Identity & Access Management Specialist
Listed on 2026-07-06
-
IT/Tech
Cybersecurity
Overview
The Identity Management Specialist is responsible for designing, implementing, and operating the firm’s identity and access management (IAM) program across on-premises and cloud environments — with a strong emphasis on Microsoft Entra hybrid identity architectures. This role administers the full identity lifecycle — joiner, mover, leaver (JML) - enforces least-privilege access, automates provisioning and governance, and ensures that every user, service account, and privileged identity is provisioned, reviewed, and deprovisioned in a controlled, auditable manner across both on-premises Active Directory and the Entra .
Responsibilities- Identity Lifecycle Management
- Operate and enhance the JML (Joiner / Mover / Leaver) process across Active Directory, Entra , Exchange, M365, and downstream business applications.
- Automate provisioning, role changes, and deprovisioning through identity management solutions (One Identity Manager, Service Now, Manage Engine ADManager Plus, Cayosoft Administrator or others).
- Manage Active Directory and Entra (users, groups, OUs, contacts, mail-enabled objects) at scale using identity management solutions.
- Hybrid Identity & Directory Operations
- Design, operate, and troubleshoot hybrid identity across on-premises Active Directory and Microsoft Entra — including Entra Connect / Connect Sync / Cloud Sync, password hash sync (PHS), pass-through authentication (PTA), federation (AD FS), and seamless SSO.
- Administer multi-domain / multi-forest Active Directory, Entra , and B2B/B2C scenarios.
- Manage Conditional Access, Entra , Privileged Identity Management (PIM), Access Reviews, and Entra .
- Maintain hybrid object flow, attribute mapping, filtering, and writeback (group, device, password writeback).
- Access Governance & Reviews
- Design and execute periodic access certification campaigns (One Identity Manager / Service Now Access Reviews / Entra s Reviews) for high-risk applications, shared mailboxes, distribution lists, and privileged groups.
- Maintain role-based access control (RBAC) models, entitlement catalogs, and segregation of duties (SoD) policies.
- Investigate and remediate orphaned accounts, stale entitlements, and policy violations.
- Service Request & Workflow Automation
- Own the IAM request catalog in Service Now — new accounts, group membership changes, application access, privileged access, and terminations.
- Build and maintain Service Now workflows, Integration Hub / Flow Designer flows, and approval routings that connect HRIS, ITSM, and identity systems.
- Implement self-service password reset, MFA enrollment, and account unlock through Entra .
- Privileged Account Operations
- Administer privileged and service accounts across AD and Entra ; integrate with PAM solutions where applicable.
- Use privilege accounts password management solution for delegated administration, change auditing, AD recovery, and Entra t management.
- Monitoring, Compliance & Reporting
- Monitor identity-related alerts, sign-in risk events, and Conditional Access policy enforcement.
- Produce metrics and reports for audit, risk, and leadership — provisioning SLAs, access review completion, dormant accounts, privileged access usage.
- Support compliance evidence collection for SOC 2, ISO 27001, NYDFS Part 500, GDPR, and client security questionnaires.
- Collaboration & Documentation
- Partner with HR, Security, Infrastructure, and Application owners on onboarding/offboarding and role design.
- Maintain runbooks, SOPs, integration designs, and architecture diagrams for the IAM platform.
- Provide L3 support and mentor L1/L2 service desk staff on identity issues.
- Compensation
The anticipated base salary range offered for this role will be between $140,000 to $160,000 and represents the firm’s good faith and reasonable estimate of the range of possible base compensation. Actual base compensation will be dependent upon several factors, including but not limited to the candidate’s relevant experience, performance, qualifications, degrees, and location, as well as the needs of the firm.
- Bachelor’s degree in Computer Science, Information Systems, or related field (equivalent experience accepted).
- 5+ years of hands-on Identity…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).