Enterprise IAM Operations Engineer with Entra ID, RBAC, and Application Integration
LocationNorth America, New York City, NY
Typecontract
DepartmentSecurity (Cyber only)
Company size1,001–5,000 people
First seen1w ago
Last seen2d ago
About the company
Join New Era Technology, where People First is at the heart of everything we do. With a global team of over 3,000 professionals, we’re committed to creating a workplace where everyone feels valued, empowered, and inspired to grow. Our mission is to securely connect people, places, and information with end-to-end technology solutions at scale.
At New Era, you’ll join a team-oriented culture that prioritizes your personal and professional development. Work alongside industry-certified experts, access continuous training, and enjoy competitive benefits. Guided by our core attributes — putting people first, embracing continuous learning, and thriving through collaboration and inclusion — we nurture our people to deliver exceptional customer service.
If you want to make an impact in a supportive, growth-oriented environment, New Era is the place for you. Apply today and help us shape the future of work—together
Job Summary
About the role
New Era Technology is seeking an experienced Senior IAM Engineer to support enterprise Identity and Access Management operations, cloud access governance, RBAC modernization, privileged access, application identity integrations, and identity security initiatives within a mature hybrid and multi-cloud environment.
The ideal candidate will have strong hands-on experience with Microsoft Entra ID/Azure AD, Azure RBAC, Privileged Identity Management (PIM), application federation/SSO, least-privilege access, IAM operations, automation, Splunk-based identity monitoring, and Identity Threat Detection and Response (ITDR).
Key Responsibilities
•
Design, maintain, and optimize Azure RBAC across subscriptions, management groups, resource groups, and Azure services.
•
Define enterprise role taxonomy and implement governed access using groups, roles, and approved assignments.
•
Administer Microsoft Entra ID/Azure AD, on-premises Active Directory, hybrid identity, and workforce, partner, guest, service, and application identities.
•
Implement Microsoft Entra PIM, Just-in-Time (JIT) privileged access, MFA, Conditional Access, break-glass procedures, privileged access monitoring, and audit evidence.
•
Design, implement, and troubleshoot SAML, OIDC, OAuth, Entra SSO, enterprise applications, app registrations, service principals, claims, groups, and application roles.
•
Promote managed identities, govern service principals, support credential rotation, and improve CI/CD secret management.
•
Support the Saviynt-to-SailPoint transition, including identity, entitlement, role, certification, policy, procedure, and control documentation.
•
Support IAM monitoring, logging, alerting, investigation, and ITDR use cases using Azure-native tools and Splunk.
•
Support AWS IAM, GCP IAM, and multi-cloud identity governance where required.
•
Support FedRAMP-relevant access controls, configuration baselines, change control, audit readiness, and privileged access governance.
•
Develop automation and scripting to improve IAM workflows, reporting, documentation, access reviews, runbooks, and operational efficiency.
•
Identify opportunities to responsibly use AI tools for IAM analysis, reporting, documentation, and workflow optimization.
•
Collaborate with Information Security, infrastructure, cloud, application, DevOps, audit, and other technical stakeholders.
Required Technical Skills
•
Strong hands-on experience with Microsoft Entra ID/Azure AD administration.
•
Strong knowledge of Azure RBAC, security groups, role assignments, management groups, subscriptions, and resource-level access.
•
Experience with Microsoft Entra PIM, JIT privileged access, MFA, Conditional Access, and privileged authentication.
•
Strong understanding of Active Directory and hybrid identity.
•
Enterprise experience with SAML, OIDC, OAuth, SSO, Entra Enterprise Applications, app registrations, managed identities, service principals, claims, and application roles.
•
Experience with least-privilege access design, access reviews, access certification, identity/entitlement inventory, credential management, and secret hygiene.
•
Experience with Azure monitoring/logging and Splunk or comparable SIEM platforms.
•
Understanding of Identity Threat Detection and Response (ITDR).
•
Experience with IAM automation/scripting and CI/CD identity controls.
•
Strong IAM documentation skills, including policies, standards, procedures, runbooks, and audit evidence.
Regular use of a computer, keyboard, mouse, and standard office equipment.
•
Ability to work for extended periods using computer screens and participate in remote meetings.
•
Ability to communicate effectively through phone and video conferencing.
#L1-RB1
Legal
New Era Technology, LLC., and its subsidiaries (“New Era” “we”, “us”, or “our”) in its operating regions worldwide are committed to respecting your privacy and recognize the need for appropriate protection and management of any Personal Data that you may provide us. In this, we are also committed to providing you with a positive experience on our websites and while using our products, services and solutions (“Solutions”).
View our Privacy Policy here https://www.neweratech.com/us/privacy-policy/
We never ask candidates to pay any fees at any point in our hiring process. If you are ever asked to provide payment for training, certification, equipment, or any other purpose, it is not from our company. Only communications from our official company channels should be trusted. Please note our official email domain is @neweratech.com. If you suspect fraudulent activity, please contact us immediately at [email protected] .