Senior Identity & Access Management (IAM) Engineer, Workforce Identity
On-siteAtlanta, Georgia, United States or Grand Rapids, Michigan, United States
Job Summary
Design and operate Acrisure's Workforce Identity Platform across Microsoft Entra ID, Active Directory, and cloud platforms, implementing federation, authentication, and least privilege patterns. Manage tenant architecture, Conditional Access, MFA, and identity protection while automating provisioning pipelines using PowerShell, Terraform, and the Microsoft Graph API. Troubleshoot authentication issues, govern application registrations, and execute access reviews to maintain compliance with SOC 2, PCI DSS, and ISO 27001 standards. Collaborate with security teams on incident response and identity-centric detections. Participate in on-call rotation and structured cross-training to ensure operational resiliency.
Required Qualifications
- 5+ years of experience in Identity and Access Management engineering supporting hybrid and multi-cloud enterprise environments
- Strong experience administering Microsoft Entra ID, Active Directory, and hybrid identity architectures at enterprise scale
- Strong knowledge of AWS IAM, Azure identity services, and authentication technologies including SAML, OIDC, OAuth2, and SCIM
- Strong experience implementing and operating Conditional Access, Identity Protection, MFA, phishing-resistant authentication, and passwordless authentication solutions
- Experience with Entra Connect, cloud synchronization, and hybrid identity operations
- Experience with PowerShell, Microsoft Graph API, Python, Terraform, or other automation technologies
- Experience with PAM platforms such as Delinea, CyberArk, BeyondTrust, or Azure PIM
- Experience with identity governance and administration (IGA) platforms such as SailPoint, Saviynt, or Okta
- Strong understanding of Zero Trust Architecture, least privilege, RBAC, and privileged access design principles
- Proven ability to translate business requirements into secure, scalable, and supportable identity solutions
- Strong troubleshooting skills across authentication, federation, access governance, and directory services
- Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership
Desired Qualifications
- Experience supporting large-scale Microsoft Entra ID tenant administration and governance programs
- Familiarity with NIST 800-63, NIST CSF, CIS Controls, and Zero Trust Maturity Models
- Experience integrating IAM, PAM, and IGA telemetry into SIEM platforms
- Experience securing workforce, workload, and machine identities in cloud-native environments
- Relevant certifications such as: CISSP, CISM, Microsoft Certified: Identity and Access Administrator Associate, Microsoft Certified: Azure Security Engineer Associate, AWS Security Specialty, Okta Certified Professional, SailPoint Certified Engineer
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.