IAM Engineer

American Heart Association•Dallas, TX
•$105,000 - $115,000•Hybrid

About The Position

We are seeking a skilled and motivated IAM Engineer to join our Business Technology team. In this role, you will be responsible for engineering, operating, and continuously improving enterprise identity and access management services across cloud and on-premises environments. You will support identity lifecycle management, authentication, authorization, access governance, directory services, federation, and privileged access capabilities. The ideal candidate is a detail-oriented engineer with hands-on experience in Microsoft Entra ID, Active Directory, identity governance, automation, and modern authentication. You will collaborate with Cybersecurity, Human Resources, application owners, infrastructure teams, and business stakeholders to deliver secure, reliable, and user-friendly identity solutions aligned with organizational policy, audit requirements, and business objectives.

Requirements

  • Bachelor’s degree or equivalent experience
  • 3 years of relevant experience
  • 3+ years of experience in identity and access management, directory services, cybersecurity engineering, or a related technical role
  • Hands-on experience with Microsoft Entra ID and Active Directory in enterprise environments
  • Experience with identity lifecycle management, automated provisioning and deprovisioning, access governance, and role-based access control
  • Knowledge of modern authentication and federation standards, including SAML, OAuth 2.0, OpenID Connect, and SCIM
  • Experience configuring multifactor authentication, Conditional Access, single sign-on, and privileged access controls
  • Experience with PowerShell, Microsoft Graph, REST APIs, or comparable scripting and integration technologies
  • Understanding of least privilege, zero trust, separation of duties, and identity-related security controls

Nice To Haves

  • Experience integrating IAM platforms with human resources systems and enterprise applications
  • Experience with Microsoft Entra ID Governance, Privileged Identity Management, entitlement management, and access reviews
  • Knowledge of privileged access management platforms and service account governance
  • Experience with identity monitoring, logging, reporting, and security incident investigation
  • Familiarity with IT service management, change control, audit evidence, and compliance frameworks
  • Identity and security certifications such as: Microsoft Certified: Identity and Access Administrator Associate (SC-300), Microsoft Certified: Cybersecurity Architect Expert (SC-100), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Identity platform or privileged access management certifications relevant to the enterprise environment

Responsibilities

  • Design, implement, and maintain identity lifecycle processes for employees, contractors, partners, and service identities
  • Engineer automated joiner, mover, and leaver workflows using authoritative identity sources and policy-based provisioning
  • Configure and support Microsoft Entra ID, Active Directory, hybrid identity synchronization, and directory-integrated applications
  • Develop and maintain role-based access control, group-based access, entitlement structures, and access packages
  • Create automation using PowerShell, Microsoft Graph, APIs, and workflow tools to improve accuracy, consistency, and speed
  • Implement and support single sign-on, multifactor authentication, passwordless authentication, Conditional Access, and risk-based access controls
  • Configure and troubleshoot SAML, OAuth 2.0, OpenID Connect, SCIM, and related identity protocols
  • Integrate enterprise applications with identity providers and establish secure authentication and provisioning patterns
  • Support privileged identity and access management controls, including just-in-time access and administrative role governance
  • Implement access reviews, separation-of-duties controls, certification campaigns, and governance reporting
  • Partner with Cybersecurity, Internal Audit, Legal, and application owners to address identity risks and control requirements
  • Monitor identity-related events, investigate anomalous access, and support security incident response activities
  • Maintain evidence, documentation, and control records that support audits and compliance assessments
  • Monitor IAM service health, provisioning performance, synchronization, authentication, and integration failures
  • Troubleshoot complex access issues and perform root-cause analysis across directories, applications, and identity platforms
  • Participate in incident response, change management, problem management, and an on-call rotation as required
  • Maintain technical designs, operational procedures, support documentation, and troubleshooting guides
  • Evaluate emerging identity capabilities and recommend improvements that strengthen security and user experience

Benefits

  • medical
  • dental
  • vision
  • disability
  • life insurance
  • retirement program that includes an employer match and automatic contribution
  • employee assistance program
  • employee wellness program
  • telemedicine, and medical consultation
  • Paid Time Off (PTO) at a minimum of 16 days per year for new employees
  • 12 paid holidays off each year
  • Tuition Assistance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service