Our Client, a Commercial Banking company, is looking for a Senior IAM Engineer for their Atlanta GA / Charlotte NC location.
Responsibilities:
Work with Cyber and Enterprise architectures to on selection (and development as needed) of appropriate IAM patterns, and translate into engineering / implementation designs.
Work with SMEs across other technology teams (End User tech: Desktop, Mobile, Collab, VDI, etc; Network services: VPN) on IAM designs, configuration, pilot testing & implementation)
Work with Project Management team to identify (and size: resource requirements and timelines)technical tasks to implement various program deliverables
Configure Entra ID identity, trust settings, and entitlement management
Implement Conditional Access with phishing-resistant MFA (FIDO2) and risk-based controls
Migrate federated applications and validate authentication flows
Help develop and support processes to procure and manage FIDO2 keys, manage implementation of passkeys, and provide IAM support for Windows Hello for Business rollouts
Enable step-up authentication for sensitive operations
Identify break glass accounts and secure privileged access paths according to Architecture patterns
Validate playbooks, assess lifecycle models, and support deployment expansion"
Requirements:
Identity & Access Management (IAM) Architecture - Ability to design and implement enterprise identity patterns, authentication models, authorization frameworks, and access governance aligned with security and enterprise architecture standards.
Microsoft Entra ID Administration & Engineering - Expertise in configuring Entra ID tenants, identity trust relationships, entitlement management, application integrations, and hybrid identity solutions.
Zero Trust & Conditional Access Design - Experience implementing risk-based access controls, Conditional Access policies, device trust requirements, and adaptive security measures based on Zero Trust principles.
Strong Authentication Technologies (FIDO2, Passkeys, WHfB) - Knowledge of phishing-resistant authentication methods including FIDO2 security keys, passkeys, Windows Hello for Business, and modern credential lifecycle management.
IAM Program Delivery & Cross-Functional Engineering - Capability to collaborate with architecture, endpoint, networking, and project management teams to design, pilot, estimate, and deploy IAM solutions at enterprise scale. Identity Architecture and Microsoft Entra External ID
Identity Governance & Administration (IGA) - Experience with identity lifecycle management, access certifications, SoD analysis, and role-based access control (RBAC) using tools such as SailPoint, Saviynt, Entra ID Governance, or Omada.
Identity Threat Detection & Incident Response - leveraging Microsoft Defender XDR, Entra Identity Protection, Sentinel, or similar solutions to investigate compromised identities, risky sign-ins, and account takeover attacks.
Identity Governance Automation - Experience automating IAM processes through PowerShell, Graph API, Logic Apps, Terraform, or Infrastructure-as-Code methodologies"