IAM (Identity Access Management) Engineer
About the job
Job Description:
Our client, a University, is seeking a technically skilled and proactive Identity and Access Management (IAM) Engineer with deep expertise in Microsoft identity, infrastructure, and federated authentication technologies. This role is critical in managing the university's identity lifecycle and ensuring secure, seamless access for staff and students to digital services across Active Directory (AD), Microsoft Entra ID, Microsoft 365, and federated identity platforms.
The successful candidate will maintain and enhance the university identity provisioning system, which integrates with Student Information System, HR systems and multiple downstream applications. The existing identity repository architecture uses a SQL-based staging repository with a library of scripts and APIs to provide timely access to resources. The successful applicant will be the IT Services owner of the identity platform ensuring the system is operational on a daily basis, quickly troubleshooting and resolving issue, and enhancing and developing system to meet emerging needs.
Responsibilities include:
- Proactively identify opportunities to enhance and develop the identity platform, integrating new features, improving automation, and adopting emerging security standards to meet evolving university needs.
- Design, manage, and support the university's hybrid identity infrastructure, including Active
- Directory, Microsoft Entra ID, and Azure AD Connect.
- Administer and configure Microsoft Entra ID features
- Manage and optimize Microsoft 365 identity integrations
- Maintain and enhance the SQL-based identity staging repository used for provisioning and deprovisioning accounts.
- Automate identity lifecycle processes (joiners, movers, leavers) using PowerShell, Microsoft Graph API, and other tools.
- Collaborate with application and data owners to ensure accurate and timely identity data flows.
- Act as a subject matter expert and provide guidance to IT teams and university stakeholders on IAM best practices, IAM security standards, and new identity solutions.
- Ensure compliance with security policies, data protection regulations, and audit requirements.
- Document standards, processes, configurations, and workflows to deliver best-in-class service, support continuity and knowledge sharing.
- Provide documentation to relevant stakeholders including internal and external auditors and respond to compliance queries.
Essential Criteria:
- Bachelor's degree in computer science, Information Technology or a related field, or significant proven experience in a similar role.
- At least 5 years' experience working with Microsoft technologies.
- Proven experience leading and delivering complex IT/Technical projects
- Proven experience managing Microsoft identity platforms
- Proficiency in PowerShell scripting, SQL database and automation skills for managing data pipelines and transformations.
- Familiarity with Microsoft Graph API, Entra ID Connect, and Entra ID Governance.
- Understanding of IAM best practices, including RBAC, least privilege, and zero trust principles.
- Understanding of security principles and best practices around securing identities
- Ability to work independently and collaboratively within a team environment.
- Strong communication skills, both written and verbal, with the ability to articulate complex technical concepts to non-technical stakeholders
Desirable Criteria:
- Experience in higher education or large-scale enterprise environments.
- Familiarity with identity governance platforms (e.g., SailPoint, Saviynt).
- Experience with cloud infrastructure (e.g., Azure IaaS/PaaS) and hybrid networking.
- Knowledge of implementing IAM in a Zero Trust environment
- Knowledge of ITIL practices and service management tools.
- Relevant Microsoft certifications are highly desirable, such as:
- Microsoft Certified: Identity and Access Administrator Associate
- Microsoft Certified: Windows Server Hybrid Administrator Associate
- Microsoft Certified: Security, Compliance, and Identity Fundamentals