Hines

Identity & Access Management (IAM) Engineer – Enterprise Technology Infrastructure

Hines • $90K — $130K *
Enterprise Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a relevant field.
  • 5+ years in Identity & Access Management and enterprise IT settings.
  • Expertise in Entra ID (Azure AD) and on-premises Active Directory.
  • Experience with Conditional Access, MFA, SSO, and RBAC implementations.
  • Proficient in PowerShell scripting for automation tasks.
  • Knowledge of Zero Trust and least privilege principles.
  • Hands-on familiarity with Microsoft 365 / Exchange environments.

Responsibilities

  • Administer and optimize Entra ID and Active Directory infrastructures.
  • Design and implement identity solutions for SaaS and enterprise applications.
  • Troubleshoot SSO and authentication issues for internal and third-party platforms.
  • Manage identity lifecycle processes from onboarding to termination.
  • Apply Zero Trust principles to identity and access controls.
  • Support Microsoft 365 environments and troubleshoot email functionality.
  • Leverage AI tools to enhance operational efficiency and security.

Benefits

  • Opportunity to work with cutting-edge AI technology in identity management.
  • Cross-functional collaboration with various teams to enhance systems.
  • Engagement in continuous learning and professional development.
  • Involvement in innovative security and compliance initiatives.
Full Job Description
Overview

Responsibilities

As a Identity & Access Management (IAM) Engineer 6 Enterprise Technology Infrastructure with Hines, you will support, modernize, and continuously improve our enterprise identity and access infrastructure of the firm. This role will focus on Entra ID (Azure AD) and Active Directory, with additional responsibility supporting enterprise messaging platforms including Microsoft 365 (Exchange Online and Hybrid) and secure email gateways.The ideal candidate brings a strong AI-first mindset, proactively leveraging AI tools and automation to enhance operational efficiency, strengthen security posture, and elevate the end-user experience. This role is not just about maintaining identity systems 6its about rethinking how identity and access are managed through intelligent tooling, automation, and continuous optimization. Responsibilities include, but are not limited to:

 

Identity & Access Management

  • Administer and optimize Entra ID (Azure AD) and on-premises Active Directory
  • Design and implement identity solutions including:
  • Configure and manage Single Sign-On (SSO) integrations in Entra ID for SaaS and enterprise applications (SAML, OIDC, OAuth)
  • Administer and maintain Enterprise Applications in Entra ID, including application onboarding, access assignment, and lifecycle management
  • Troubleshoot SSO, federation, and application authentication issues across internal and third-party platforms
  • Partner with application owners to design and implement secure, scalable authentication and authorization models
  • Multi-Factor Authentication (MFA)
  • Conditional Access policies
  • Identity Protection and risk-based access controls
  • Manage and enforce Privileged Identity Management (PIM), including role activation, just-in-time access, and privileged access governance
  • Manage identity lifecycle processes (joiner, mover, leaver)
  • Implement and enforce least privilege access and role-based access control (RBAC)
  • Troubleshoot complex authentication, federation, and directory-related issues
  • Support directory synchronization and hybrid identity configurations

Security & Compliance

  • Apply Zero Trust principles across identity and access controls
  • Monitor, investigate, and respond to identity-related threats and anomalies
  • Support access reviews, certifications, and identity governance initiatives
  • Partner with security and compliance teams on audit readiness, risk mitigation, and policy enforcement

 

Messaging & Email Infrastructure (Supporting Responsibility)

  • Support Microsoft 365 (Exchange Online) environments and core messaging functionality
  • Assist with troubleshooting mail flow issues and email-related incidents
  • Maintain awareness of email security controls and authentication standards (SPF, DKIM, DMARC)

AI-First Operations & Automation

  • Apply an AI-first approach to problem solving, leveraging tools such as Microsoft Copilot and AI-assisted scripting to accelerate analysis and resolution
  • Design and implement automation solutions to reduce manual effort and improve reliability (PowerShell, workflows, orchestration tools)
  • Use AI to enhance troubleshooting, anomaly detection, and root cause analysis
  • Identify and lead opportunities to embed AI across identity, messaging, and security operations
  • Stay current on emerging AI capabilities within Microsoft 365, Azure, and enterprise IT ecosystems and translate them into practical use cases

Documentation, Diagramming & Knowledge Management

  • Create and maintain clear, structured technical documentation for systems, processes, and configurations
  • Develop architecture and process diagrams using tools such as Microsoft Visio (or similar) to illustrate identity flows, access models, and integrations
  • Ensure documentation reflects current-state and future-state designs to support scalability and knowledge transfer
  • Contribute to internal knowledge bases and operational runbooks

Collaboration & Continuous Improvement

  • Work cross-functionally with security, infrastructure, and application teams
  • Proactively identify opportunities for system optimization, automation, and risk reduction
  • Continuously improve identity security posture and user access experience
  • Participate in on-call support rotation as needed

Qualifications

Minimum Requirements include:

 

  • Bachelors degree from an accredited institution
  • Five or more years of experience in Identity & Access Management and enterprise IT environments

  • Strong expertise in:

    • Entra ID (Azure AD)

    • Active Directory (on-premises)

    • Hands-on experience with Conditional Access, MFA, SSO, and RBAC

    • Experience supporting Microsoft 365 / Exchange environments

    • Familiarity with email security solutions (e.g., Cisco IronPort or similar)

    • Strong PowerShell scripting skills for automation

    • Solid understanding of identity security principles (Zero Trust, least privilege)

    • Proven ability to troubleshoot complex identity and access issues

  • Experience with identity governance and access review processes

  • Hands-on experience with Privileged Identity Management (PIM) and privileged access strategies

  • Familiarity with Microsoft security and compliance tools

  • Experience implementing or supporting AI tools in IT operations

  • Hands-on experience with Microsoft Copilot or similar AI platforms

  • Knowledge of email authentication and security best practices

  • Relevant certifications (Microsoft 365, Azure, Security, etc.)

 

About Hines

The Birmingham Small Arms Company Limited was a major British industrial combine, a group of businesses manufacturing military and sporting firearms; bicycles; motorcycles; cars; buses and bodies; steel; iron castings; hand, power, and machine tools; coal cleaning and handling plants; sintered metals; and hard chrome process. After the Second World War, BSA did not manage its business well, and a government-organised rescue operation in 1973 led to a takeover of such operations as it still owned. Those few that survived this process disappeared into the ownership of other businesses. BSA began in June 1861 in the Gun Quarter, Birmingham, England. It was formed by a group of fourteen gunsmith members of the Birmingham Small Arms Trade Association specifically to manufacture guns by machinery. They were encouraged to do this by the War Office which gave the BSA gunsmiths free access to technical drawings and to the War Office's Board of Ordnance's Royal Small Arms Factory factory at Enfield. New machinery developed in the USA installed at Enfield had greatly increased its output without needing more skilled craftsmen. This new machinery brought to Birmingham the principle of the interchangeability of parts.
Learn more about Hines
Industry
Founded
2007

Similar Jobs

More Jobs at Hines

More Enterprise Technology Jobs

Find similar Identity & Access Management (IAM) Engineer – Enterprise Technology Infrastructure jobs: