Skip to content

Open nowPosted 8 hours ago

Workforce IAM Engineer

Jobgether3,848 open roles

Where
US
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowWorkforce IAM EngineerJobgether · US
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 6 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 33.9%30 days
This job: posted 8 hours ago

Jobgether median: 6 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Workforce IAM Engineer based in the United States.

This role sits at the center of enterprise identity and access management, helping secure how employees access applications, systems, and data. You’ll take a hands-on role in designing and maintaining persona-based RBAC across cloud and hybrid environments. The position combines engineering, automation, platform administration, troubleshooting, and security operations at enterprise scale. You’ll work extensively with Microsoft Entra ID, Active Directory, Okta, password management platforms, and hardware security keys. Your work will directly support Zero Trust initiatives while improving reliability and reducing friction for end users. You’ll collaborate with senior engineers, security architects, application teams, and business partners in a highly collaborative environment. This is an opportunity to make meaningful improvements to identity infrastructure while developing expertise across modern security technologies.

Accountabilities

  • Design, build, test, deploy, and maintain persona-based RBAC roles and access policies as applications and workforce personas are onboarded.
  • Develop scalable application logic, automation, integrations, and workflows across Microsoft Entra ID and Okta.
  • Configure and maintain application onboarding, SSO, SCIM, and identity automation using Microsoft Graph, Okta APIs, and related technologies.
  • Develop PowerShell and/or Python scripts and tooling to automate role assignment, provisioning, reporting, and identity workflows.
  • Maintain RBAC implementations as organizational structures, entitlements, applications, and access requirements evolve.
  • Write, test, document, and review code in accordance with engineering standards, including appropriate unit testing and version control practices.
  • Administer the enterprise password management platform, including vault structures, policies, group and SCIM provisioning, onboarding, offboarding, and upgrades.
  • Manage the lifecycle of hardware security keys, including enrollment, provisioning, replacements, PIN resets, and recovery of lost or damaged devices.
  • Coordinate with asset management teams on security-key distribution, reclamation, replacement, and offboarding logistics.
  • Monitor identity platform health, apply updates, work with vendors to resolve issues, and maintain operational readiness.
  • Analyze authentication, authorization, and access data to support troubleshooting, audits, and continuous improvement.
  • Investigate and resolve application access problems, authentication errors, and integration failures, escalating issues when appropriate.
  • Support end users and partner teams with identity-related requests, RBAC questions, and platform capabilities.
  • Participate in on-call rotations and respond to identity platform incidents according to established escalation procedures.
  • Contribute to runbooks, knowledge articles, and technical documentation that improve team efficiency and reduce recurring issues.
  • 3+ years of IT engineering experience, including at least 1 year administering an enterprise password management platform; experience with 1Password is preferred, while Keeper or Bitwarden experience is also relevant.
  • Hands-on experience with Active Directory, Microsoft Entra ID, and Okta, including application onboarding and SSO/SCIM configuration.
  • Strong understanding of IAM concepts such as RBAC, SSO, SAML, OIDC, MFA, authentication, authorization, and access governance.
  • Practical experience with hardware security tokens such as YubiKey, Google Titan, or Feitian.
  • Scripting experience with PowerShell, Python, or both, ideally including Microsoft Graph automation and Entra ID application registrations.
  • Working knowledge of ITIL or comparable change-management practices, including change requests, incident management, and release processes.
  • Experience with cloud platforms, with Azure required and AWS strongly preferred.
  • Familiarity with Git, CI/CD, code reviews, and modern software development practices.
  • Exposure to privileged access management platforms such as CyberArk is strongly preferred.
  • Strong troubleshooting, analytical, and practical decision-making abilities, with a proactive approach to identifying and resolving problems.
  • Strong written and verbal communication skills, with the ability to document technical decisions and create useful runbooks and knowledge articles.
  • Willingness and ability to learn emerging technologies and adopt new digital and AI-driven tools.
  • Security certifications or coursework such as CISSP, CISA, SC-300, AZ-900, Security+, or AI governance credentials are advantageous.
  • Ability to work independently while collaborating effectively with engineers, security teams, application owners, and other stakeholders.
  • Authorization to work in the United States for any employer.
  • Commitment to mission-driven work, continuous learning, inclusive collaboration, and delivering measurable impact.
  • Remote-first position within the United States, with hybrid flexibility available for employees located near designated offices.
  • Full-time employment with occasional travel for in-person business activities.
  • Hiring salary range of $128,000–$139,000, with compensation adjusted based on location, experience, qualifications, impact, and market data.
  • Competitive compensation designed around fairness, transparency, and market benchmarks.
  • Annual bonus opportunities and potential merit-based raises and promotions.
  • Comprehensive benefits package designed to support employee wellbeing and long-term growth.
  • Opportunities for professional development and continued learning in IAM, cloud security, automation, and emerging technologies.
  • Mission-driven work supporting expanded educational and career opportunities.
  • Collaborative environment with opportunities to work alongside experienced security and identity professionals.
  • Meaningful opportunities to contribute to Zero Trust initiatives and enterprise-scale security improvements.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.