Design and implement identity and access management solutions while ensuring compliance with security and audit requirements. Manage identities, roles, and permissions across Active Directory, Microsoft Entra ID, and SaaS applications using automation scripts.
We are looking for an experienced Identity & Access Management (IAM) Engineer to join a complex and highly regulated enterprise environment. In this role, you will be responsible for designing and implementing identity and access management solutions while ensuring compliance with security, governance, and audit requirements.
A key responsibility is the design and maintenance of an enterprise authorization model, with a strong focus on the separation of privileged and standard user accounts based on an established tiering concept.
Key responsibilities
- Design, implement, and maintain Identity & Access Management (IAM) solutions.
- Develop and maintain enterprise authorization and permission models.
- Ensure the proper separation of privileged and standard accounts in accordance with the organization's tiering strategy.
- Manage identities, groups, roles, and permissions across Active Directory, Microsoft Entra ID, and SaaS applications.
- Configure and administer Azure Role-Based Access Control (RBAC), including:
- Role Definitions
- Scopes
- Permission Inheritance
- Custom Roles
- Process and implement access requests received through ServiceNow while communicating with stakeholders to clarify business requirements when necessary.
- Develop and maintain PowerShell automation scripts for identity and access management tasks.
- Work with Microsoft Graph, Az PowerShell modules, and related Microsoft technologies to automate administrative processes.
- Ensure all IAM activities comply with internal security policies, compliance standards, and audit requirements
Required Skills & Experience
- Strong technical knowledge of:
- Active Directory
- Microsoft Entra ID
- Identity and access management for SaaS applications
- Solid understanding of Azure RBAC concepts and administration.
- Experience with PowerShell scripting, including Microsoft Graph and Az PowerShell modules.
- Good understanding of privileged access management and account tiering concepts.
- Strong analytical and problem-solving skills.
- Good communication skills in German, as the role involves working with ServiceNow tickets and interacting with requestors to clarify access requirements.
- Experience working in regulated enterprise environments is considered an advantage.
Working conditions
- Availability during the service window from Tuesday to Friday, 08:00–12:00 (remote presence preferred during these hours).
- Full-time assignment (40 hours per week).