{"id":1523325,"url":"https://alion.io/job/kokosing-iam-engineer","title":"IAM Engineer","company":{"id":1996545,"name":"Kokosing","domain":"kokosing.biz","url":"https://alion.io/company/kokosing","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"B","score":70,"open_postings":33,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":63,"computed_at":"2026-10-03T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":85000,"max_usd":178000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":237},"experience_years_min":3,"visa_sponsorship":true,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"IAM","optional":false},{"name":"Least Privilege","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"NIST 800-171","optional":false},{"name":"Platform Engineering","optional":false},{"name":"PowerShell","optional":false},{"name":"Zero Trust","optional":false},{"name":"Azure","optional":true},{"name":"BeyondTrust","optional":true},{"name":"CyberArk","optional":true},{"name":"Microsoft Defender","optional":true},{"name":"ServiceNow","optional":true}],"status":"live","first_seen_at":"2026-08-04T00:00:00Z","employer_posted_date":"2026-08-04","last_verified_at":"2026-10-04T00:18:49Z","board_verified":true,"closed_at":null,"days_open":61,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":61},"description":"Kokosing (www.kokosing.biz) is one of America's 50 largest General Contractors and services a broad spectrum of clients in both the private and public business sectors. Kokosing's services include heavy civil/industrial construction such as highways, bridges, underground utilities, water/wastewater facilities, and marine construction. For over 75 years, Kokosing has successfully attracted the most qualified technical personnel in the construction industry by offering visible challenges, superior quality, and attractive rewards. With over $2.8 billion in annual sales and a commitment to its workforce, Kokosing is the winning team.\n Job Description:\nWe are seeking an Identity and Access Management (IAM) Engineer to help modernize and evolve our identity platform into a strategic trust, governance, and authorization architecture supporting employees, applications, machine identities, cloud services, data platforms, and emerging AI technologies.\nThis role will contribute to the design, implementation, and continuous improvement of identity governance, privileged access management, Zero Trust initiatives, modern authorization models, and data-centric access controls across hybrid enterprise environments.\nThe ideal candidate combines strong technical expertise with a governance-first mindset and understands that identity is more than account management. Identity serves as the foundation for securing enterprise resources, governing access to critical data, enabling automation, and supporting trusted human and non-human interactions across the organization.\nThis position plays a key role in the organization's transition from traditional identity administration toward a modern identity security and governance model capable of supporting future business, cloud, and AI-driven initiatives.\nThis role is not eligible for visa sponsorship.\nKey Responsibilities\nIdentity Architecture & Modernization\nParticipate in the development and execution of the IAM modernization roadmap.\nContribute to enterprise identity architecture and governance standards.\nAssist in the transition from legacy access management approaches to modern identity-centric security models.\nEvaluate emerging IAM technologies, industry trends, and best practices.\nIdentify opportunities to simplify authorization models, improve governance, and reduce security risk.\nSupport enterprise adoption of Zero Trust architecture principles.\nCollaborate with cybersecurity, infrastructure, application, and data teams to improve enterprise-wide identity capabilities.\nIdentity Governance & Modern Authorization\nSupport implementation and continuous improvement of Identity Governance and Administration (IGA) capabilities.\nParticipate in role engineering and entitlement management initiatives.\nAssist with access certification campaigns and entitlement lifecycle governance.\nSupport Segregation of Duties (SoD) and least-privilege initiatives.\nAssist in implementing policy-based authorization and Attribute-Based Access Control (ABAC) models.\nParticipate in data-centric access governance initiatives.\nSupport implementation of Just-In-Time (JIT) and Just-Enough-Access (JEA) access models.\nAssist in governance of privileged, service, machine, and workload identities.\nSupport development of access governance processes that improve accountability, traceability, and compliance.\nEmerging Technology, Automation & AI Governance\nSupport governance and lifecycle management of machine, application, service, automation, and AI-related identities.\nAssist in securing access to AI-enabled applications, cloud services, and business processes.\nParticipate in reviews of AI data access and authorization requirements.\nSupport auditing and monitoring of privileged access used by automation platforms and AI workloads.\nAssist in developing identity controls that support responsible and secure adoption of AI technologies.\nCollaborate with cybersecurity, enterprise architecture, and data governance teams to establish trusted identity controls for emerging technologies.\nIdentity Platform Engineering\nDesign, implement, maintain, and optimize Microsoft Entra ID and Active Directory solutions.\nSupport hybrid identity synchronization and federation services.\nImplement and maintain Multi-Factor Authentication (MFA), Conditional Access, and authentication controls.\nConfigure and support Single Sign-On (SSO) integrations with enterprise and SaaS applications.\nImplement and maintain Role-Based Access Control (RBAC) and privileged access management solutions.\nDeploy and support Microsoft Entra Identity Governance capabilities.\nDevelop and enhance automation using PowerShell and platform integrations.\nSupport identity-related integrations with business applications and enterprise platforms.\nOperational IAM Support\nManage user provisioning, deprovisioning, and access requests.\nMaintain user, group, and role management processes.\nTroubleshoot authentication, authorization, and identity synchronization issues.\nMonitor identity platform health, security alerts, and access-related events.\nSupport access reviews, account lifecycle management, and operational governance processes.\nDevelop and maintain technical documentation, standards, and operational procedures.\nSecurity & Compliance\nSupport enterprise least privilege and Zero Trust initiatives.\nParticipate in identity-related security investigations and incident response activities.\nAssist with audit preparation and regulatory compliance activities.\nSupport access certification reviews and compliance reporting.\nContribute to compliance initiatives including:NIST 800-171\nCMMC\nInternal security and governance standards\n\nAssist in identifying and remediating identity-related risks and control gaps.\nRequired Qualifications\n3+ years of experience in Identity and Access Management, Identity Security, Systems Engineering, or a related discipline.\nExperience supporting Microsoft Entra ID and Active Directory environments.\nExperience with hybrid identity architectures and synchronization technologies.\nExperience implementing and supporting:Multi-Factor Authentication (MFA)\nConditional Access\nSingle Sign-On (SSO)/SCIM\nSAML\nOAuth\nOpenID Connect\nRole-Based Access Control (RBAC)\n\nUnderstanding of Zero Trust security principles.\nKnowledge of identity lifecycle management processes.\nExperience with PowerShell scripting and automation.\nStrong analytical, troubleshooting, and problem-solving skills.\nStrong communication and collaboration abilities.\nPreferred Qualifications\nMicrosoft Certified: Identity and Access Administrator Associate.\nMicrosoft Certified: Azure Administrator Associate.\nExperience with:Microsoft Entra Identity Governance\nMicrosoft Entra Privileged Identity Management (PIM)\nMicrosoft Intune\nMicrosoft Defender for Identity\nServiceNow integrations\nCyberArk, BeyondTrust, or other PAM platforms\n\nExperience supporting enterprise environments with 1,500+ users.\nExperience implementing or supporting Identity Governance and Administration (IGA) solutions.\nExperience with access certifications, entitlement management, and Segregation of Duties (SoD).\nFamiliarity with machine identities, service principles, managed identities, and workload authentication.\nKnowledge of cloud-native authorization models and modern access control frameworks.\nUnderstanding of data classification, data governance, and data access control principles.\nExperience integrating identity governance with cloud platforms, analytics environments, and AI-enabled services.\nKnowledge of identity threat detection, identity protection, and identity security best practices.\nTechnical Skills\nIdentity Platforms\nMicrosoft Entra ID\nActive Directory\nEntra Connect / Azure AD Connect\nMicrosoft Entra Identity Governance\nAuthentication & Authorization\nMFA\nConditional Access\nSSO/SCIM\nFederation\nSAML\nOAuth\nOpenID Connect\nRBAC\nABAC\nPrivileged Access & Identity Security\nMicrosoft PIM\nPAM Solutions (CyberArk, BeyondTrust, etc.)\nDefender for Identity\nZero Trust Security Models\nAutomation & Integration\nPowerShell\nIdentity Process Automation\nServiceNow Integration\nAPI Integration\nIdentity Governance\nAccess Reviews\nAccess Certification\nEntitlement Management\nSegregation of Duties\nIdentity Governance and Administration (IGA)\nData & Emerging Technologies\nData Access Governance\nMachine Identity Management\nWorkload Identity Management\nAI Governance Support\nCloud Authorization Models\nKokosing is an equal employment opportunity/affirmativeaction federal and state contractor. The company does not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected class.","description_format":"text","description_chars":8699,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Manufacturing","Natural Resources","Construction"],"lifecycle":[{"event":"open","at":"2026-09-30T12:47:06Z"}],"visa":[],"liveness":{"score":28,"band":"fade","label":"Fading","p_open":1,"p_active":0.468,"p_room":0.6,"age_days":60,"expected_fill_days":63,"reasons":["conf:13","stale_co","win:late","crowd:brand"],"computed_at":"2026-10-03T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/kokosing-iam-engineer","json_url":"https://alion.io/job/kokosing-iam-engineer.json","meta":{"generated_at":"2026-10-04T02:13:34Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3064,"day_limit":5000,"remaining_today":1936,"minute_limit":60,"resets_at":"2026-10-05T00:00:00Z"}}}