Workforce IAM Engineer

Posted 1hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Workforce IAM Engineer advancing College Board’s education-focused nonprofit workforce identity security. Building RBAC, Entra ID, Okta, password-management, and hardware-key solutions.

Responsibilities:

  • Build, test, deploy, and maintain persona-based RBAC roles and access policies
  • Develop scalable application logic and automations
  • Build and maintain Microsoft Entra ID and Okta integrations and workflows, including application onboarding and SSO/SCIM configuration
  • Automate role assignment, access provisioning, and reporting with scripts and tooling such as PowerShell
  • Maintain RBAC roles as organizational structures, entitlements, and applications change
  • Write, test, and document code; perform code reviews
  • Administer the enterprise password management platform, including vault structure, policies, provisioning, onboarding/offboarding, and upgrades
  • Support the hardware security key lifecycle, including provisioning, enrollment, replacements, PIN resets, and recovery
  • Coordinate hardware security key shipping and reclamation with Asset Management
  • Monitor platform health, apply updates, and coordinate with vendors
  • Create runbooks, documentation, and knowledge-base articles
  • Review requirements and identify design considerations
  • Analyze authentication, authorization, and access data for troubleshooting, audits, and improvement
  • Troubleshoot application access issues, authentication errors, and integration failures
  • Support end users and partner teams with identity-related requests and RBAC questions
  • Participate in the on-call rotation and respond to identity platform incidents

Requirements:

  • 3+ years of IT engineering experience
  • At least 1 year administering an enterprise password management platform; 1Password preferred, with Keeper and Bitwarden considered
  • Hands-on experience with Active Directory, Microsoft Entra ID, and Okta, including application onboarding and SSO/SCIM configuration
  • Strong understanding of hardware security tokens such as YubiKey, Google Titan, and Feitian
  • Working knowledge of RBAC, SSO, SAML/OIDC, and MFA
  • Scripting experience with PowerShell, Python, or both; ideally including Microsoft Graph API and Entra ID app registrations
  • Working knowledge of ITIL or other change management frameworks, including change requests, incident management, and release processes
  • Experience with cloud platforms; Azure required and AWS strongly preferred
  • Experience with Git, CI/CD, and code review
  • Exposure to PAM platforms such as CyberArk strongly preferred
  • Proactive, self-directed approach and ability to identify improvements
  • Enthusiasm for learning new technologies; enterprise security certifications or coursework such as CISSP, CISA, SC-300, AZ-900, Security+, or AI governance completed or in progress is ideal
  • Practical decision-making and commitment to documentation
  • Authorization to work in the United States for any employer
  • Clear and concise written and verbal communication skills
  • Learner's mindset and commitment to growth
  • Drive for impact and excellence
  • Collaborative and empathetic approach

Benefits:

  • Fully remote or hybrid option for candidates living near College Board offices (Tuesday and Wednesday in office)
  • Meaningful career and supportive team
  • Comprehensive compensation and benefits package
  • Location-adjusted salaries
  • Transparent conversations about compensation and benefits
  • Occasional business travel to meet in person