IAM Engineer
Jobot · Houston, TX · Yesterday
HybridEngineering$140k–$160k/yrFull-time
Core Responsibilities
- Administer and optimize Entra ID and Active Directory environments, including hybrid synchronization.
- Design, implement, and troubleshoot Single Sign-On (SSO) integrations using SAML, OIDC, and OAuth for internal and third-party applications.
- Manage Enterprise Applications in Entra ID, handling onboarding, access provisioning, and lifecycle governance.
- Configure and enforce Multi-Factor Authentication (MFA), Conditional Access policies, Identity Protection, and risk-based controls.
- Oversee Privileged Identity Management (PIM), just-in-time access, and privileged access governance.
- Implement and manage identity lifecycle processes (joiner/mover/leaver) and role-based access control (RBAC) following least-privilege principles.
- Troubleshoot complex authentication, federation, and directory synchronization issues.
- Apply Zero Trust principles across identity systems and support access reviews and certification processes.
- Support Microsoft 365 Exchange Online environments, including mail flow troubleshooting.
- Maintain knowledge of email security standards (SPF, DKIM, DMARC) and related gateway solutions.
- Leverage Microsoft Copilot and other AI tools for accelerated troubleshooting, anomaly detection, and root cause analysis.
- Develop automation solutions using PowerShell, workflows, and orchestration tools to reduce manual tasks.
- Identify and implement AI-enhanced capabilities across identity, security, and messaging operations.
- Create and maintain technical documentation, architecture diagrams (using Visio or equivalent), and operational runbooks.
- Participate in on-call rotation and drive continuous improvement initiatives.
Minimum Qualifications
- Bachelor’s degree in a relevant field.
- 5+ years of hands-on experience in Identity & Access Management within enterprise environments.
- Strong expertise in Entra ID (Azure AD), on-premises Active Directory, Conditional Access, MFA, SSO, PIM, and RBAC.
- Experience supporting Microsoft 365 / Exchange Online.
- Proficiency with PowerShell scripting for automation.
- Solid understanding of Zero Trust, identity governance, and email security best practices.
- Familiarity with Microsoft security/compliance tools and experience implementing AI-assisted IT operations (Copilot or similar).
- Relevant certifications (Azure, Microsoft 365, Security) preferred.