Senior Identity & Access Management (IAM) Engineer, Workforce Identity

Posted Yesterday
Be an Early Applicant
2 Locations
In-Office
Senior level
Fintech • Software • Financial Services
The Role
Design, automate, and operate workforce identity services across Microsoft Entra ID and Active Directory. Build and maintain federation, SSO, conditional access, MFA, passwordless, PAM/IGA integrations, hybrid sync, and lifecycle automation. Monitor identity health, support incident response, integrate identity telemetry with security tooling, and participate in on-call and cross-training to ensure secure, scalable identity governance.
Summary Generated by Built In

About Acrisure

A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. Bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across a range of insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services – and more. 

In the last twelve years, Acrisure has grown in revenue from $38 million to almost $5 billion and employs over 19,000 colleagues in more than 20 countries. Acrisure was built on entrepreneurial spirit. Prioritizing leadership, accountability, and collaboration, we equip our teams to work at the highest levels possible.

Job Summary:

You will be a hands-on IAM engineer responsible for designing, automating, and operating Acrisure's Workforce Identity Platform across Microsoft Entra ID, Active Directory, cloud platforms, and enterprise applications. You will build paved-road patterns for identity federation, authentication, least privilege, privileged access management, and lifecycle governance while ensuring authentication and authorization boundaries remain secure, measurable, and frictionless. 

As a member of the Workforce Identity team, you will develop deep expertise across both Microsoft Entra ID and Active Directory technologies. Success in this role means turning identity into an enabler by making secure access seamless for users, applications, and services while maintaining the highest standards of governance, security, and compliance.

Responsibilities:

Workforce Identity Platform Engineering 

Design and Operate Workforce Identity Services 

  • Design, implement, and maintain Microsoft Entra ID and Active Directory services supporting the enterprise workforce. 
  • Develop and maintain workforce identity architecture standards, authentication policies, and tenant governance controls. 
  • Manage and secure Entra ID tenant architecture and identity infrastructure. 
  • Implement and support Conditional Access, MFA, phishing-resistant authentication, passwordless authentication, and Identity Protection capabilities. 
  • Establish and maintain tenant security posture standards, administrative tiering strategies, and privileged identity controls. 
  • Design and maintain federation and enterprise SSO integrations using SAML, OIDC, OAuth2, and related identity protocols. 
  • Support Entra B2B collaboration and external workforce access patterns. 
  • Define and maintain enterprise application onboarding standards and identity integration requirements. 

Workforce Identity Operations and Administration 

  • Implement and support SAML/OIDC application integrations across SaaS, cloud, and enterprise platforms. 
  • Manage group administration, dynamic group lifecycle management, and directory governance processes. 
  • Administer Entra Connect, cloud synchronization, and hybrid identity platforms. 
  • Troubleshoot authentication, federation, Conditional Access, synchronization, and access-related issues. 
  • Govern application registrations, service principals, enterprise applications, and API permissions. 
  • Manage guest-user onboarding, lifecycle management, access reviews, and external collaboration controls. 
  • Maintain directory hygiene, tenant monitoring, operational support procedures, and identity health reporting. 
  • Develop automation solutions using PowerShell, Microsoft Graph API, Terraform, and related identity engineering tools. 

Cross-Training and Operational Resiliency 

  • Develop broad expertise across both Entra ID and Active Directory platforms. 
  • Participate in structured cross-training programs to ensure workforce identity services do not depend on a single individual. 
  • Maintain shared runbooks, architecture documentation, standards, and operational procedures. 
  • Participate in on-call support and escalation activities for workforce identity services as required. 

Architect and Automate Identity Foundations 

Work with Identity Architects and Identity Automation Engineering to: 

  • Design and maintain secure-by-default IAM architectures across Entra ID, AWS IAM, and hybrid enterprise systems. 
  • Develop paved-road templates for access control patterns such as federated access, role assumption, service accounts, and workload identities. 
  • Automate provisioning and deprovisioning pipelines using identity APIs, SCIM, and workflow orchestration platforms. 
  • Implement policy-as-code for IAM guardrails including least privilege, Conditional Access, MFA enforcement, and privilege expiration. 
  • Engineer scalable automation to reduce manual identity operations and improve governance consistency. 

