CliftonLarsonAllen

Senior IAM Engineer - (Entra ID/AD)

CliftonLarsonAllen$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years of experience managing hybrid identity environments, specifically with Microsoft Entra ID and Active Directory.
  • Proficiency in administering Domain Controllers, Group Policy, and DNS services.
  • Experience implementing Conditional Access, Role-Based Access Control (RBAC), and Privileged Identity Management (PIM).
  • Strong scripting skills in PowerShell for automation and Infrastructure as Code (IaC) development.
  • Familiarity with enterprise application integrations using SAML, OAuth, and OpenID Connect.

Responsibilities

  • Execute the implementation and maintenance of complex IAM infrastructure.
  • Plan and ensure alignment of IAM projects with business requirements and security standards.
  • Automate identity lifecycle processes and optimize access provisioning.
  • Integrate Entra ID with cloud platforms and enterprise systems.
  • Monitor and maintain IAM infrastructure for optimal performance and security.
  • Document and maintain IAM architecture and operating procedures.
  • Provide technical leadership and mentorship to junior team members.

Benefits

  • Comprehensive health, dental, and vision coverage.
  • 401k plan and other financial benefits.
  • Focus on physical, financial, social, and emotional well-being.
  • Opportunities for professional growth and flexible work arrangements.
Full Job Description
CLA is growing and seeking to hire an experienced Identity & Access Management (IAM) Senior Engineer to join our talented Information Technology team. The position offers growth, flexibility and a collaborative work environment.

The Identity & Access Management (IAM) Senior Engineer will be responsible for planning and executing programs both in the cloud and on premises

How you'll create opportunities in this Identity & Access Management (IAM) Senior Engineer position

  • Execute the implementation and maintenance of complex Identity & Access Management (IAM) infrastructure.
  • Plan and execute IAM projects and programs, ensuring alignment with business requirements, security standards, and delivery timelines.
  • Automate and optimize identity lifecycle management processes, access provisioning, and governance controls.
  • Integrate Entra ID with enterprise systems, cloud platforms, and third-party applications.
  • Collaborate with cross-functional teams to support and drive IAM program goals and enterprise security initiatives.
  • Monitor, troubleshoot, and maintain IAM infrastructure, ensuring optimal performance, reliability, and security.
  • Document and maintain comprehensive IAM architecture, workflows, standards, and operating procedures.
  • Implement and enforce IAM security, compliance, governance, and risk management best practices.
  • Provide technical leadership and mentorship to junior team members.
  • Participate in an on-call rotation supporting critical IAM systems and services.

Identity Governance & Access Management:
  • Design and support Role-Based Access Control (RBAC) models and access governance frameworks.
  • Manage Privileged Identity Management (PIM) processes and privileged access controls.
  • Implement and support passwordless authentication, managed identities, and modern identity security practices.
  • Develop and maintain identity lifecycle processes, including onboarding, transfers, and offboarding.
  • Ensure access controls comply with regulatory, audit, and security requirements.
  • Support Identity Governance and Administration (IGA) capabilities and access certification processes.

Identity Architecture & Platform Administration:
  • Administer and support Microsoft Entra ID, Active Directory, and hybrid identity environments.
  • Manage on-premises Active Directory infrastructure, including Domain Controllers, organizational units, and directory services.
  • Design, maintain, and enforce Group Policy Objects (GPOs) to support enterprise security and operational requirements.
  • Design, implement, and maintain identity federation and authentication solutions.
  • Support SAML, OAuth, and OpenID Connect integrations across enterprise applications.
  • Implement and maintain Entra B2B, Entra External Identity, and Conditional Access Policies.
  • Partner with business and technical teams to evaluate identity and access requirements for new systems and applications.
  • Develop scalable and secure identity solutions that support cloud and hybrid environments.

Infrastructure Automation & Engineering:
  • Develop and maintain Infrastructure as Code (IaC) solutions utilizing Terraform and related automation frameworks.
  • Create and support automation solutions using PowerShell, Python, and Bash scripting.
  • Improve operational efficiency through automation and process standardization.
  • Support Active Directory, Group Policy, DNS, Entra ID, and Azure identity services across the enterprise.
  • Continuously evaluate and implement improvements to IAM infrastructure and operational processes.

Technical Competencies:
  • Strong hands-on experience administering Active Directory, Domain Controllers, Group Policy Objects (GPO), and DNS services.
  • Strong hands-on experience with Microsoft Entra ID administration and identity lifecycle management.
  • Advanced PowerShell scripting and automation experience.
  • Experience designing and managing Conditional Access Policies.
  • Experience with Identity Governance and Administration (IGA) platforms and controls.
  • Knowledge of SAML, OAuth, OpenID Connect, and modern authentication protocols.
  • Experience with RBAC, PIM, passwordless authentication, managed identities, and identity governance technologies.
  • Experience with Terraform, Infrastructure as Code (IaC), and automation frameworks.
  • Experience supporting cloud, hybrid, and enterprise IAM environments.
  • Experience with PingOne is preferred.

As our ideal candidate, you have:

Experience:
  • 4+ years of experience required
  • Experience managing hybrid identity environments across Microsoft Entra ID and Active Directory.
  • Experience administering Domain Controllers, Group Policy, DNS, and enterprise authentication services.
  • Experience implementing Conditional Access, RBAC, PIM, and identity governance solutions.
  • Experience developing PowerShell automations and Infrastructure as Code solutions.
  • Experience integrating enterprise applications using SAML, OAuth, and OpenID Connect.


Preferred Qualifications:
  • Experience with PingOne and other enterprise identity platforms.
  • Experience with Entra B2B and Entra External Identity.
  • Experience supporting identity governance, access certification, and compliance programs.
  • Relevant Microsoft, Security, Identity, or Cloud certifications preferred.


Education:
• Bachelor's degree is required. Combination of relevant experience, education, and training may be accepted in lieu of degree.

  • Degrees in Computer Science, Information Technology, or a related field are preferred.


#LI-JH1

Wellness at CLA

To support our CLA family members, we focus on their physical, financial, social, and emotional well-being and offer comprehensive benefit options that include health, dental, vision, 401k and much more.

To view a complete list of benefits, click here.

About CliftonLarsonAllen

CliftonLarsonAllen (CLA) is a professional services firm that provides audit, tax, and advisory services to clients in a variety of industries. The firm was formed in 2012 through the merger of Clifton Gunderson and LarsonAllen, and has since grown to become one of the largest accounting firms in the United States. CLA has over 6,000 employees and serves clients in all 50 states. The firm is committed to providing exceptional service to its clients and helping them achieve their goals.
Learn more about CliftonLarsonAllen
Size
6,000 employees
Industry
Founded
1960

Similar Jobs

More Jobs at CliftonLarsonAllen

More Information Technology Jobs

Find similar Senior IAM Engineer - (Entra ID/AD) jobs: