What are the responsibilities and job description for the AZURE IAM Architect position at Techim INC?
Job Details
Azure IAM Architect
No OPT & H1 profiles please
Location: While REMOTE working is allowed, personnel based out of Atlanta/Raleigh/Charlotte shall be preferred.
Exclude people from Mountain and Pacific time zones.
Summary:
Experienced and results-driven Azure Engineering IAM Architect with 7 years of hands-on expertise in designing, implementing, and managing Identity and Access Management (IAM) systems in complex, enterprise-grade Azure environments. Proven track record of developing secure, scalable, and policy-compliant access control models using Azure AD, IAM policies, and RBAC. Adept at working with cross-functional teams to ensure identity governance, security posture management, and regulatory compliance.
Key Skills:
- Azure Identity & Access Management (IAM)
- Azure RBAC (Role-Based Access Control)
- Custom RBAC Role Definition and Scoping
- Conditional Access Policies
- Privileged Identity Management (PIM)
- Azure Active Directory (Azure AD)
- Azure Policy and Azure Blueprints
- Enterprise-Grade IAM Architecture
- Identity Governance and Compliance
- Access Reviews and Audit Trails
- B2B and B2C Identity Management
- Integration with On-Prem AD / Hybrid Identity
- Terraform / Bicep / ARM Templates for IAM Automation
- Microsoft Entra ID / Identity Protection
- Zero Trust Architecture Implementation
Technical Expertise:
- Cloud Platforms: Microsoft Azure, Microsoft Entra ID
- IAM Tools: Azure AD, PIM, Azure Policy, Defender for Cloud
- Automation: PowerShell, Azure CLI, Terraform, Bicep
- Monitoring & Auditing: Azure Monitor, Log Analytics, Security Center
- DevSecOps Alignment: Integration with CI/CD pipelines
- Compliance: ISO 27001, NIST, GDPR, HIPAA, SOX
Responsibilities handled:
- Designed and implemented RBAC models for Azure subscriptions across multiple tenants with principle of least privilege.
- Created and maintained custom IAM policies to govern access to Azure resources using tagging and policy initiatives.
- Integrated Azure AD with third-party IdPs (Okta, Ping, ADFS) for SSO and identity federation.
- Enabled PIM to manage and monitor just-in-time privileged access.
- Developed automated scripts using Terraform and Bicep to deploy IAM resources in compliance with company standards.
- Worked with security and compliance teams to enforce Conditional Access, MFA, and audit logging.