Role Overview:
We are seeking a detail-oriented and self-driven IAM Automation and Governance Specialist to enhance and automate our identity and access management (IAM) practices. The role will be primarily focused on integrating Microsoft Entra ID (Azure AD) with UKG (HRIS) systems, ensuring secure identity lifecycle management aligned with Zero Trust, least privilege, and regulatory compliance (HITRUST, HIPAA, SOC 2, PCI DSS).
Key Responsibilities:
Identity & Access Management:
• Expert-level experience with Microsoft Entra ID (Azure AD)
• Hands-on with Entitlement Management: Access Packages, Catalogs
• Proficient in Privileged Identity Management (PIM), Access Reviews, Conditional Access
• Automate Joiner-Mover-Leaver (JML) workflows and user lifecycle events
• Identify and remediate orphaned accounts and over-permissioned users
• Strong understanding of RBAC and ABAC access control models.
Scripting & Automation:
• Strong proficiency in PowerShell (Graph API, AzureAD, MSOnline, Az modules)
• Ability to automate:
• IAM data exports (e.g., PIM assignments, access packages)
• Sign-in & activity log queries
• Provisioning/Deprovisioning tasks
• Knowledge of modular and maintainable scripting best practices
Security & Compliance:
• Understanding of frameworks: NIST 800-53, HIPAA, SOC 2, PCI DSS
• Ability to map IAM controls to compliance framework
• Experience supporting audits through evidence gathering and documentation
Azure Cloud & Microsoft Ecosystem:
• Manage Azure subscriptions, resource groups, and RBAC
• Experience with Intune, Defender for Endpoint, and Company Portal
• Troubleshoot Conditional Access and authentication issues
• Familiarity with Microsoft 365 Security & Compliance Center
Documentation & Process Management:
• Develop SOPs, process flows, and policy documents
• Create and maintain IAM maturity models and strategic roadmaps
• Prepare documentation to support regulatory audits
Key Competencies:
• Process Automation: Streamline IAM operations through scripting and workflows
• Security Focus: Deep understanding of IAM security challenges and solutions
• Analytical Thinking: Ability to evaluate and improve access control models
• Cross-functional Collaboration: Bridge gaps between technical and business functions
• Regulatory Awareness: Strong foundation in data protection, access control standards, and compliance regulations
Soft Skills:
• Self-motivated and capable of working independently
• Strong attention to detail with a security-first mindset
• Excellent communication skills for technical and non-technical stakeholders
• Strong collaboration across HR, IT, Security, and DevOps teams
Education & Experience:
• Bachelor’s in computer science, Information Security, or related field
• 8–10 years of experience in IAM or IT Security
• Experience integrating Microsoft Entra ID with HRIS platforms (preferably UKG)
• Background in IAM governance and automation in compliance-heavy environments
Preferred Certifications:
• Microsoft Identity and Access Administrator
• CISSP / CISM (or equivalent)
• Azure Security Engineer Associate
Skills Required
- Bachelor's degree in computer science, information security, or a related field
- 8-10 years of experience in identity and access management or IT security
- Expert-level experience with Microsoft Entra ID or Azure AD
- Experience integrating Microsoft Entra ID with HRIS platforms, preferably UKG
- Experience with IAM governance and automation in compliance-heavy environments
- Strong proficiency in PowerShell, including Graph API, AzureAD, MSOnline, and Az modules
- Hands-on experience with Entitlement Management, Access Packages, and Catalogs
- Experience with Privileged Identity Management, Access Reviews, and Conditional Access
- Understanding of RBAC and ABAC access control models
- Understanding of NIST 800-53, HIPAA, SOC 2, and PCI DSS frameworks
- Experience mapping IAM controls to compliance frameworks and supporting audits
- Experience managing Azure subscriptions, resource groups, and RBAC
- Experience with Intune, Defender for Endpoint, and Company Portal
- Microsoft Identity and Access Administrator certification
- CISSP, CISM, or equivalent certification
- Azure Security Engineer Associate certification
NationsBenefits Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about NationsBenefits and has not been reviewed or approved by NationsBenefits.
-
Fair & Transparent Compensation — Pay is frequently characterized as decent or good for certain entry-level and frontline roles, with timely pay also highlighted. Compensation is sometimes positioned as competitive relative to the work performed in those positions.
-
Leave & Time Off Breadth — Unlimited PTO is described as available for some salaried roles, which can increase perceived flexibility. Paid holidays and paid time off are presented as part of the standard package for eligible employees.
-
Wellbeing & Lifestyle Benefits — A fitness stipend and occasional company-sponsored outings or training-related perks are included among the extra benefits. These additions can modestly strengthen the overall rewards experience beyond core insurance.
NationsBenefits Insights
What We Do
NationsBenefits® is a leading supplemental benefits company providing managed care organizations with innovative healthcare solutions helping to promote independence, health, and well-being for more than 20 million members across the U.S. When the company was founded in 2015 by Glenn Parker, M.D., we set out to disrupt the healthcare industry. In 2020, we rebranded to NationsBenefits to expand the company’s core offering and broaden the scope of our clinically focused services. Today, we surpass traditional benefit management programs by helping our health plan partners drive growth, improve outcomes, reduce costs, and delight members. Our best-in-class service model engages members in meaningful and measurable ways with technology-based solutions tailored to the unique needs of each population.







