Senior IAM Engineer – Entra ID
Apply now
About the Role
RELEX is looking for a Senior IAM Engineer, specializing in Entra ID, to join our Identity & Access Management (IAM) and Security team. This role owns the design, implementation, and ongoing operation of our Microsoft Entra ID (Azure AD) environment, ensuring secure, scalable, and automated identity solutions across the organization. The ideal candidate combines deep Entra ID and IAM expertise with broader Azure infrastructure knowledge and a DevOps mindset, automating the monitoring, management, and governance of Entra ID resources through Microsoft Graph API, Azure Logic Apps, and Azure Functions.
Technical Role Accountability
- Act as the technical owner and escalation point for the Entra ID environment: architecture decisions, configuration changes, and operational health.
- Accountable for the security, availability, and compliance posture of Entra ID and related Azure identity infrastructure, including sign-off on changes with security or governance impact.
- Drive continuous improvement of identity governance by automating monitoring, alerting, and reporting on Entra ID resources (users, groups, apps, roles, policies) rather than relying on manual reviews.
- Own the audit trail for identity changes: ensure automated logging, alerting, and remediation workflows are in place to catch drift, misconfigurations, or policy violations early.
- Partner with Security and Infrastructure leadership to define governance KPIs (e.g., access review completion, stale account cleanup, privileged role usage) and report on them.
Key Responsibilities
- Design, configure, and maintain Microsoft Entra ID (Azure AD), including conditional access policies, identity governance, PIM, and access reviews.
- Own end-to-end identity and access management processes: user lifecycle management, role-based access control (RBAC), single sign-on (SSO), and multi-factor authentication (MFA).
- Automate the monitoring and management of Entra ID resources (users, groups, app registrations, roles, licenses, policies) for stronger governance, using Microsoft Graph API, Azure Logic Apps, and Azure Functions to detect drift, enforce policy, and trigger remediation.
- Develop and maintain automation for identity operations using Microsoft Graph API, Azure Logic Apps, Azure Functions, and PowerShell/Graph SDK.
- Build event-driven automation (e.g., Event Grid triggers, scheduled/Timer-triggered Functions, Automation Account runbooks) to react to identity events in near real time rather than relying on periodic manual checks.
- Apply security best practices and compliance standards (Zero Trust, least privilege, SOC2/ISO 27001) across the identity landscape.
- Integrate Entra ID with enterprise applications (SAML, OIDC, OAuth2, SCIM provisioning).
- Work across the broader Azure infrastructure stack (subscriptions, resource groups, networking, Key Vault, storage, monitoring/Log Analytics) to ensure identity controls are properly integrated with the underlying cloud environment.
- Build and maintain CI/CD pipelines and infrastructure-as-code for identity configuration changes (DevOps practices applied to IAM).
- Monitor, audit, and respond to identity-related security incidents; support investigations and threat detection.
- Collaborate with Security, Infrastructure, and Application teams to embed identity security into broader IT and DevOps workflows.
- Document architecture, processes, and runbooks, and mentor junior team members on IAM and Entra ID practices.
Required Qualifications
- 7+ years of experience in Identity and Access Management, with strong hands-on expertise in Microsoft Entra ID (Azure AD).
- Proven experience with IAM concepts: RBAC, SSO, MFA, conditional access, privileged identity management (PIM), and identity governance.
- Strong background in IT/cloud security, including familiarity with Zero Trust architecture and common compliance frameworks.
- Practical experience automating monitoring, management, and governance of Entra ID resources using Microsoft Graph API, Azure Logic Apps, and Azure Functions.
- Familiarity with related Azure automation/integration services such as Event Grid, Azure Automation Accounts/runbooks, and Key Vault for secrets used by automation.
- Broad working knowledge of Azure infrastructure in general (subscriptions/management groups, networking, Key Vault, storage, Log Analytics/Monitor, RBAC at the Azure resource level), beyond just the identity layer.
- DevOps experience: CI/CD pipelines, infrastructure-as-code (e.g., Bicep, Terraform, or ARM templates), and version-controlled automation.
- Scripting proficiency in PowerShell and/or the Microsoft Graph SDK.
- Solid understanding of authentication/authorization protocols: SAML, OAuth2, OIDC, SCIM.
- Demonstrated ownership/accountability for a technical domain, comfortable being the go-to escalation point and decision-maker on identity and governance matters.
- Strong troubleshooting, documentation, and cross-team collaboration skills.
Education
- Bachelor’s or Master’s degree in Computer Science, Information Technology, Software/Computer Engineering, or a related engineering discipline (or equivalent practical experience).
Nice to Have
- Microsoft certifications such as SC-300 (Identity and Access Administrator) or SC-100 (Cybersecurity Architect).
- Experience with hybrid identity (Entra Connect/Azure AD Connect) and on-prem Active Directory integration.
- Familiarity with Microsoft Sentinel or other SIEM tools for identity threat detection.
- Experience working in a regulated or enterprise SaaS environment.
What We Offer
- The opportunity to shape and modernize enterprise identity architecture at scale.
- A collaborative, security-focused team culture with strong engineering practices.
- Ownership of automation and DevOps initiatives within the IAM domain.



