JobTarget Logo

Enterprise IAM Operations Engineer with Entra ID, RBAC, and Application Integration (copy) in Abbeyville, Colorado at Jobgether

NewJob Function: Engineering
Jobgether
Abbeyville, Colorado, 81210, United States
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

Enterprise IAM Operations Engineer with Entra ID, RBAC, and Application Integration (copy)

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Enterprise IAM Operations Engineer with Entra ID, RBAC, and Application Integration based in United States.

This senior-level role is responsible for strengthening enterprise identity and access management across a complex hybrid and multi-cloud environment.
You’ll help design and operate secure access models spanning Microsoft Entra ID, Azure RBAC, privileged access, application identities, and enterprise SSO.
The position combines hands-on IAM operations with cloud access governance, automation, monitoring, and identity security initiatives.
You’ll work closely with Security, Cloud, Infrastructure, Applications, DevOps, Audit, and other technical teams to balance security with business needs.
The role offers the opportunity to modernize RBAC, improve least-privilege practices, strengthen ITDR capabilities, and enhance operational efficiency.
You’ll also contribute to IAM transformation initiatives, including identity governance migration and multi-cloud access management.
This is a full-time, 12-month staff augmentation engagement within a highly regulated enterprise environment.

Accountabilities:
  • Design, maintain, and optimize Azure RBAC across subscriptions, management groups, resource groups, and Azure services, while establishing governed enterprise role structures.
  • Administer Microsoft Entra ID/Azure AD, Active Directory, hybrid identity, and workforce, partner, guest, service, and application identities.
  • Implement and manage Entra PIM, Just-in-Time privileged access, MFA, Conditional Access, break-glass procedures, privileged access monitoring, and audit controls.
  • Design, implement, and troubleshoot SAML, OIDC, OAuth, SSO, enterprise applications, app registrations, service principals, claims, groups, and application roles.
  • Promote managed identities, govern service principals, support credential rotation, and strengthen CI/CD secret-management practices.
  • Support identity governance transformation initiatives, including the transition from Saviynt to SailPoint and associated identity, entitlement, role, certification, policy, and control documentation.
  • Monitor and investigate identity-related activity using Azure-native monitoring capabilities and Splunk or comparable SIEM technologies, supporting ITDR use cases.
  • Support AWS IAM, GCP IAM, workload identity, and broader multi-cloud access governance where required.
  • Contribute to regulated-environment controls, configuration baselines, change management, audit readiness, and privileged access governance.
  • Develop automation and scripts to streamline IAM workflows, reporting, documentation, access reviews, runbooks, and operational processes.
  • Identify responsible opportunities to use AI-assisted tools for IAM analysis, reporting, documentation, and workflow optimization.
  • Collaborate across Information Security, Cloud, Infrastructure, Applications, DevOps, Audit, and other technical teams while maintaining strong operational and security standards.
Requirements:
  • 7+ years of professional Identity and Access Management experience, with at least 4 years of hands-on Microsoft Entra ID/Azure AD experience preferred.
  • 3+ years of experience with Azure RBAC, privileged access, or cloud access governance preferred.
  • Strong practical knowledge of Entra ID/Azure AD, Azure RBAC, security groups, role assignments, management groups, subscriptions, and resource-level access.
  • Hands-on experience with Entra PIM, JIT privileged access, MFA, Conditional Access, and privileged authentication.
  • Strong understanding of Active Directory and hybrid identity architectures.
  • Enterprise experience with SAML, OIDC, OAuth, SSO, enterprise applications, app registrations, managed identities, service principals, claims, and application roles.
  • Demonstrated knowledge of least-privilege access design, access reviews, access certification, identity and entitlement inventories, credential management, and secret hygiene.
  • Experience with Azure monitoring and logging, Splunk, or comparable SIEM platforms, together with an understanding of Identity Threat Detection and Response.
  • Experience developing IAM automation and scripting solutions and implementing identity controls within CI/CD environments.
  • Strong documentation capabilities across IAM policies, standards, procedures, runbooks, technical guidance, and audit evidence.
  • Experience with SailPoint, IdentityIQ, IdentityNow, Saviynt, or Saviynt-to-SailPoint migration projects is an advantage.
  • Familiarity with PAM solutions such as Broadcom/Symantec PAM, CyberArk, BeyondTrust, or Delinea is a plus.
  • Experience with AWS IAM, GCP IAM, multi-cloud identity governance, FedRAMP controls, or highly regulated financial services environments is advantageous.
  • Bachelor’s degree in Information Security, Computer Science, Information Technology, or a related field, or equivalent practical experience.
  • Strong troubleshooting, analytical, communication, documentation, and problem-solving skills, with the ability to collaborate across security, cloud, infrastructure, application, DevOps, and audit teams.
  • Ability to operate effectively within disciplined change-control, compliance, audit, and operational-stability environments while balancing security requirements with technical and business priorities.
  • Must be eligible to work in Canada and able to satisfy applicable background verification requirements.
Benefits:
  • Full-time, 12-month staff augmentation contract.
  • Remote work arrangement within United States.
  • Standard full-time working hours, with occasional weekend availability for scheduled change-management activities.
  • Opportunity to work on enterprise-scale IAM, cloud security, application integration, PAM, IGA, SIEM, and identity governance initiatives.
  • Exposure to complex hybrid and multi-cloud environments and highly regulated security and compliance requirements.
  • Collaboration with cross-functional teams spanning Security, Cloud, Infrastructure, Applications, DevOps, and Audit.
  • Opportunity to contribute to IAM modernization, automation, operational efficiency, and identity security transformation.
  • Professional environment focused on strong technical standards, security, accountability, and continuous improvement.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

Job Location

Abbeyville, Colorado, 81210, United States

Frequently asked questions about this position

Similar Jobs In Abbeyville, Colorado

New
New

Sr. Principal Product Manager

Jobgether
Abbeyville, Colorado
New

Sr Manager Continuous Improvement

Jobgether
Abbeyville, Colorado
New

Senior Manager, Security Engineering

Jobgether
Abbeyville, Colorado
New

Senior Product Manager

Jobgether
Abbeyville, Colorado
Continue to apply
Enter your email to continue. You’ll be redirected to the employer’s application.
By clicking Continue, you understand and agree to JobTarget's Terms of Use and Privacy Policy.