About The Position

Acrisure is a global fintech leader that empowers businesses and individuals with solutions for growth. They combine technology and human support to offer customized solutions in insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services, and more. Acrisure has experienced significant growth, from $38 million in revenue to nearly $5 billion, with over 19,000 employees in more than 20 countries. The company values entrepreneurial spirit, leadership, accountability, and collaboration. In this role, you will be a hands-on IAM engineer responsible for designing, automating, and operating Acrisure's Workforce Identity Platform. This includes managing Microsoft Entra ID, Active Directory, cloud platforms, and enterprise applications. You will develop patterns for identity federation, authentication, least privilege, privileged access management, and lifecycle governance, ensuring secure, measurable, and frictionless access. The position requires deep expertise in both Microsoft Entra ID and Active Directory technologies. The goal is to make identity an enabler by providing seamless and secure access for users, applications, and services while maintaining high standards of governance, security, and compliance.

Requirements

  • 5+ years of experience in Identity and Access Management engineering supporting hybrid and multi-cloud enterprise environments.
  • Strong experience administering Microsoft Entra ID, Active Directory, and hybrid identity architectures at enterprise scale.
  • Strong knowledge of AWS IAM, Azure identity services, and authentication technologies including SAML, OIDC, OAuth2, and SCIM.
  • Strong experience implementing and operating Conditional Access, Identity Protection, MFA, phishing-resistant authentication, and passwordless authentication solutions.
  • Experience with Entra Connect, cloud synchronization, and hybrid identity operations.
  • Experience with PowerShell, Microsoft Graph API, Python, Terraform, or other automation technologies.
  • Experience with PAM platforms such as Delinea, CyberArk, BeyondTrust, or Azure PIM.
  • Experience with identity governance and administration (IGA) platforms such as SailPoint, Saviynt, or Okta.
  • Strong understanding of Zero Trust Architecture, least privilege, RBAC, and privileged access design principles.
  • Proven ability to translate business requirements into secure, scalable, and supportable identity solutions.
  • Strong troubleshooting skills across authentication, federation, access governance, and directory services.

Nice To Haves

  • Experience supporting large-scale Microsoft Entra ID tenant administration and governance programs.
  • Familiarity with NIST 800-63, NIST CSF, CIS Controls, and Zero Trust Maturity Models.
  • Experience integrating IAM, PAM, and IGA telemetry into SIEM platforms.
  • Experience securing workforce, workload, and machine identities in cloud-native environments.
  • Relevant certifications such as: CISSP, CISM, Microsoft Certified: Identity and Access Administrator Associate, Microsoft Certified: Azure Security Engineer Associate, AWS Security Specialty, Okta Certified Professional, SailPoint Certified Engineer.

Responsibilities

  • Design and Operate Workforce Identity Services: Design, implement, and maintain Microsoft Entra ID and Active Directory services. Develop and maintain workforce identity architecture standards, authentication policies, and tenant governance controls. Manage and secure Entra ID tenant architecture and identity infrastructure. Implement and support Conditional Access, MFA, phishing-resistant authentication, passwordless authentication, and Identity Protection capabilities. Establish and maintain tenant security posture standards, administrative tiering strategies, and privileged identity controls. Design and maintain federation and enterprise SSO integrations using SAML, OIDC, OAuth2, and related identity protocols. Support Entra B2B collaboration and external workforce access patterns. Define and maintain enterprise application onboarding standards and identity integration requirements.
  • Workforce Identity Operations and Administration: Implement and support SAML/OIDC application integrations. Manage group administration, dynamic group lifecycle management, and directory governance. Administer Entra Connect, cloud synchronization, and hybrid identity platforms. Troubleshoot authentication, federation, Conditional Access, synchronization, and access-related issues. Govern application registrations, service principals, enterprise applications, and API permissions. Manage guest-user onboarding, lifecycle management, access reviews, and external collaboration controls. Maintain directory hygiene, tenant monitoring, operational support procedures, and identity health reporting. Develop automation solutions using PowerShell, Microsoft Graph API, Terraform, and related identity engineering tools.
  • Cross-Training and Operational Resiliency: Develop broad expertise across both Entra ID and Active Directory platforms. Participate in structured cross-training programs. Maintain shared runbooks, architecture documentation, standards, and operational procedures. Participate in on-call support and escalation activities.
  • Architect and Automate Identity Foundations: Design and maintain secure-by-default IAM architectures across Entra ID, AWS IAM, and hybrid enterprise systems. Develop paved-road templates for access control patterns. Automate provisioning and deprovisioning pipelines using identity APIs, SCIM, and workflow orchestration platforms. Implement policy-as-code for IAM guardrails. Engineer scalable automation to reduce manual identity operations and improve governance consistency.
  • Access Control, Federation, and Governance: Engineer federated identity solutions. Manage Conditional Access policies, adaptive authentication, Identity Protection controls, and passwordless authentication strategies. Define and enforce least privilege for human and non-human identities. Integrate IAM governance with enterprise GRC systems. Partner with AppSec and Cloud Engineering teams to secure authentication and authorization boundaries. Define standards for enterprise application onboarding, identity integration, and access governance. Support administrative tiering and privileged access separation strategies.
  • Lifecycle and Risk Management: Automate joiner, mover, and leaver processes. Support periodic access reviews, certifications, and entitlement recertification campaigns. Deliver evidence and support for audits. Develop and maintain dashboards for identity risk indicators. Prioritize remediation using risk-based approaches and ensure compliance with internal SLAs.
  • Detection and Response Integration: Collaborate with Security Operations to define identity-centric detections. Correlate identity events with telemetry to identify potential threats. Assist in incident response activities involving identity-based attacks. Support forensic investigations through identity and authentication data analysis.

Benefits

  • Comprehensive medical insurance
  • Dental insurance
  • Vision insurance
  • Life and disability insurance
  • Fertility benefits
  • Wellness resources
  • Paid sick time
  • Generous paid time off and holidays
  • Employee Assistance Program (EAP)
  • Complimentary Calm app subscription
  • Immediate vesting in a 401(k) plan
  • Health Savings Account (HSA) and Flexible Spending Account (FSA) options
  • Commuter benefits
  • Employee discount programs
  • Paid maternity leave
  • Paid paternity leave (including for adoptive parents)
  • Legal plan options
  • Pet insurance coverage
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service