Confirmed on the employer's own hiring board on Oct 6, 2026. First seen by Alion on Oct 6, 2026.
Overview
At PowerSchool, we power education for students around the world. As a global leader in cloud-based K-12 education technology, we help schools operate more effectively and support better outcomes for educators, students, and families.
Our Security team protects the people, systems, and information that make that mission possible. We are looking for an Identity & Access Management Engineer who can help us make access simple for the right people and difficult for everyone else.
Responsibilities
The Identity & Access Management (IAM) Engineer helps build, secure, automate, and support the identity services that connect PowerSchool employees and partners to the technology they need.
You will own and support IAM capabilities across Microsoft Active Directory, Microsoft Entra ID, SailPoint, privileged access, authentication, and enterprise applications. You will implement secure access controls, onboard applications, troubleshoot complex identity issues, automate manual processes, and continuously improve how identities and access are managed across our environment.
This is a hands-on engineering role for someone who understands both sides of identity: protecting the organization while providing a reliable, efficient user experience.
What You Will Do
- Administer and support Microsoft Active Directory and Microsoft Entra ID across hybrid enterprise environments, including identity synchronization, users, groups, roles, and authentication services.
- Manage identity lifecycle processes across joiner, mover, and leaver events, including provisioning, deprovisioning, access requests, birthright access, and entitlement changes.
- Implement and maintain role-based access control (RBAC), least-privilege access, separation of duties, and other identity governance controls.
- Configure and support Multi-Factor Authentication (MFA), Conditional Access, passwordless authentication, passkeys, FIDO2, and related authentication technologies.
- Implement and support enterprise SSO and federation integrations using SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), SCIM, and related standards.
- Onboard enterprise and SaaS applications into PowerSchool’s identity ecosystem, including application registrations, federation, provisioning, certificates, claims, permissions, and access models.
- Administer Microsoft Entra Privileged Identity Management (PIM) and support privileged access controls that enforce just-in-time and least-privilege access.
- Support SailPoint identity governance capabilities, including provisioning workflows, access requests, entitlement management, access certifications, and application onboarding.
- Troubleshoot authentication, federation, provisioning, directory synchronization, entitlement, and access issues across cloud and on-premises environments.
- Build and maintain automation using PowerShell, Bash, Microsoft Graph API, REST APIs, and other appropriate tools to improve reliability and reduce manual administration.
- Monitor IAM platforms and authentication services for availability, performance, security events, and control failures, and support identity-related incident investigation and response.
- Support access reviews, audits, and compliance activities by maintaining accurate controls, documentation, technical evidence, and remediation records.
- Partner with Security, Infrastructure, Compliance, HR, application owners, and business teams to translate access requirements into secure and scalable identity solutions.
- Create and maintain technical documentation, diagrams, standards, runbooks, and operating procedures.
- Identify recurring issues and opportunities to improve IAM processes through automation, standardization, and stronger controls.
- Provide backup support for Microsoft 365 identity-related administration, including Exchange Online and SharePoint, as needed.
What Success Looks Like
You make secure access easier to manage, easier to audit, and more reliable for the people who depend on it. You reduce manual work through automation, resolve identity issues before they become larger problems, strengthen access controls, and help PowerSchool continuously improve how identities are protected across the enterprise.
You bring sound technical judgment, curiosity, attention to detail, and a service mindset to an area of security where both protection and user experience matter.
Qualifications
What You Bring
- 3+ years of experience in identity and access management, security engineering, systems engineering, or a related technical field, or an equivalent combination of education and experience.
- Hands-on experience administering Microsoft Active Directory and Microsoft Entra ID in an enterprise environment.
- Experience with identity lifecycle management, including provisioning, deprovisioning, access requests, entitlements, and joiner/mover/leaver processes.
- Experience implementing or supporting SSO and federation using SAML, OAuth, and OIDC.
- Experience configuring MFA, Conditional Access, and modern authentication controls.
- Working knowledge of identity governance and administration platforms such as SailPoint Identity Security Cloud or IdentityIQ.
- Experience with RBAC, least privilege, privileged access, access certification, and identity governance principles.
- Experience using PowerShell / Bash scripting to automate identity administration and troubleshoot IAM processes.
- Strong troubleshooting and root-cause analysis skills across complex cloud and hybrid identity environments.
- Ability to communicate technical concepts clearly and work effectively with security, infrastructure, application, compliance, and business teams.
Even Better If You Have
- Experience with Microsoft Graph API, REST APIs, JSON, Python, or other scripting and integration technologies.
- Experience configuring Microsoft Entra PIM or enterprise Privileged Access Management (PAM) platforms.
- Experience with SCIM provisioning and API-based application integrations.
- Experience with SailPoint application onboarding, connectors, access certifications, workflows, or entitlement management.
- Experience supporting Microsoft 365, cloud platforms, or enterprise SaaS applications.
- Familiarity with security and compliance frameworks such as NIST, ISO 27001, SOC 2, or SOX.
- Experience supporting security incidents involving compromised identities, credentials, authentication, or privileged access.
- Microsoft SC-300, SailPoint, Security+, SSCP, CISSP, or other relevant identity/security certification.
Compensation & Benefits
Compensation & Benefits
PowerSchool offers the following benefits:
Comprehensive Insurance Coverage (including Medical, Dental, Vision, Pharmacy benefits, Life Insurance and AD&D)
Flexible Spending Accounts and Health Savings Accounts
Short-Term Disability and Long-Term Disability
Comprehensive 401(k) plan
Generous Parental Leave
Unrestricted paid time off (known as Discretionary Time Off - DTO)
Wellness Program, including ClassPass & Employee Assistance Program
Tuition Reimbursement
Optional Benefits: Pet Insurance, Identity Theft Protection, Student Debt Repayment Program and Prepaid Legal coverage
EEO Commitment
EEO Commitment
PowerSchool is committed to a diverse and inclusive workplace. PowerSchool is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. Our inclusive culture empowers PowerSchoolers to deliver the best results for our customers. We not only celebrate the diversity of our workforce, we celebrate the diverse ways we work. If you have a disability and need an accommodation regarding our recruiting process, please let us know by emailing [email protected].

