Unknown Company

IAM/RBAC Engineer

new york, ny • Posted 2 weeks ago
Remote Contract Architecture and Engineering Occupations
IAM/RBAC Engineer

Hybrid 4 days onsite in either Pittsburgh, PA or NYC, NY or Remote

Our client seeks an IAM/RBAC Engineer with deep experience in Microsoft Entra ID and Azure RBAC. The contractor will design, implement, and administer access controls, enforce least-privilege, and support secure, auditable access for privileged and non-privileged users. The role emphasizes scalable identity solutions, strong authenticator management, and consistent access governance and monitoring.

This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.

Rate: $80.00 to $90.00/hr. w2

Responsibilities:
  • Define and maintain an enterprise role taxonomy across Azure resources.
  • Map permissions to roles and enforce least-privilege access via security groups and role assignments.
  • Prohibit broad, direct privilege assignments and document role-to-permission mappings and changes.
  • Implement JIT workflows for elevated access with approvals and time-bound permissions.
  • Establish usage restrictions and configuration norms for VPN, jump hosts, and privileged sessions.
  • Define and oversee emergency access procedures, incident notification, and review.
  • Configure MFA for privileged roles using strong authenticators such as smartcards or security keys.
  • Provision Azure AD administrator roles for services such as SQL where applicable.
  • Enforce managed identities for applications and reduce reliance on local service keys.
  • Ensure authorized users safeguard issued authenticators and follow secret hygiene.
  • Prevent unencrypted, embedded static credentials in code, images, and configurations.
  • Author and maintain policies, standards, and operating procedures for access controls.
  • Conduct periodic access reviews and support audit evidence collection.
  • Maintain inventories of assets and data with baseline configurations per configuration management practices.
  • Configure Azure-native monitoring and logging for identity and access events.
  • Route alerts to service owners and security teams and support audit readiness.
  • Validate use of emergency access through incident workflows and post-event reviews.
Experience Requirements:
  • Advanced knowledge of Microsoft Entra ID, Azure RBAC, security groups, PIM, and JIT access workflows.
  • Hands-on experience with Azure Policy and resource configurations, including managed identities and Azure AD admin role provisioning.
  • Familiarity with Azure monitoring and logging, AAA concepts, and integration with approval workflow tools.
  • Strong understanding of least-privilege access design and access control best practices in Azure.
  • Competence in baseline configuration management and accurate asset and data inventories.
  • Demonstrated experience implementing least-privilege at scale and articulating Azure RBAC rationale.
  • Ability to author and maintain IAM policies and procedures, perform access reviews, and support audits.
  • Proven capability to implement and govern remote and elevated access and emergency access processes.
  • Strong communication and documentation skills for technical writing and stakeholder coordination.
  • Ability to collaborate across engineering, security, and operations teams for compliant access practices.
  • Nice-to-have: Experience integrating identity workflows with approval systems and ticketing processes.
  • Nice-to-have: Exposure to application identity design patterns and CI/CD secret management controls.
  • Nice-to-have: Background in supporting audit readiness for access controls in cloud environments.

IAM/RBAC Engineer in new york at Unknown Company

This position is listed as contract and able to be worked remotely.

Back to Job Search