Workforce IAM Engineer
Posted 1hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Workforce IAM Engineer advancing College Board’s education-focused nonprofit workforce identity security. Building RBAC, Entra ID, Okta, password-management, and hardware-key solutions.
Responsibilities:
- Build, test, deploy, and maintain persona-based RBAC roles and access policies
- Develop scalable application logic and automations
- Build and maintain Microsoft Entra ID and Okta integrations and workflows, including application onboarding and SSO/SCIM configuration
- Automate role assignment, access provisioning, and reporting with scripts and tooling such as PowerShell
- Maintain RBAC roles as organizational structures, entitlements, and applications change
- Write, test, and document code; perform code reviews
- Administer the enterprise password management platform, including vault structure, policies, provisioning, onboarding/offboarding, and upgrades
- Support the hardware security key lifecycle, including provisioning, enrollment, replacements, PIN resets, and recovery
- Coordinate hardware security key shipping and reclamation with Asset Management
- Monitor platform health, apply updates, and coordinate with vendors
- Create runbooks, documentation, and knowledge-base articles
- Review requirements and identify design considerations
- Analyze authentication, authorization, and access data for troubleshooting, audits, and improvement
- Troubleshoot application access issues, authentication errors, and integration failures
- Support end users and partner teams with identity-related requests and RBAC questions
- Participate in the on-call rotation and respond to identity platform incidents
Requirements:
- 3+ years of IT engineering experience
- At least 1 year administering an enterprise password management platform; 1Password preferred, with Keeper and Bitwarden considered
- Hands-on experience with Active Directory, Microsoft Entra ID, and Okta, including application onboarding and SSO/SCIM configuration
- Strong understanding of hardware security tokens such as YubiKey, Google Titan, and Feitian
- Working knowledge of RBAC, SSO, SAML/OIDC, and MFA
- Scripting experience with PowerShell, Python, or both; ideally including Microsoft Graph API and Entra ID app registrations
- Working knowledge of ITIL or other change management frameworks, including change requests, incident management, and release processes
- Experience with cloud platforms; Azure required and AWS strongly preferred
- Experience with Git, CI/CD, and code review
- Exposure to PAM platforms such as CyberArk strongly preferred
- Proactive, self-directed approach and ability to identify improvements
- Enthusiasm for learning new technologies; enterprise security certifications or coursework such as CISSP, CISA, SC-300, AZ-900, Security+, or AI governance completed or in progress is ideal
- Practical decision-making and commitment to documentation
- Authorization to work in the United States for any employer
- Clear and concise written and verbal communication skills
- Learner's mindset and commitment to growth
- Drive for impact and excellence
- Collaborative and empathetic approach
Benefits:
- Fully remote or hybrid option for candidates living near College Board offices (Tuesday and Wednesday in office)
- Meaningful career and supportive team
- Comprehensive compensation and benefits package
- Location-adjusted salaries
- Transparent conversations about compensation and benefits
- Occasional business travel to meet in person



















