Location: Braintree, MA (Onsite)
Duration: 6 Months (Tentative)
We are seeking a highly skilled IAM Engineer to join a government-affiliated IT team responsible for maintaining and securing the organization’s identity and access infrastructure. The ideal candidate will play a critical role in supporting enterprise-wide access to digital resources while upholding security, scalability, and compliance with industry standards. This role focuses on Microsoft Entra ID (Azure AD), Active Directory, and Single Sign-On (SSO) implementations.
Design, configure, and maintain the IAM ecosystem using Microsoft Entra ID (Azure AD), Active Directory, and SSO tools.
Align IAM strategies with security policies and business needs.
Administer and support Active Directory forests, domains, trusts, and replication.
Manage and enhance Microsoft Entra ID services such as MFA, conditional access, and identity protection.
Configure and support SSO using SAML, OAuth, and OpenID Connect protocols.
Integrate SSO with both cloud-based and on-premises applications.
Enforce IAM best practices including RBAC, access controls, and identity governance.
Ensure compliance with standards such as PCI, NIST, and 201 CMR 17.
Conduct security audits and risk assessments to ensure robust identity management.
Manage the complete lifecycle of user identities including provisioning, de-provisioning, and access reviews.
Optimize IAM workflows through automation.
Troubleshoot IAM and SSO-related issues.
Collaborate with cybersecurity, IT, and application teams to maintain seamless identity access control.
Provide guidance and technical expertise on IAM practices.
Maintain up-to-date documentation of IAM configurations and procedures.
Provide performance reports and issue summaries to leadership and stakeholders.
Must be willing to travel within the state to various office locations as needed.
Available for on-call support during critical IAM incidents.
5+ years of experience in IAM, specifically with Azure AD (Microsoft Entra ID), Active Directory, and SSO integrations
Strong knowledge of SSO protocols: SAML, OAuth, OpenID Connect
Deep understanding of Active Directory architecture (forests, domains, trusts, replication)
Proficient in MFA and conditional access configuration
Experience with regulatory compliance frameworks (e.g., PCI, NIST, 201 CMR 17)
Skilled in identity lifecycle operations (provisioning, access reviews, de-provisioning)
Strong troubleshooting and problem-solving skills
Preferred certifications:
Microsoft Certified: Azure Solutions Architect Expert
Certified Information Systems Security Professional (CISSP)
Certified Identity and Access Manager (CIAM)