Access Control, Federation, and Governance 

  • Engineer federated identity solutions for users, applications, partners, and services using SAML, OIDC, OAuth2, and SCIM. 
  • Manage Conditional Access policies, adaptive authentication, Identity Protection controls, and passwordless authentication strategies. 
  • Define and enforce least privilege for human and non-human identities across AWS, Azure, SaaS, and enterprise platforms. 
  • Integrate IAM governance with enterprise GRC systems to ensure traceability, certification, and audit readiness. 
  • Partner with AppSec and Cloud Engineering teams to secure authentication and authorization boundaries across applications, APIs, and services. 
  • Define standards for enterprise application onboarding, identity integration, and access governance. 
  • Support administrative tiering and privileged access separation strategies across the enterprise. 

Lifecycle and Risk Management 

Work with the appropriate teams to:  

  • Automate joiner, mover, and leaver processes through API-driven workflows and HR system integrations. 
  • Support periodic access reviews, certifications, and entitlement recertification campaigns. 
  • Deliver evidence and support for SOC 2, PCI DSS, ISO 27001, cyber insurance, and regulatory audits. 
  • Develop and maintain dashboards for identity risk indicators, including:  
  • Automated provisioning rates 
  • MFA adoption 
  • Stale and orphaned accounts 
  • Access review completion 
  • Failed recertifications 
  • Access-removal SLA performance 
  • Prioritize remediation using risk-based approaches and ensure compliance with internal SLAs. 

Detection and Response Integration 

  • Collaborate with Security Operations to define identity-centric detections, including impossible travel, lateral movement, privilege abuse, and account compromise. 
  • Correlate identity events with endpoint, cloud, and application telemetry to identify potential threats. 
  • Assist in incident response activities involving identity-based attacks, credential theft, and privileged access abuse. 
  • Support forensic investigations through identity and authentication data analysis. 

Requirements

Required Qualifications

  • 5+ years of experience in Identity and Access Management engineering supporting hybrid and multi-cloud enterprise environments. 
  • Strong experience administering Microsoft Entra ID, Active Directory, and hybrid identity architectures at enterprise scale. 
  • Strong knowledge of AWS IAM, Azure identity services, and authentication technologies including SAML, OIDC, OAuth2, and SCIM. 
  • Strong experience implementing and operating Conditional Access, Identity Protection, MFA, phishing-resistant authentication, and passwordless authentication solutions. 
  • Experience with Entra Connect, cloud synchronization, and hybrid identity operations. 
  • Experience with PowerShell, Microsoft Graph API, Python, Terraform, or other automation technologies. 
  • Experience with PAM platforms such as Delinea, CyberArk, BeyondTrust, or Azure PIM. 
  • Experience with identity governance and administration (IGA) platforms such as SailPoint, Saviynt, or Okta. 
  • Strong understanding of Zero Trust Architecture, least privilege, RBAC, and privileged access design principles. 
  • Proven ability to translate business requirements into secure, scalable, and supportable identity solutions. 
  • Strong troubleshooting skills across authentication, federation, access governance, and directory services. 

Preferred Qualifications

  • Experience supporting large-scale Microsoft Entra ID tenant administration and governance programs. 
  • Familiarity with NIST 800-63, NIST CSF, CIS Controls, and Zero Trust Maturity Models. 
  • Experience integrating IAM, PAM, and IGA telemetry into SIEM platforms. 
  • Experience securing workforce, workload, and machine identities in cloud-native environments. 
  • Relevant certifications such as: CISSP, CISM, Microsoft Certified: Identity and Access Administrator Associate, Microsoft Certified: Azure Security Engineer Associate, AWS Security Specialty, Okta Certified Professional, SailPoint Certified Engineer 

Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.


Why Join Us:

At Acrisure, we’re building more than a business, we’re building a community where people can grow, thrive, and make an impact. Our benefits are designed to support every dimension of your life, from your health and finances to your family and future.

Making a lasting impact on the communities it serves, Acrisure has pledged more than $22 million through its partnerships with Corewell Health Helen DeVos Children's Hospital in Grand Rapids, Michigan, UPMC Children's Hospital in Pittsburgh, Pennsylvania and Blythedale Children's Hospital in Valhalla, New York.


Employee Benefits

We also offer our employees a comprehensive suite of benefits and perks, including:

  • Physical Wellness: Comprehensive medical insurance, dental insurance, and vision insurance; life and disability insurance; fertility benefits; wellness resources; and paid sick time.

  • Mental Wellness: Generous paid time off and holidays; Employee Assistance Program (EAP); and a complimentary Calm app subscription.

  • Financial Wellness: Immediate vesting in a 401(k) plan; Health Savings Account (HSA) and Flexible Spending Account (FSA) options; commuter benefits; and employee discount programs.

  • Family Care: Paid maternity leave and paid paternity leave (including for adoptive parents); legal plan options; and pet insurance coverage.

  • … and so much more!

This list is not exhaustive of all available benefits. Eligibility and waiting periods may apply to certain offerings. Benefits may vary based on subsidiary entity and geographic location.


Acrisure is an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, disability, or protected veteran status. Applicants may request reasonable accommodation by contacting [email protected].

Final candidates will be required to complete post-offer verification processes related to the role and in accordance with applicable laws.


California Residents: Learn more about our privacy practices for applicants by visiting the Acrisure California Applicant Privacy Policy.


Recruitment Fraud: Please visit here to learn more about our Recruitment Fraud Notice.


Welcome, your new opportunity awaits you.

Skills Required

  • 5+ years of experience in Identity and Access Management engineering supporting hybrid and multi-cloud enterprise environments
  • Strong experience administering Microsoft Entra ID and Active Directory at enterprise scale
  • Experience with Entra Connect, cloud synchronization, and hybrid identity operations
  • Strong knowledge of AWS IAM and Azure identity services
  • Strong knowledge of authentication technologies and identity protocols: SAML, OIDC, OAuth2, and SCIM
  • Experience implementing and operating Conditional Access, Identity Protection, MFA, phishing-resistant and passwordless authentication
  • Experience with PowerShell, Microsoft Graph API, Python, Terraform, or similar automation technologies
  • Experience with PAM platforms (e.g., Delinea, CyberArk, BeyondTrust, Azure PIM)
  • Experience with identity governance and administration (IGA) platforms such as SailPoint, Saviynt, or Okta
  • Strong understanding of Zero Trust Architecture, least privilege, RBAC, and privileged access design principles
  • Proven ability to translate business requirements into secure, scalable, and supportable identity solutions
  • Strong troubleshooting skills across authentication, federation, access governance, and directory services
  • Experience supporting large-scale Entra ID tenant administration and governance programs
  • Familiarity with NIST 800-63, NIST CSF, CIS Controls, and Zero Trust Maturity Models
  • Experience integrating IAM, PAM, and IGA telemetry into SIEM platforms
  • Relevant certifications (CISSP, CISM, Microsoft Identity and Azure security certs, AWS Security Specialty, Okta or SailPoint certifications)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Grand Rapids, Michigan
3,983 Employees

What We Do

Acrisure is a global Fintech leader that combines the best of humans and high tech to offer multiple financial products and services to millions of businesses and individual clients. We connect clients to solutions that help them protect and grow what matters, including Insurance, Reinsurance, Cyber Services, Mortgage Origination and more. Acrisure employs over 16,000 entrepreneurial colleagues in 21 countries and has grown from $38 million to $4 billion in revenue in just over ten years. Our culture is defined by our entrepreneurial spirit and all that comes with it: innovation, client centricity and an indomitable will to win. Additionally, Acrisure is committed to making an impact in our communities by giving back, as seen by our partnerships with Helen Devos Children’s Hospital and UPMC Children's Hospital. Discover more at www.Acrisure.com.

Similar Jobs

IDeaS Logo IDeaS

Project Manager

Software • Analytics • Hospitality
Remote or Hybrid
United States
702 Employees

DFIN Logo DFIN

Manager - Sales Operations

Fintech • Software
Remote or Hybrid
United States
1750 Employees

Enverus Logo Enverus

Manager, Power Markets - 26232

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
5 Locations
1800 Employees
115K-130K Annually

MetLife Logo MetLife

Customer Care Advocate - 19686

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
47K-80K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account