Identity & Access Management Engineer
Glocomms · Scottsdale, AZ · 1 wk ago
EngineeringFull-time
About the role
We are seeking an IAM Engineer II to support Identity and Access Management (IAM) operations across enterprise identity platforms. This role is available in Scottsdale, AZ; Atlanta, GA; La Vista, NE; Oakdale, MN; and St. Petersburg, FL.
Responsibilities
- Automate Joiner, Mover, Leaver (JML) processes, including user provisioning, deprovisioning, access requests, and access reviews.
- Manage user and group access assignments using role-based and group-based access controls.
- Troubleshoot identity-related issues, including provisioning failures, directory synchronization problems, and entitlement assignment errors.
- Process access requests and approvals while maintaining entitlement catalogs and standard access definitions.
- Support periodic and ad hoc access certification campaigns.
- Integrate applications with IAM platforms using REST APIs and JSON-based configurations.
- Configure and support Single Sign-On (SSO) integrations using SAML and OpenID Connect (OIDC).
- Ensure adherence to security principles such as least privilege and segregation of duties.
- Support audit activities by collecting and maintaining access control documentation and evidence.
- Follow established change management, incident management, and documentation procedures.
- Utilize PowerShell, REST APIs, or similar tools to automate repetitive tasks and perform identity-related queries.
- Maintain operational documentation, runbooks, knowledge base articles, and user guides.
- Participate in troubleshooting and resolution of IAM-related incidents.
Requirements
- 2+ years of experience in Identity and Access Management, IT Operations, Cybersecurity, or a related field.
- Experience managing user accounts, groups, and access permissions.
- Familiarity with authentication and authorization technologies, including:
- SAML
- OpenID Connect (OIDC)
- Multi-Factor Authentication (MFA)
- Understanding of IAM concepts, including:
- Role-Based Access Control (RBAC)
- User provisioning and deprovisioning
- Joiner/Mover/Leaver (JML) processes
- Experience with PowerShell, Python, or similar scripting languages.
- Strong troubleshooting, analytical, and problem-solving skills.
- Ability to follow documented procedures and maintain accurate records.
- High school diploma or equivalent required. Bachelor's degree preferred.
- Must be eligible to work in the United States without current or future employer sponsorship.
Preferred Qualifications
- Experience with an enterprise IAM platform supporting:
- User provisioning
- Access requests
- Access reviews
- Application connectors
- Experience onboarding applications for SSO.
- Exposure to Privileged Access Management (PAM) tools and processes.
- Understanding of security controls and frameworks, including:
- Least Privilege
- Segregation of Duties (SoD)
- Zero Trust principles
- Ability to analyze logs and troubleshoot authentication or provisioning issues.
- Relevant certifications such as:
- CompTIA Security+
- Microsoft SC-900
- Microsoft SC-300
- ISC² CC
- ISC² SSCP