Overview
Skills
Job Details
Job Title: IAM Engineer
Location: Braintree, MA (Hybrid)
Duration: 6 Months (Tentative)
Position Overview:
A government agency is seeking an experienced Identity and Access Management (IAM) Engineer to support and enhance its identity infrastructure. This role focuses on managing secure and scalable access to digital systems using Microsoft Entra ID (Azure AD), Active Directory, and Single Sign-On (SSO) technologies. The ideal candidate will possess deep technical expertise in IAM and a strong understanding of security standards and regulatory compliance.
Key Responsibilities:
IAM Implementation and Administration:
Assist in designing, configuring, and maintaining IAM frameworks using Microsoft Entra ID (Azure AD), Active Directory, and SSO.
Align IAM policies and controls with business and security objectives.
Active Directory and Entra ID Management:
Administer and support Active Directory forests, domains, and replication.
Optimize Microsoft Entra ID services including MFA, Conditional Access, and Identity Protection.
Ensure high availability and secure operation of directory services.
SSO Configuration and Support:
Implement and support SSO using protocols such as SAML, OAuth, and OpenID Connect.
Integrate SSO with cloud-based and on-premises applications for seamless authentication.
Security and Compliance:
Enforce best practices for RBAC, access governance, and IAM policy design.
Monitor IAM environments for compliance with regulations (e.g., PCI, NIST, 201 CMR 17).
Perform risk assessments, security reviews, and IAM-related audits.
Identity Lifecycle Management:
Oversee user provisioning, de-provisioning, and periodic access reviews.
Automate identity workflows to improve operational efficiency.
Technical Support and Collaboration:
Troubleshoot IAM-related issues, including SSO failures and AD integration.
Collaborate with cybersecurity, IT, and application teams to deliver secure and functional access.
Provide guidance on IAM best practices and support ongoing projects.
Documentation and Reporting:
Develop and maintain documentation for IAM architecture, configurations, and procedures.
Communicate performance metrics and security issues to leadership and stakeholders.
Requirements:
Must be willing and able to travel to offices statewide or other required locations.
Ability to provide on-call IAM support during critical situations.
Preferred Qualifications:
5+ years of experience in IAM with a strong focus on Microsoft Entra ID (Azure AD), Active Directory, and SSO.
Hands-on expertise with authentication protocols such as SAML, OAuth, and OpenID Connect.
Deep understanding of AD infrastructure: forests, trusts, domains, and replication models.
Experience with identity protection technologies, conditional access, and MFA.
Familiarity with regulatory compliance standards: PCI, 201 CMR 17, NIST, etc.
Proficiency in identity lifecycle management and automation of IAM processes.
Strong analytical and troubleshooting skills in IAM environments.
Certifications such as Microsoft Certified: Azure Solutions Architect Expert, CISSP, or Certified Identity and Access Manager (CIAM) are a plus.