Job opening

Senior IAM Engineer

Milestone Technologies, Inc.

Torrance, CA

Filed under IT Services and IT Consulting

Full job description

6+ Month W2 Contract (No C2C/No Visa or Student Sponsorship)

Onsite in Torrance, CA

Pay up to $105/hr. (No PTO and No Paid Holidays)


Seeking a Senior IAM Engineer to own the design, integration, and governance of identity and access management across our enterprise, with Microsoft Entra ID as the central identity platform. This role is responsible for provisioning and deprovisioning automation (SCIM), single sign-on (SSO) integrations across SaaS and cloud platforms, and mapping application-specific roles and permissions — including Palantir Foundry and Polarion — to Entra security groups to drive automated, role- and department-based license and access management. The ideal candidate has deep hands-on experience with Entra ID, AWS IAM, and enterprise application integration.


Key Responsibilities

  • Own end-to-end access management strategy and governance across the organization, with Microsoft Entra ID as the identity backbone.
  • Design and implement SCIM-based user provisioning/deprovisioning integrations between Entra ID and downstream SaaS applications.
  • Configure and maintain SSO integrations (SAML/OIDC) between Entra ID and enterprise SaaS platforms, ensuring secure and reliable authentication.
  • Design and manage the mapping of Palantir Foundry roles and permissions to Entra ID security groups, enabling automated and auditable access assignment.
  • Design and manage the mapping of Polarion roles and permissions to Entra ID groups to automate license assignment and access by role and department.
  • Build automated workflows that assign or revoke SaaS licenses based on Entra group membership, role, and department attributes.
  • Configure and manage AWS IAM roles, policies, and identity federation, including SSO integration between AWS and Entra ID.
  • Implement and maintain conditional access policies, MFA, and least-privilege access controls across integrated platforms.
  • Partner with application owners and business stakeholders to define role-based access control (RBAC) models and access request/approval workflows.
  • Conduct periodic access reviews, certifications, and audits to ensure compliance with internal governance and regulatory requirements.
  • Troubleshoot identity, SSO, and provisioning issues across integrated platforms, and drive root-cause resolution.
  • Document IAM architecture, integration patterns, and standard operating procedures for access governance.
  • Stay current on Entra ID, AWS IAM, and identity governance roadmap changes, and assess impact on existing integrations.


Required Qualifications

  • 5+ years of hands-on experience in Identity & Access Management, with deep expertise in Microsoft Entra ID (Azure AD).
  • Strong experience implementing SCIM-based provisioning/deprovisioning integrations between Entra ID and SaaS applications.
  • Strong experience configuring SSO (SAML/OIDC) integrations between Entra ID and enterprise/SaaS platforms.
  • Experience mapping application roles and permissions (e.g., Palantir Foundry, Polarion, or similar enterprise platforms) to Entra ID security groups.
  • Experience automating license assignment/management based on role, group, or department attributes.
  • Hands-on experience with AWS IAM, including roles, policies, and SSO/identity federation between AWS and Entra ID.
  • Solid understanding of RBAC design, least-privilege principles, and access governance best practices.
  • Strong troubleshooting skills across identity, authentication, and provisioning integrations.
  • Excellent communication skills, with the ability to work directly with application owners and business stakeholders on access requirements.


Preferred Qualifications

  • Experience with Palantir Foundry administration or platform governance.
  • Experience with Polarion administration or ALM platform governance.
  • Familiarity with identity governance tools (Entra ID Governance, SailPoint, Saviynt, or similar).
  • Experience with scripting/automation (PowerShell, Microsoft Graph API, or AWS CLI/SDKs) for identity workflows.
  • Microsoft certifications such as SC-300 (Identity and Access Administrator) or AWS Certified Security – Specialty.


The estimated pay range for this position is USD $80.00/hr. - USD $105.00/hr. Exact compensation and offers of employment are dependent on job-related knowledge, skills, experience, licenses or certifications, and location. We also offer comprehensive benefits. The Talent Acquisition Partner can share more details about compensation or benefits for the role during the interview process.

Apply on original listing