Location: Downtown Denver
Schedule: Hybrid (3 days onsite)
Employment Type: W2 - Long-Term Contract (6-12 months)
Compensation: Flexible depending on level of experience
**We are unable to partner with third-party vendors or engage in Corp-to-Corp (C2C) arrangements.**
Overview
We are seeking an experienced IAM / RBAC Engineer to lead the design, implementation, and ongoing management of Identity and Access Management (IAM) and Role-Based Access Control (RBAC) initiatives across the enterprise. This role will be responsible for establishing and maintaining scalable access governance frameworks, enforcing least-privilege principles, and supporting identity lifecycle management processes.
In addition to IAM responsibilities, this position will provide administration and support for Microsoft Intune, ensuring secure and compliant endpoint management across the organization. The ideal candidate will have strong experience with identity governance, access controls, Microsoft Entra ID, Active Directory, and endpoint management technologies.
Key Responsibilities
Identity & Access Management (Primary Focus)
- Design, implement, and maintain enterprise RBAC frameworks, including roles, entitlements, and access policies.
- Lead or support Identity Governance and Administration (IGA) initiatives, including platform implementation and optimization.
- Develop and maintain least-privilege access models across applications and infrastructure.
- Perform access analysis, entitlement reviews, and ongoing role optimization.
- Manage user lifecycle processes, including Joiner, Mover, and Leaver workflows.
- Administer and support access certification campaigns, periodic access reviews, and governance processes.
- Design and maintain provisioning and deprovisioning workflows to ensure timely and secure access changes.
- Partner with application owners, security teams, and business stakeholders to map job functions to appropriate access models.
- Support audit, compliance, and regulatory requirements, including SOX controls, segregation of duties, and access certification activities.
- Create and maintain documentation for access governance standards, procedures, and controls.
Microsoft Entra ID & Active Directory
- Administer Microsoft Entra ID (Azure AD), Active Directory, and hybrid identity environments.
- Manage groups, role assignments, and access delegation strategies.
- Configure and support Privileged Identity Management (PIM).
- Implement and maintain Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Conditional Access policies.
- Support identity-related security initiatives and incident resolution.
Microsoft Intune Administration (20-30% of Role)
- Administer Microsoft Intune for endpoint and device management.
- Manage Windows device enrollment and provisioning, including Windows Autopilot.
- Configure and maintain compliance policies, configuration profiles, and endpoint security policies.
- Deploy and manage applications across enterprise devices.
- Support software deployment, patch management, and device lifecycle activities.
- Monitor and maintain endpoint compliance and security posture.
Required Qualifications
- 3+ years of experience in Identity and Access Management (IAM), Identity Governance, or Access Management.
- Proven experience designing, implementing, or re-architecting RBAC models.
- Hands-on experience with least-privilege access controls and entitlement management.
- Strong understanding of identity governance processes, including:
- User lifecycle management
- Joiner, Mover, and Leaver processes
- Access reviews and certifications
- Provisioning and deprovisioning workflows
- Experience administering Microsoft Entra ID (Azure AD), Active Directory, or hybrid identity environments.
- Knowledge of:
- Role assignments and security groups
- Privileged Identity Management (PIM)
- Single Sign-On (SSO)
- Multi-Factor Authentication (MFA)
- Conditional Access
- Experience with Microsoft Intune or similar MDM/UEM platforms.
- Understanding of segregation of duties (SoD), access governance, and security best practices.
- Strong documentation, communication, and stakeholder management skills.
Preferred Qualifications
- Experience with Identity Governance and Administration (IGA) platforms such as SailPoint, Saviynt, or Entra ID Governance.
- Experience automating IAM processes using PowerShell, Microsoft Graph API, or similar tools.
- Experience supporting SOX compliance, access audits, or governance programs.
- Knowledge of endpoint security and modern device management best practices.
- Relevant certifications such as:
- Microsoft Endpoint Administrator Associate
- Microsoft Identity and Access Administrator
- Security+
- Other IAM or cybersecurity-related certifications
Ideal Candidate
The ideal candidate has successfully built or redesigned RBAC frameworks, implemented identity governance processes, and administered Microsoft Entra ID in complex enterprise environments. They possess a strong understanding of access controls, governance, and compliance requirements while also being comfortable managing Microsoft Intune for endpoint administration. This individual will be a hands-on contributor who can partner effectively with Security, IT Operations, and application teams to drive mature access management practices across the organization.
Benefits:
At Ledgent Technology/Roth Staffing, we prioritize our contractors, whom we proudly call Ambassadors. Our commitment to you is demonstrated through a comprehensive benefits program that stands out in the temporary staffing industry. We annually review and update our vendor relationships to ensure we provide the most cost-effective benefits options. Our Ambassadors are eligible for a wide range of benefits, including:
- Minimum Essential Coverage (MEC) Plan
- Basic and enhanced hospital indemnity plans
- Dental and vision coverage
- Accident and critical illness plans
- Term life insurance
- Short-term disability plan
- Direct deposit/pay card options
- Credit union membership
- Employee discount clubs
- Referral bonuses
- Training and coaching
- Specialized recognition programs
All qualified applicants will receive consideration for employment without regard to race, color, national origin, age, ancestry, religion, sex, sexual orientation, gender identity, gender expression, marital status, disability, medical condition, genetic information, pregnancy, or military or veteran status. We consider all qualified applicants, including those with criminal histories, in a manner consistent with state and local laws, including the California Fair Chance Act, City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, Los Angeles County Fair Chance Ordinance, and San Francisco Fair Chance Ordinance.