IAM Engineer
About this role
Kokosing (www.kokosing.biz) is one of America's 50 largest General Contractors and services a broad spectrum of clients in both the private and public business sectors. Kokosing's services include heavy civil/industrial construction such as highways, bridges, underground utilities, water/wastewater facilities, and marine construction. For over 75 years, Kokosing has successfully attracted the most qualified technical personnel in the construction industry by offering visible challenges, superior quality, and attractive rewards. With over $2.8 billion in annual sales and a commitment to its workforce, Kokosing is the winning team.
Job Description:
We are seeking an Identity and Access Management (IAM) Engineer to help modernize and evolve our identity platform into a strategic trust, governance, and authorization architecture supporting employees, applications, machine identities, cloud services, data platforms, and emerging AI technologies.
This role will contribute to the design, implementation, and continuous improvement of identity governance, privileged access management, Zero Trust initiatives, modern authorization models, and data-centric access controls across hybrid enterprise environments.
The ideal candidate combines strong technical expertise with a governance-first mindset and understands that identity is more than account management. Identity serves as the foundation for securing enterprise resources, governing access to critical data, enabling automation, and supporting trusted human and non-human interactions across the organization.
This position plays a key role in the organization's transition from traditional identity administration toward a modern identity security and governance model capable of supporting future business, cloud, and AI-driven initiatives.
Key Responsibilities
Identity Architecture & Modernization
- Participate in the development and execution of the IAM modernization roadmap.
- Contribute to enterprise identity architecture and governance standards.
- Assist in the transition from legacy access management approaches to modern identity-centric security models.
- Evaluate emerging IAM technologies, industry trends, and best practices.
- Identify opportunities to simplify authorization models, improve governance, and reduce security risk.
- Support enterprise adoption of Zero Trust architecture principles.
- Collaborate with cybersecurity, infrastructure, application, and data teams to improve enterprise-wide identity capabilities.
Identity Governance & Modern Authorization
- Support implementation and continuous improvement of Identity Governance and Administration (IGA) capabilities.
- Participate in role engineering and entitlement management initiatives.
- Assist with access certification campaigns and entitlement lifecycle governance.
- Support Segregation of Duties (SoD) and least-privilege initiatives.
- Assist in implementing policy-based authorization and Attribute-Based Access Control (ABAC) models.
- Participate in data-centric access governance initiatives.
- Support implementation of Just-In-Time (JIT) and Just-Enough-Access (JEA) access models.
- Assist in governance of privileged, service, machine, and workload identities.
- Support development of access governance processes that improve accountability, traceability, and compliance.
Emerging Technology, Automation & AI Governance
- Support governance and lifecycle management of machine, application, service, automation, and AI-related identities.
- Assist in securing access to AI-enabled applications, cloud services, and business processes.
- Participate in reviews of AI data access and authorization requirements.
- Support auditing and monitoring of privileged access used by automation platforms and AI workloads.
- Assist in developing identity controls that support responsible and secure adoption of AI technologies.
- Collaborate with cybersecurity, enterprise architecture, and data governance teams to establish trusted identity controls for emerging technologies.
Identity Platform Engineering
- Design, implement, maintain, and optimize Microsoft Entra ID and Active Directory solutions.
- Support hybrid identity synchronization and federation services.
- Implement and maintain Multi-Factor Authentication (MFA), Conditional Access, and authentication controls.
- Configure and support Single Sign-On (SSO) integrations with enterprise and SaaS applications.
- Implement and maintain Role-Based Access Control (RBAC) and privileged access management solutions.
- Deploy and support Microsoft Entra Identity Governance capabilities.
- Develop and enhance automation using PowerShell and platform integrations.
- Support identity-related integrations with business applications and enterprise platforms.
Operational IAM Support
- Manage user provisioning, deprovisioning, and access requests.
- Maintain user, group, and role management processes.
- Troubleshoot authentication, authorization, and identity synchronization issues.
- Monitor identity platform health, security alerts, and access-related events.
- Support access reviews, account lifecycle management, and operational governance processes.
- Develop and maintain technical documentation, standards, and operational procedures.
Security & Compliance
- Support enterprise least privilege and Zero Trust initiatives.
- Participate in identity-related security investigations and incident response activities.
- Assist with audit preparation and regulatory compliance activities.
- Support access certification reviews and compliance reporting.
- Contribute to compliance initiatives including:
- NIST 800-171
- CMMC
- Internal security and governance standards
- Assist in identifying and remediating identity-related risks and control gaps.
Required Qualifications
- 3+ years of experience in Identity and Access Management, Identity Security, Systems Engineering, or a related discipline.
- Experience supporting Microsoft Entra ID and Active Directory environments.
- Experience with hybrid identity architectures and synchronization technologies.
- Experience implementing and supporting:
- Multi-Factor Authentication (MFA)
- Conditional Access
- Single Sign-On (SSO)/SCIM
- SAML
- OAuth
- OpenID Connect
- Role-Based Access Control (RBAC)
- Understanding of Zero Trust security principles.
- Knowledge of identity lifecycle management processes.
- Experience with PowerShell scripting and automation.
- Strong analytical, troubleshooting, and problem-solving skills.
- Strong communication and collaboration abilities.
Preferred Qualifications
- Microsoft Certified: Identity and Access Administrator Associate.
- Microsoft Certified: Azure Administrator Associate.
- Experience with:
- Microsoft Entra Identity Governance
- Microsoft Entra Privileged Identity Management (PIM)
- Microsoft Intune
- Microsoft Defender for Identity
- ServiceNow integrations
- CyberArk, BeyondTrust, or other PAM platforms
- Experience supporting enterprise environments with 1,500+ users.
- Experience implementing or supporting Identity Governance and Administration (IGA) solutions.
- Experience with access certifications, entitlement management, and Segregation of Duties (SoD).
- Familiarity with machine identities, service principles, managed identities, and workload authentication.
- Knowledge of cloud-native authorization models and modern access control frameworks.
- Understanding of data classification, data governance, and data access control principles.
- Experience integrating identity governance with cloud platforms, analytics environments, and AI-enabled services.
- Knowledge of identity threat detection, identity protection, and identity security best practices.
Technical Skills
Identity Platforms
- Microsoft Entra ID
- Active Directory
- Entra Connect / Azure AD Connect
- Microsoft Entra Identity Governance
Authentication & Authorization
- MFA
- Conditional Access
- SSO/SCIM
- Federation
- SAML
- OAuth
- OpenID Connect
- RBAC
- ABAC
Privileged Access & Identity Security
- Microsoft PIM
- PAM Solutions (CyberArk, BeyondTrust, etc.)
- Defender for Identity
- Zero Trust Security Models
Automation & Integration
- PowerShell
- Identity Process Automation
- ServiceNow Integration
- API Integration
Identity Governance
- Access Reviews
- Access Certification
- Entitlement Management
- Segregation of Duties
- Identity Governance and Administration (IGA)
Data & Emerging Technologies
- Data Access Governance
- Machine Identity Management
- Workload Identity Management
- AI Governance Support
- Cloud Authorization Models
Kokosing is an equal employment opportunity/affirmative action federal and state contractor. The company does not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected class.
