Identity and Access Management (IAM) Engineer

Ai Talent Au — Australia · Posted ~21 hours ago

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Description

We are partnering with an enterprise client to strengthen identity governance, automate lifecycle management, and deliver Zero Trust security initiatives. We are seeking an experienced Identity and Access Management (IAM) Engineer to represent our organisation and take technical ownership of designing, implementing, and supporting enterprise identity platforms. In this role, you will bridge cyber security policy and hands-on systems integration within our client’s environment. You will be instrumental in deploying identity governance, single sign-on (SSO), multi-factor authentication (MFA), and privileged access management (PAM) solutions across hybrid-cloud ecosystems. 🌏 Visa & Sponsorship OptionsAs the employer of record, we provide full visa and migration support for qualified engineering talent deployed to our clients: 482 On-Hire Sponsorship Transfers: Fully supported for qualified candidates currently in Australia on an existing 482 visa looking to transfer sponsorship to work with our clients.New 482 Visa Sponsorship: Available for qualified candidates meeting the technical skill and commercial experience requirements.Temporary & Working Visa Holders: Open to all working visa holders seeking a direct pathway to employer sponsorship.Core ResponsibilitiesIAM Platform Administration: Configure, maintain, and enhance enterprise IAM and Identity Governance (IGA) platforms (e.g., Okta, PingIdentity, SailPoint, Microsoft Entra ID).Identity Lifecycle Management: Design and automate Joiner, Mover, Leaver (JML) workflows, SCIM provisioning, and role-based access control (RBAC/ABAC) policies.SSO & Federation Integrations: Implement and troubleshoot federated identity integrations using industry protocols including SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC).Access Governance & Privileged Access: Support User Access Reviews (UAR), credential vaulting, and PAM tooling (e.g., CyberArk, BeyondTrust) to enforce least-privilege principles.Directory & Cloud Sync: Manage hybrid identity sync between on-prem Active Directory, Azure AD/Entra ID, and cloud infrastructure.Client Engagement & Collaboration: Partner with client application owners, security operations, and audit teams to align identity architectures with regulatory and compliance standards.Selection CriteriaIAM Platform Mastery: Hands-on commercial experience administering and engineering enterprise identity platforms (Okta, PingIdentity, or SailPoint).Federation Protocols: Deep technical understanding of authentication and authorization standards (SAML, OAuth2, OIDC, SCIM, Kerberos).Directory Services: Strong background managing Microsoft Entra ID (Azure AD) and on-premises Active Directory.Automation & Scripting: Practical scripting experience using PowerShell or Python to automate identity workflows and API integrations.Location Requirements: Currently residing in Australia with valid work rights or eligibility for 482 visa sponsorship/transfer.Preferred Qualifications (Nice to Have)Experience with Privileged Access Management (PAM) platforms (CyberArk, BeyondTrust).Familiarity with compliance standards (ISO 27001, SOC 2, Essential Eight).Relevant certifications (e.g., Okta Certified Administrator/Consultant, SailPoint Certified IdentityIQ/ISC Engineer, Microsoft SC-300).