What are the responsibilities and job description for the Lead Hybrid Identity Lead Engineer (IAM) position at Kforce Inc?
Responsibilities
Lead IAM Engineer Responsibilities Kforce is partnering with a mission-driven organization in New York, NY seeking a Hybrid Identity Lead Engineer to help lead enterprise-wide IAM initiatives supporting a modern Zero Trust architecture. This is a hands-on, lead-level role focused on hybrid identity across on-prem and cloud environments, with core emphasis on Microsoft Entra ID (Azure AD) and AWS IAM (GCP is a plus, not required). You'll play a key role in designing secure, scalable identity solutions, driving automation and governance, and partnering closely with security and infrastructure teams. The role is super flexible (about once per week onsite) and offers a strong overall package including a 403(b), generous PTO, excellent medical benefits, tuition reimbursement, and a discretionary bonus. Lead IAM Engineer Lead IAM Engineer What You'll Do:
Lead IAM Engineer Requirements
We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.
Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.
This job is not eligible for bonuses, incentives or commissions.
Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
By clicking “Apply Today” you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.
Lead IAM Engineer Responsibilities Kforce is partnering with a mission-driven organization in New York, NY seeking a Hybrid Identity Lead Engineer to help lead enterprise-wide IAM initiatives supporting a modern Zero Trust architecture. This is a hands-on, lead-level role focused on hybrid identity across on-prem and cloud environments, with core emphasis on Microsoft Entra ID (Azure AD) and AWS IAM (GCP is a plus, not required). You'll play a key role in designing secure, scalable identity solutions, driving automation and governance, and partnering closely with security and infrastructure teams. The role is super flexible (about once per week onsite) and offers a strong overall package including a 403(b), generous PTO, excellent medical benefits, tuition reimbursement, and a discretionary bonus. Lead IAM Engineer Lead IAM Engineer What You'll Do:
- Identity Lead Engineer will architect and maintain a unified IAM framework across AD, Azure AD, AWS, and GCP
- Implement enterprise identity standards including RBAC, naming conventions, and lifecycle automation
- Lead the adoption of Zero Trust principles and enforce least privilege access across multi-cloud environments
- Collaborate with DevOps and cloud teams to ensure secure, auditable access models
- Administer and optimize on-prem Active Directory and Entra ID Conditional Access policies
- Automate provisioning and group management using PowerShell, Python, or Terraform
- As an Identity Lead Engineer, you will respond to audit findings and security assessments with expert-level IAM solutions
- Mentor engineers and contribute to cross-functional initiatives across IT security, infrastructure, and compliance
Lead IAM Engineer Requirements
- Bachelor's degree in a related field
- Cloud certifications such as: Microsoft Certified: Identity and Access Administrator Associate; AWS Certified Security Specialty; GCP Cloud Security Engineer
- 7 years of experience in identity and access management
- Hands-on experience with Active Directory, Azure AD, AWS IAM, and GCP IAM
- Strong scripting skills (PowerShell, Python, Terraform)
- Familiarity with PAM tools (e.g., CyberArk, BeyondTrust) and IGA solutions (e.g., SailPoint)
We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.
Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.
This job is not eligible for bonuses, incentives or commissions.
Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
By clicking “Apply Today” you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.
Salary : $150,000 - $170,000