About The Role
The Senior Identity and Access Management (IAM) Engineer will implement, administer, and continuously improve enterprise identity services across Active Directory, Microsoft Entra ID, and federated multi-cloud and SaaS platforms. Ensure identity systems are secure, resilient, compliant, and audit-ready; enable modern authentication, automated lifecycle management, and least-privilege access. Partner with Cybersecurity, Infrastructure & Operations, Enterprise Applications, Computer System Validation (CSV), and Quality Assurance (QA) to maintain a validated identity environment for regulatory and modernization needs.
What Youβll Do
- Administer Active Directory Domain Services and Microsoft Entra ID (users, groups, devices).
- Manage hybrid identity sync (Entra ID Connect/Cloud Sync) and troubleshoot provisioning/synchronization.
- Maintain directory health/replication/security and access governance; implement SSO (SAML, OIDC, OAuth, LDAP).
- Configure Conditional Access, MFA, passwordless; support Privileged Identity Management (PIM) and enforce least-privilege.
- Implement Joiner-Mover-Leaver identity lifecycle and governance workflows.
- Maintain federation across AD, Entra ID, AWS, GCP, and enterprise SaaS; troubleshoot authentication/federation/provisioning.
- Support integrations with Workday, ServiceNow, AWS, Microsoft 365, and regulated applications.
- Investigate identity alerts; support incident response; implement Zero Trust-aligned identity security controls.
- Develop/maintain identity disaster recovery and business continuity; validate backup/restore/failover.
- Automate identity provisioning using PowerShell and Microsoft Graph/scripting.
Who You Are (Qualifications)
- Bachelorβs degree in IT/Computer Science or related + 8+ years supporting enterprise IAM or Directory Services.
You Are Or You Have (Required)
- Hands-on Active Directory (users/groups/GPOs/trusts/replication/security admin).
- Entra ID administration and hybrid identity design.
- Experience with SSO, MFA, Conditional Access, and identity lifecycle automation.
- Knowledge of SAML, OAuth, OIDC, LDAP.
- Experience with Entra Connect/Cloud Sync.
- Federation support across AD/Entra ID/AWS/GCP.
- Identity security operations, incident response, or resilience planning.
Nice to Have
- Okta and Entra ID experience.
- Life Sciences/Pharma/GxP regulated environment experience.
- Microsoft 365 security/compliance familiarity.
- PowerShell/Microsoft Graph API automation.
- Microsoft certifications (Identity and Access Administrator Associate, Azure Administrator Associate, Windows Server/Active Directory).
Application Instructions
- Current Insmed employees: apply via the Jobs Hub in Workday.