IAM/RBAC Engineer
Eliassen Group
Hybrid 4 days onsite in either New York, NY or Pitt, PA or Lake Mary, FL
Our client seeks an IAM/RBAC Engineer to design, implement, and administer access controls in Microsoft Entra ID and Azure RBAC. The contractor will enforce least-privilege, govern privileged and remote access, strengthen authenticator management, and maintain audit-ready documentation and monitoring across Azure environments.
This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $82.00 to $92.00/hr. w2
Responsibilities:- Define and maintain an enterprise Azure RBAC role taxonomy and document role-to-permission mappings.
- Map permissions to roles and enforce least-privilege via security groups and scoped role assignments.
- Eliminate broad direct privilege assignments and track changes to access models.
- Implement PIM and JIT workflows for elevated access with approvals and time-bound permissions.
- Establish standards for VPN, jump hosts, and privileged session configurations and restrictions.
- Define and manage emergency access procedures with incident notification and post-event review.
- Configure MFA for privileged roles using strong authenticators such as smartcards or security keys.
- Provision Azure AD administrator roles for applicable services, including SQL.
- Enforce managed identities for applications and reduce reliance on local service keys.
- Prevent unencrypted static credentials in code and enforce secret hygiene standards.
- Author and maintain IAM policies, standards, and operating procedures.
- Conduct periodic access reviews and support audit evidence collection.
- Maintain asset and data inventories and baseline configurations aligned with configuration management.
- Configure Azure-native monitoring and logging for identity and access events.
- Route alerts to service owners and security teams and support audit readiness.
- Advanced knowledge of Microsoft Entra ID, Azure RBAC, security groups, PIM, and JIT access workflows.
- Hands-on experience with Azure Policy, managed identities, and Azure AD admin role provisioning.
- Familiarity with Azure monitoring and logging and AAA concepts.
- Strong understanding of least-privilege design and access control best practices in Azure.
- Competence in baseline configuration management and accurate inventory maintenance.
- Experience implementing least-privilege at scale and articulating Azure RBAC rationale.
- Ability to author IAM policies and procedures, perform access reviews, and support audits.
- Proven capability governing remote and elevated access and emergency access processes.
- Effective communication and documentation skills for technical writing and stakeholder coordination.
- Ability to collaborate with engineering, security, and operations teams for compliant access practices.
- Nice-to-have: Integration with approval systems and ticketing, application identity patterns and CI/CD secret controls, and audit readiness for cloud access controls.
Recruitment Transparency Notice
Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( View email address on careers.eliassen.com , Show phone number) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group’s use of these tools, including AI tools, as part of the application and hiring process.
Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range. W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.
If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:
· When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
· Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group.
If you have any indication of fraudulent activity, please contact View email address on careers.eliassen.com .
About Eliassen Group:
Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients’ capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.
Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws.
Don’t miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
- NYC IT Inc is seeking an experienced IAM Solutions Architect with over 12 years of hands-on experience in designing and maintaining robust IAM solutions. You will work with technologies such as Active Directory, EntraID, and LDAP to deliver complex projects. The ideal candidate...Suggested
- ...Title: IAM Engineer Location: NYC, New York 10004 Duration: 12 month contract Position Overview We're looking for a hands... ...support environments Experience with privileged access, RBAC design, or CIAM platforms udit or compliance exposure (e.g...SuggestedContract workFor contractors
- ...IAM Engineer Location: Brooklyn, NY - 11201 Duration: 1 year Job Description: Part of Infrastructure Resilience Identity and Access... ...complex technical subjects and tasks. A deep understanding of RBAC methodologies, coupled with strong analytical and troubleshooting...Suggested
- ...1 hour mealtime The Identity and Access Management (IAM) team seeks a highly motivated Engineer with the following specifications to lead the ongoing modernization... ...(IAM) tools and processes, Role Based Access Controls (RBAC), Privileged Access Management (PAM) and IGA platforms...SuggestedFull timeWork at officeRemote work
- ...on experience in designing, implementing, and maintaining robust IAM solutions. Demonstrated expertise in working with industry-leading... ...technical subjects and tasks. A deep understanding of RBAC methodologies, coupled with strong analytical and troubleshooting...Suggested
- A leading HR solutions provider in New York is seeking a Senior Identity and Access Management Analyst to enhance their IAM program. The ideal candidate will collaborate with stakeholders to define access control requirements and support IAM roadmaps. Responsibilities include...
- Medium is looking for an IAM Software Engineer based in Pennsylvania. You will design, develop, and support scalable IAM solutions leveraging the Ping Identity Suite. Collaborating with cross-functional teams, you’ll implement authentication mechanisms and automate workflows...
