New Era Technology
Enterprise IAM Operations Engineer with Entra ID, RBAC, and Application Integration
New York City, NY · Senior · Contract
Stay score
odds of building a lasting career here
Thin sponsorship signal and lottery-bound. A low-probability bet with your clock running. Prioritize cap-exempt roles and proven entry-level sponsors first.
Lottery odds assume a STEM candidate.
Personalize to your clock →Employer immigration record
from this employer's Department of Labor filings
Green-card filing pattern in this occupation
Third-party placement is common here
Sourced from Department of Labor LCA, PERM and prevailing-wage disclosure data. Employer matching is by name, so figures may be split across an employer's legal entities. Absence of a filing means none appears in our copy of the data, not that none exists.
Community outcomes
No reports yet — be the first to help the next applicant.
About the role
- New Era Technology is seeking an experienced Senior IAM Engineer to support enterprise Identity and Access Management operations, cloud access governance, RBAC modernization, privileged access, application identity integrations, and identity security initiatives within a mature hybrid and multi-cloud environment.
- The ideal candidate will have strong hands-on experience with Microsoft Entra ID/Azure AD, Azure RBAC, Privileged Identity Management (PIM), application federation/SSO, least-privilege access, IAM operations, automation, Splunk-based identity monitoring, and Identity Threat Detection and Response (ITDR).
Responsibilities
- Design, maintain, and optimize Azure RBAC across subscriptions, management groups, resource groups, and Azure services.
- Define enterprise role taxonomy and implement governed access using groups, roles, and approved assignments.
- Implement Microsoft Entra PIM, Just-in-Time (JIT) privileged access, MFA, Conditional Access, break-glass procedures, privileged access monitoring, and audit evidence.
- Design, implement, and troubleshoot SAML, OIDC, OAuth, Entra SSO, enterprise applications, app registrations, service principals, claims, groups, and application roles.
- Promote managed identities, govern service principals, support credential rotation, and improve CI/CD secret management.
- Support the Saviynt-to-SailPoint transition, including identity, entitlement, role, certification, policy, procedure, and control documentation.
- Support IAM monitoring, logging, alerting, investigation, and ITDR use cases using Azure-native tools and Splunk.
- Support FedRAMP-relevant access controls, configuration baselines, change control, audit readiness, and privileged access governance.
- Develop automation and scripting to improve IAM workflows, reporting, documentation, access reviews, runbooks, and operational efficiency.
- Collaborate with Information Security, infrastructure, cloud, application, DevOps, audit, and other technical stakeholders.
Requirements
- Hands-on enterprise application federation and SSO experience required.
- Bachelor's degree in Information Security, Computer Science, Information Technology, or equivalent practical experience.
- Strong understanding and practical implementation of RBAC and least-privilege access at enterprise scale.
- Ability to work effectively across IAM, Security, Cloud, Infrastructure, Applications, DevOps, and Audit teams.
- Ability to work within disciplined change control, audit, compliance, and operational stability environments.
- Ability to balance security requirements with technical and business needs.
- Required Technical Skills
Nice to have
- Support AWS IAM, GCP IAM, and multi-cloud identity governance where required.
- Identify opportunities to responsibly use AI tools for IAM analysis, reporting, documentation, and workflow optimization.
- Strong hands-on experience with Microsoft Entra ID/Azure AD administration.
- Strong knowledge of Azure RBAC, security groups, role assignments, management groups, subscriptions, and resource-level access.
- Experience with Microsoft Entra PIM, JIT privileged access, MFA, Conditional Access, and privileged authentication.
- Enterprise experience with SAML, OIDC, OAuth, SSO, Entra Enterprise Applications, app registrations, managed identities, service principals, claims, and application roles.
- Experience with least-privilege access design, access reviews, access certification, identity/entitlement inventory, credential management, and secret hygiene.
- Experience with Azure monitoring/logging and Splunk or comparable SIEM platforms.
Company info
- Join New Era Technology, where People First is at the heart of everything we do.
- With a global team of over 3,000 professionals, we're committed to creating a workplace where everyone feels valued, empowered, and inspired to grow.
- Our mission is to securely connect people, places, and information with end-to-end technology solutions at scale.
- In this, we are also committed to providing you with a positive experience on our websites and while using our products, services and solutions ("Solutions").
- If you are ever asked to provide payment for training, certification, equipment, or any other purpose, it is not from our company.
- Only communications from our official company channels should be trusted.
This listing is sourced directly from New Era Technology's careers page and normalized into a canonical job model.