Source-listed Job

Workforce IAM Engineer

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Workforce IAM Engineer based in the United States.

Job Remote Source description available
Jobgether Source published Oct 8, 2026 Source retrieved Oct 8, 2026
Source: jobgether (lever) · A retrieval date records when our system last obtained the source record. It does not guarantee the vacancy is still open or that every detail has been independently checked.
Description from the source The source description is formatted below for discovery. The provider owns the original wording and may change its requirements or close applications.
EmploymentFull-time
Work modeRemote / location-flexible

Overview

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Workforce IAM Engineer based in the United States.

Full job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Workforce IAM Engineer based in the United States. This role sits at the center of enterprise identity and access management, helping secure how employees access applications, systems, and data. You’ll take a hands-on role in designing and maintaining persona-based RBAC across cloud and hybrid environments. The position combines engineering, automation, platform administration, troubleshooting, and security operations at enterprise scale. You’ll work extensively with Microsoft Entra ID, Active Directory, Okta, password management platforms, and hardware security keys. Your work will directly support Zero Trust initiatives while improving reliability and reducing friction for end users. You’ll collaborate with senior engineers, security architects, application teams, and business partners in a highly collaborative environment. This is an opportunity to make meaningful improvements to identity infrastructure while developing expertise across modern security technologies.

Design, build, test, deploy, and maintain persona-based RBAC roles and access policies as applications and workforce personas are onboarded. Develop scalable application logic, automation, integrations, and workflows across Microsoft Entra ID and Okta. Configure and maintain application onboarding, SSO, SCIM, and identity automation using Microsoft Graph, Okta APIs, and related technologies. Develop PowerShell and/or Python scripts and tooling to automate role assignment, provisioning, reporting, and identity workflows. Maintain RBAC implementations as organizational structures, entitlements, applications, and access requirements evolve. Write, test, document, and review code in accordance with engineering standards, including appropriate unit testing and version control practices. Administer the enterprise password management platform, including vault structures, policies, group and SCIM provisioning, onboarding, offboarding, and upgrades. Manage the lifecycle of hardware security keys, including enrollment, provisioning, replacements, PIN resets, and recovery of lost or damaged devices. Coordinate with asset management teams on security-key distribution, reclamation, replacement, and offboarding logistics. Monitor identity platform health, apply updates, work with vendors to resolve issues, and maintain operational readiness. Analyze authentication, authorization, and access data to support troubleshooting, audits, and continuous improvement. Investigate and resolve application access problems, authentication errors, and integration failures, escalating issues when appropriate. Support end users and partner teams with identity-related requests, RBAC questions, and platform capabilities. Participate in on-call rotations and respond to identity platform incidents according to established escalation procedures. Contribute to runbooks, knowledge articles, and technical documentation that improve team efficiency and reduce recurring issues. Requirements 3+ years of IT engineering experience, including at least 1 year administering an enterprise password management platform; experience with 1Password is preferred, while Keeper or Bitwarden experience is also relevant. Hands-on experience with Active Directory, Microsoft Entra ID, and Okta, including application onboarding and SSO/SCIM configuration. Strong understanding of IAM concepts such as RBAC, SSO, SAML, OIDC, MFA, authentication, authorization, and access governance. Practical experience with hardware security tokens such as YubiKey, Google Titan, or Feitian. Scripting experience with PowerShell, Python, or both, ideally including Microsoft Graph automation and Entra ID application registrations. Working knowledge of ITIL or comparable change-management practices, including change requests, incident management, and release processes. Experience with cloud platforms, with Azure required and AWS strongly preferred. Familiarity with Git, CI/CD, code reviews, and modern software development practices. Exposure to privileged access management platforms such as CyberArk is strongly preferred. Strong troubleshooting, analytical, and practical decision-making abilities, with a proactive approach to identifying and resolving problems. Strong written and verbal communication skills, with the ability to document technical decisions and create useful runbooks and knowledge articles. Willingness and ability to learn emerging technologies and adopt new digital and AI-driven tools. Security certifications or coursework such as CISSP, CISA, SC-300, AZ-900, Security+, or AI governance credentials are advantageous. Ability to work independently while collaborating effectively with engineers, security teams, application owners, and other stakeholders. Authorization to work in the United States for any employer. Commitment to mission-driven work, continuous learning, inclusive collaboration, and delivering measurable impact. Benefits Remote-first position within the United States, with hybrid flexibility available for employees located near designated offices. Full-time employment with occasional travel for in-person business activities. Hiring salary range of $128,000–$139,000 , with compensation adjusted based on location, experience, qualifications, impact, and market data. Competitive compensation designed around fairness, transparency, and market benchmarks. Annual bonus opportunities and potential merit-based raises and promotions. Comprehensive benefits package designed to support employee wellbeing and long-term growth. Opportunities for professional development and continued learning in IAM, cloud security, automation, and emerging technologies. Mission-driven work supporting expanded educational and career opportunities. Collaborative environment with opportunities to work alongside experienced security and identity professionals. Meaningful opportunities to contribute to Zero Trust initiatives and enterprise-scale security improvements.

Tips for this job

Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.
Original authoritative source

JobOpportunity.info helps you discover and organize source listings. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Apply through JobOpportunity →

Browse current JobOpportunity listings from jobgether (lever) →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books