$90 - $100 per hour
Job Title: Identity and Access Management (IAM) Engineer Labor Category: Specialist 3 Location: 2 Metrotech Center, Brooklyn NY, 11201 (2... ...complex technical subjects and tasks. A deep understanding of RBAC methodologies, coupled with strong analytical and troubleshooting...Hourly payContract workRemote workMonday to Friday- ...respectfully. JOB OVERVIEW The Identity and Access Management (IAM) Engineer is tasked to design, implement, and maintain enterprise IAM... ...deprovisioning workflows Maintain role-based access control (RBAC) models Conduct regular access reviews and certifications Enforce...Live inLocal areaRemote work
- Job Title Identity and Access Management (IAM) Engineer Job Details Location: Brooklyn, NY - Hybrid (3 Days onsite/2 Remote) Employment... ...complex technical subjects and tasks. Deep understanding of RBAC methodologies. Strong analytical and troubleshooting skills....Hourly payFull timeLocal areaRemote work
- Identity & Access Management (IAM) EngineerSkip to main content#Identity & Access Management (IAM) Engineer page is loaded## Identity & Access Management (IAM) EngineerApplylocations... ...standards and best practices including RBAC, ABAC, MFA, least privilege, and secure...Local area
$92k - $195k
Vantor is seeking IAM Engineers to support mission requirements for a structured approach to further develop, integrate, and sustain a scalable... ...Architecture (ZTA) principles and role‑based access control (RBAC) policies to protect mission‑critical systems. Integrate IAM...- A technology company based in the United States is seeking an experienced IAM Engineer to design and implement identity and access management systems. The role involves managing authentication processes and ensuring compliance with security policies. Ideal candidates should...Remote job
- ...Hello, I have an opportunity for "Senior IAM Engineer and looking for a candidate who can join Immediately if you are interested reply me with your updated resume or consultant's contact details and if you could refer someone i really appreciate it. Job Title :...Work experience placementImmediate startFlexible hours
- Gilder Search Group is looking for an IAM Engineer to support and maintain identity access management solutions. This role requires 12 years of experience in designing and implementing IAM solutions, particularly with Active Directory and EntraID. The position includes...Remote workFlexible hours
- ...0+ Years of IT Experience ii. 3+ direct years of experience engineering and providing operations support for Okta SSO solutions. iii... ...Active Directory (AD) Experience vi. Intimately familiar with IAM related protocols such as SAML, SPML, XACML, SCIM, OAuth, OIDC,...
- ...Overview: IAM Engineer Experience Required - 6+ Years Must Have Technical/Functional Skills Job Summary: As Identity & Access Management (I&AM) Engineer and Developer will be responsible for design, analysis, evaluation, testing, debugging and implementation...
- ...Required Qualifications Experience : 7+ years of dedicated Identity and Access Management (IAM) engineering experience within an enterprise environment. Platform Mastery : Proven hands-on engineering experience configuring and maintaining Microsoft Entra...
- A leading cloud technology company is looking for a Cloud Security Engineer to enhance the security of its multi-cloud environments. In this role, you will design and implement automated security controls and assist in hardening infrastructure. Candidates should have over...
- ...part of the Identity and Access Management (IAM) organization, focusing on workforce... ...Recertification , Role-Based Access Control (RBAC) , Policy-Based Access Control (PBAC) ,... ...Management (PAM) . As a Software Engineer , you will design, develop, and integrate...Remote workFlexible hours
- A leading technology company is seeking a SailPoint Identity and Access Management (IAM) Engineer for a federal program in the DMV area. The role includes implementing and supporting SailPoint IAM solutions and requires an active DoD clearance along with 4-8 years of extensive...Remote job
- AVEVA Denmark is seeking an IDAM Engineer to join their global IT team in Philadelphia, PA. The role focuses on engineering automated IAM solutions using SailPoint, aiming to reduce manual operations and enhance identity lifecycle processes. The ideal candidate will have...Flexible hours
- Vytwo is looking for a Senior IAM Engineer to support and optimize Identity and Access Management operations. In this fully remote position, you will lead the design and implementation of IAM systems, focusing on security and operational efficiency. The ideal candidate...Remote job
- top-tier hedge fund is seeking a highly skilled Senior IAM Engineer to strategically shape the future of its identity and access management infrastructure. This permanent position , based onsite in New York, NY , offers a high-impact engineering role at the crucial intersection...Permanent employment
$124k - $177k
New York Life is looking for an IAM Solutions Engineer with at least 10 years of experience. This hybrid position involves designing and maintaining IAM solutions across cloud and on-premises environments, utilizing technologies like SailPoint and CyberArk. The ideal candidate...- Innovatus Technology Consulting is looking for an Identity & Access Management (IAM) Engineer to operate remotely in the U.S. The role involves designing and supporting identity solutions, configuring IdP solutions, managing Active Directory and LDAP environments, and developing...Remote job
- GitLab is seeking a Staff Security Engineer with extensive IAM experience to lead the Corporate Security Identity Team. This role involves designing innovative identity access solutions and mentoring other engineers. Candidates must have 8+ years of IAM experience and be...Flexible hours
$120k - $140k
Payfuture Technologies in New York is seeking a Privileged Access Management Engineer to design, implement, and support PAM solutions with a focus on CyberArk. You'll engineer enterprise solutions, manage privileged accounts, and develop automation scripts. The ideal candidate...Remote job$125k - $165k
.... About the Role We're looking for a Senior Site Reliability Engineer who genuinely enjoys the craft. Someone who takes pride in a... ...'ll be hands‑on with our AWS infrastructure, especially EKS, IAM, and RBAC, building things that are secure by default, not as an afterthought...Temporary workRemote work$185k - $227k
...purpose and we are hiring the world’s best engineers, scientists, designers, product managers,... ...using Nutanix Flow and configure RBAC, encryption, and security hardening Lead... ...Organization hierarchies with consolidated billing, IAM policies, and centralized governance...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IAM/RBAC Engineer. Be the first to apply!

