Skip to content

Open nowPosted today

Workforce IAM Engineer

The College Board30 open roles

Where
Remote - USA
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowWorkforce IAM EngineerThe College Board · Remote - USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on The College Board's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. The College Board postings stay open a median of 29 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.5%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 33.9%30 days
This job: posted today

The College Board median: 29 days open

The posting

College Board – Technology – Workforce IAM

Location: This is a remote role. Candidates who live near CB offices have the option of being fully remote or hybrid (Tuesday and Wednesday in office). All CB employees are required to occasionally travel to meet in person for business purposes.

Role Type: This is a full-time position

About the Team

The Workforce Identity and Access Management (WIAM) team is the identity control plane for College Board's enterprise. The team owns the full workforce identity lifecycle, from onboarding and provisioning through access governance, certification, and offboarding, and operates the platforms that enforce authentication, authorization, and privileged access management across the organization.

WIAM's work spans six capability pillars: identity onboarding, provisioning, authentication and authorization, credential management, access certification, and identity offboarding. The team is the primary owner of College Board's enterprise IGA platform and PAM infrastructure, and it partners closely with Talent, ISGRC, and security peer teams to ensure identity services are reliable, auditable, and aligned to Zero Trust principles.

The team operates at the intersection of security rigor and user experience; the controls WIAM builds directly affect how every College Board employee accesses systems and data every day. As College Board's workforce has grown and its cloud and SaaS footprint has expanded, WIAM's scope has grown to match: centralizing more applications, automating more lifecycle actions, and governing an increasingly complex mix of human and non-human identities.

About the Opportunity

As a Workforce IAM Engineer on the WIAM team, you are a proactive, self-directed identity engineer who tries a fix before asking for one. You bring real depth in Microsoft Entra ID, Active Directory, and Okta, and you spot what could be better before anyone complains. You will play a hands-on role keeping identity access secure and reliable across a mix of cloud and hybrid platforms at enterprise scale, where clean role design, dependable provisioning, and strong documentation directly support College Board's Zero Trust strategy. This role exists to carry WIAM's persona-based RBAC rollout forward and keep our standing identity platforms running well. With guidance from senior engineers, you will independently design, build, and ship pieces of the rollout, application by application and role by role, while owning day-to-day administration of our enterprise password management and hardware security key platforms.

You will partner closely with senior WIAM engineers, security architects, and the application teams onboarding to Entra ID and Okta to keep access moving without last-mile friction for end users. Success in this role means personas and applications onboarded on schedule, password and hardware key platforms that hold up under real operational load, and identity access that keeps pace as College Board grows.

In this role, you will:

Design, Build, and Maintain: Persona-Based Access (RBAC) (50%)

  • Build, test, deploy, and maintain RBAC roles and access policies as new applications and personas are added to the program
  • Develop and evolve application logic and automations using well-architected, scalable design patterns
  • Build and maintain Microsoft Entra ID and Okta integrations and workflows, including application onboarding, SSO/SCIM configuration, and automation via Microsoft Graph and Okta APIs
  • Write and maintain scripts and tooling (e.g., PowerShell) to automate role assignment, access provisioning, and reporting workflows
  • Maintain existing RBAC roles as organizational structures, entitlements, and applications change over time
  • Write, test, and document code according to team standards, including unit tests, and perform code reviews to help identify patterns for improvement

Operate and Maintain: Password Management and Hardware Security Keys (30%)

  • Administer the enterprise password management platform: vault structure, policies, group and SCIM provisioning, onboarding/offboarding, and version upgrades
  • Support the hardware security key lifecycle: provisioning and enrollment, replacements, PIN resets, and lost/damaged key recovery
  • Coordinate with Asset Management on shipping logistics for hardware security key distribution to end users and reclamation upon offboarding, replacement, or role change
  • Monitor platform health, apply updates, and coordinate with vendors on issues as they arise
  • Contribute to runbooks, documentation, and knowledge-based articles that reduce repeat issues and improve team efficiency

