Full-Time Identity and Access Management Engineer
Kellermeyer Bergensons Services is hiring a remote Full-Time Identity and Access Management Engineer. The career level for this job opening is Experienced and is accepting USA based applicants remotely. Read complete job description before applying.
Kellermeyer Bergensons Services
Job Title
Posted
Career Level
Career Level
Locations Accepted
Salary
Share
Job Details
About KBSKellermeyer Bergensons Services (KBS) is the largest privately held provider of facility services in North America, servicing over 2 billion square feet of space daily. We help industry leaders across a wide range of key verticals—including retail, industrial and logistics, healthcare, education, manufacturing, and more—maintain clean, efficient and welcoming spaces that support their operations.
Identity and Access Management (IAM) Engineer Job Description
KBS is seeking a skilled and security-minded Identity & Access Management (IAM) Engineer to join our Cybersecurity team. This role plays a critical part in enabling secure, reliable access across both our on-premises and cloud environments, focusing on modern identity governance, authentication protocols, and Zero Trust access controls.
LOCATION: 100% remote, but candidates must live in the Pacific or Central time zone
SALARY: $115-125K
The salary range for this position is based on market data and is intended to provide a general guideline for the position. Actual compensation may vary depending on factors such as experience, qualifications, skills, internal equity, and geographic location. The final offer will be determined through a comprehensive evaluation during the hiring process.
Key Responsibilities
- Design, implement, and manage identity solutions across Microsoft Entra ID / Azure AD, Active Directory, AWS IAM, and OneLogin, supporting hybrid and cloud-first architectures.
- Integrate cloud and on-prem applications using SCIM, SAML, OIDC, OAuth2, and FIDO2/WebAuthn.
- Manage and automate identity lifecycle processes (Joiner, Mover, Leaver), including both HR-driven and technical workflows, using tools like Python, PowerShell, Microsoft Graph API for provisioning, deprovisioning, and policy enforcement.
- Enforce and fine-tune Conditional Access policies, including MFA, device trust, RBAC, and risk-based access controls using Microsoft Entra ID.
- Lead troubleshooting and root-cause analysis for IAM-related issues across cloud and on-prem environments; collaborate closely with infrastructure and application teams.
- Conduct periodic access reviews, audit reporting, and identity governance activities to support compliance with SOC2, NIST CSF, and internal policies.
- Partner with stakeholders to capture IAM use cases, define process requirements, and manage cross-functional IAM project dependencies.
- Maintain accurate documentation of IAM processes, policies, and automation workflows.
- Stay current with evolving IAM technologies, threat trends, and best practices to improve security posture and support a Zero Trust strategy.
Required Skills & Qualifications
- 5+ years of hands-on experience with:
- Microsoft Entra ID / Azure AD
- AWS IAM and Identity Center
- OneLogin or similar IAM platforms
- Strong knowledge of IAM standards: SCIM, SAML, OIDC, OAuth2, FIDO2/WebAuthn
- Scripting/automation skills (e.g., Python, PowerShell, Graph API, Terraform)
- Experience with Zero Trust principles and identity-based security enforcement
- Clear documentation and communication skills
- Strong Analytical and problem-solving abilities
- Ethical judgment and critical thinking
- Excellent interpersonal and customer service skills
- Proven time management and ability to meet deadlines
Education and Experience
- Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience)