Job Title: Identity and Access Management (IAM) Engineer
Location: Braintree, MA (Hybrid – 3 days onsite per week)
Duration: 9 Months
Position Overview:
We are seeking a highly skilled IAM Engineer to support the implementation and management of secure identity and access solutions. This role will focus on Microsoft Entra ID (Azure AD), Active Directory, and Single Sign-On (SSO) technologies to enable secure, efficient access to digital resources across various platforms. The ideal candidate brings hands-on experience in identity lifecycle management, security compliance, and IAM infrastructure optimization.
IAM Implementation & Administration
Design, configure, and maintain IAM infrastructure using Entra ID (Azure AD), Active Directory, and SSO
Align IAM policies with business needs and security best practices
Directory Services Management
Administer and support AD forests, domains, trusts, and replication
Manage Microsoft Entra ID features including MFA, conditional access, and identity protection
Ensure high availability and security of directory services
SSO Integration
Implement and maintain SSO solutions using SAML, OAuth, and OpenID Connect
Integrate SSO with cloud and on-prem applications for seamless authentication
Security & Compliance
Enforce RBAC, access controls, and identity governance
Ensure compliance with standards such as PCI, NIST, and 201 CMR 17
Conduct security assessments and audits
Identity Lifecycle Management
Oversee user provisioning, de-provisioning, and access reviews
Automate IAM processes for efficiency and scalability
Technical Support & Collaboration
Troubleshoot IAM-related issues (e.g., SSO failures, directory integration)
Collaborate with IT, cybersecurity, and application teams
Provide technical guidance on IAM best practices
Documentation & Reporting
Maintain up-to-date documentation for IAM systems and procedures
Report on IAM metrics and issues to stakeholders
Must be able to travel to statewide offices as required
Ability to provide on-call support during critical IAM events
5+ years of IAM experience, especially with Entra ID (Azure AD), Active Directory, and SSO
Strong knowledge of SAML, OAuth, OpenID Connect
Familiar with AD architecture: forests, domains, trusts, replication
Experience with MFA, conditional access, and identity protection
Knowledge of PCI, NIST, and 201 CMR 17 compliance
Skilled in identity lifecycle management
Relevant certifications a plus (e.g., Microsoft Azure Architect, CISSP, CIAM)