and access data to support troubleshooting, audits, and continuous improvement.
  • Investigate and resolve application access problems, authentication errors, and integration failures, escalating issues when appropriate.
  • Support end users and partner teams with identity-related requests, RBAC questions, and platform capabilities.
  • Participate in on-call rotations and respond to identity platform incidents according to established escalation procedures.
  • Contribute to runbooks, knowledge articles, and technical documentation that improve team efficiency and reduce recurring issues.
  • Requirements

    ~2 min read
  • 3+ years of IT engineering experience, including at least 1 year administering an enterprise password management platform; experience with 1Password is preferred, while Keeper or Bitwarden experience is also relevant.
  • Hands-on experience with Active Directory, Microsoft Entra ID, and Okta, including application onboarding and SSO/SCIM configuration.
  • Strong understanding of IAM concepts such as RBAC, SSO, SAML, OIDC, MFA, authentication, authorization, and access governance.
  • Practical experience with hardware security tokens such as YubiKey, Google Titan, or Feitian.
  • Scripting experience with PowerShell, Python, or both, ideally including Microsoft Graph automation and Entra ID application registrations.
  • Working knowledge of ITIL or comparable change-management practices, including change requests, incident management, and release processes.
  • Experience with cloud platforms, with Azure required and AWS strongly preferred.
  • Familiarity with Git, CI/CD, code reviews, and modern software development practices.
  • Exposure to privileged access management platforms such as CyberArk is strongly preferred.
  • Strong troubleshooting, analytical, and practical decision-making abilities, with a proactive approach to identifying and resolving problems.
  • Strong written and verbal communication skills, with the ability to document technical decisions and create useful runbooks and knowledge articles.
  • Willingness and ability to learn emerging technologies and adopt new digital and AI-driven tools.
  • Security certifications or coursework such as CISSP, CISA, SC-300, AZ-900, Security+, or AI governance credentials are advantageous.
  • Ability to work independently while collaborating effectively with engineers, security teams, application owners, and other stakeholders.
  • Authorization to work in the United States for any employer.
  • Commitment to mission-driven work, continuous learning, inclusive collaboration, and delivering measurable impact.
  • What We Offer

    ~2 min read
  • Remote-first position within the United States, with hybrid flexibility available for employees located near designated offices.
  • Full-time employment with occasional travel for in-person business activities.
  • Hiring salary range of $128,000–$139,000, with compensation adjusted based on location, experience, qualifications, impact, and market data.
  • Competitive compensation designed around fairness, transparency, and market benchmarks.
  • Annual bonus opportunities and potential merit-based raises and promotions.
  • Comprehensive benefits package designed to support employee wellbeing and long-term growth.
  • Opportunities for professional development and continued learning in IAM, cloud security, automation, and emerging technologies.
  • Mission-driven work supporting expanded educational and career opportunities.
  • Collaborative environment with opportunities to work alongside experienced security and identity professionals.
  • Meaningful opportunities to contribute to Zero Trust initiatives and enterprise-scale security improvements.
  • How Jobgether works:
    We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
    We appreciate your interest and wish you the best!
     
    Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
     
     
    #LI-CL1
    ✓Remote-first position within the United States, with hybrid flexibility available for employees located near designated offices.
    ✓Full-time employment with occasional travel for in-person business activities.
    ✓Hiring salary range of $128,000–$139,000, with compensation adjusted based on location, experience, qualifications, impact, and market data.
    ✓Competitive compensation designed around fairness, transparency, and market benchmarks.
    ✓Annual bonus opportunities and potential merit-based raises and promotions.
    ✓Comprehensive benefits package designed to support employee wellbeing and long-term growth.
    ✓Opportunities for professional development and continued learning in IAM, cloud security, automation, and emerging technologies.
    ✓Mission-driven work supporting expanded educational and career opportunities.
    ✓Collaborative environment with opportunities to work alongside experienced security and identity professionals.
    ✓Meaningful opportunities to contribute to Zero Trust initiatives and enterprise-scale security improvements.

    Location & Eligibility

    Where is the job
    United States
    Remote within one country
    Who can apply
    US

    Listing Details

    Posted
    October 8, 2026
    First seen
    October 8, 2026
    Last seen
    October 8, 2026

    Posting Health

    Days active
    0
    Repost count
    0
    Trust Level
    80%
    Scored at
    October 8, 2026

    Signal breakdown

    freshnesssource trustcontent trustemployer trust
    Newsletter

    Stay ahead of the market

    Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

    A
    B
    C
    D
    Join 12,000+ marketers

    No spam. Unsubscribe at any time.

    Workforce IAM EngineerUSD 128000-139000