Analysis and Support (20%)

  • Review requirements and identify design considerations, providing feedback on the design and implementation of features
  • Analyze authentication, authorization, and access data to support troubleshooting, audits, and continuous improvement
  • Troubleshoot and resolve application access issues, authentication errors, and integration failures, escalating as appropriate
  • Support end users and partner teams on identity-related requests, RBAC questions, and platform features
  • Participate in the team's on-call rotation, responding to identity platform incidents and following established escalation procedures

About You

To qualify for this role, you must have:

  • 3+ years of IT engineering experience, including at least 1 year administering an enterprise password management platform (1Password preferred; Keeper and Bitwarden also considered)
  • Hands-on experience with Active Directory, Microsoft Entra ID, and Okta, including application onboarding and SSO/SCIM configuration
  • A strong understanding of hardware security tokens such as YubiKey, Google Titan, and Feitian
  • Working knowledge of identity and access management concepts such as role-based access control (RBAC), SSO, SAML/OIDC, and MFA
  • Scripting experience with PowerShell, Python, or both, ideally including automation through the Microsoft Graph API and Entra ID app registrations
  • Working knowledge of ITIL or other change management frameworks, including change requests, incident management, and release processes
  • Experience with cloud platforms, with Azure required and AWS strongly preferred, and with modern development practices such as version control (Git), CI/CD, and code review
  • Exposure to privileged access management (PAM) platforms, such as CyberArk (strongly preferred)
  • A proactive, self-directed approach: you try first, bring what you tried and where you landed when you ask for help, and spot improvements before anyone asks
  • Enthusiasm for learning new technologies, ideally shown through enterprise security certifications or coursework, completed or in progress (e.g., CISSP, CISA, SC-300, AZ-900, Security+, or AI governance)
  • Practical decision-making and a belief in good comments and documentation, reflected in runbooks and knowledge-based articles that others can pick up and use

All roles at College Board require:

  • A passion for expanding educational and career opportunities and mission-driven work
  • Authorization to work in the United States for any employer
  • Curiosity and enthusiasm for emerging technologies, with a willingness to experiment with and adopt new AI-driven solutions and comfort learning and applying new digital tools independently and proactively.
  • Clear and concise communication skills, written and verbal
  • A learner's mindset and a commitment to growth: welcoming diverse perspectives, giving and receiving timely, respectful feedback, and continuously improving through iterative learning and user input
  • A drive for impact and excellence: solving complex problems, making data-informed decisions, prioritizing what matters most, and continuously improving through learning, user input, and external benchmarking
  • A collaborative and empathetic approach: working across differences, fostering trust, and contributing to a culture of shared success

About Our Process

  • Application review will begin immediately and will continue until the position is filled. This role is expected to accept applications for a minimum of 5 business days.
  • While the hiring process may vary, it generally includes: resume and application submission, recruiter phone/video screen, hiring manager interview, performance exercise such as live coding, a panel interview, a conversation with leadership and reference checks.

What We Offer

At College Board, we offer more than just a paycheck—we provide a meaningful career, a supportive team, and a comprehensive package designed to help you thrive. We’re a self-sustaining nonprofit that believes in fair and competitive compensation, grounded in your qualifications, experience, impact, and the market.

A Thoughtful Approach to Compensation

  • The hiring range for this role is $128,000 – $139,000.
  • Your exact salary will depend on your location, experience, and how your background compares to others in similar roles at College Board.
  • We aim to make our best offer upfront—rooted in fairness, transparency, and market data.
  • We adjust salaries by location to ensure fairness, no matter where you live.

You’ll have open, transparent conversations about compensation, benefits, and what it’s like to work at College Board throughout your hiring process. Check out our careers page for more.

#LI-MS1

#LI-REMOTE

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against The College Board's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on The College Board's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    The College Board's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.