Senior Identity Access Management Engineer
Roku · San Jose, United States
About The Role
Join Roku as a Senior Identity Access Management Engineer. In this role, you will enhance our Zero-Trust architecture, drive standardization initiatives, and optimize our Microsoft-centric identity platform for a geographically distributed workforce. You will lead enterprise-wide IAM standardization, drive automation across IAM, support enterprise applications onboarding into Azure Entra ID, enhance privileged access management, and collaborate with IT, Networking, and Security teams. The ideal candidate has hands-on experience in identity and access management, securing cloud environments within the Microsoft ecosystem, and a strong automation mindset.
- Lead enterprise-wide IAM standardization, including identity lifecycle, access governance, and policy enforcement across global regions.
- Drive automation across IAM to streamline administration and deliver a smoother user experience.
- Support enterprise applications onboarding into Azure Entra ID, including SSO, Conditional Access, and role-based access control (RBAC).
- Strong analytical skills and attention to detail, with the ability to troubleshoot complex infrastructure and identity-related issues
- Deep experience with Microsoft Entra ID, including Conditional Access, Identity Governance, and Privileged Identity Management
- Understanding of Zero Trust Architecture principles
- Good to have familiarity with Microsoft Purview for DLP and data classification
- Strong understanding of multi-factor authentication and FIDO2
- Knowledge of privileged access tools (Azure PIM, CyberArk, etc), secrets management (HashiCorp or Azure Key Vault), and workload identity patterns SPIFEE & SPIRE
- Familiarity with Microsoft 365 services: Exchange Online, Defender, Purview, Sentinel, Intune, and related platforms
- 8+ years of hands-on experience with identity and access management and automating cloud technologies, particularly within the Microsoft ecosystem
- Advanced knowledge of Azure Single Sign-On (SSO) login methods, including OAuth2, OpenID Connect, and SAML, and their integration with enterprise applications
- Experience in onboarding and managing enterprise applications in Azure Entra ID
- Experience with backup and recovery strategies for identity-related services
- Familiarity with NHI governance concepts for service accounts and AI agents, and exposure to OPA / Rego or similar policy-as-code frameworks
- Excellent communication skills, with the ability to clearly explain technical concepts to both technical and non-technical stakeholders
- B.S. in Computer Science, Information Technology, Engineering, or equivalent experience
- Familiarity with IT security frameworks and compliance standards
- Basic understanding of email security and DNS
- Knowledge of logging, monitoring, and alerting practices for identity and access events
- Automation and scripting skills using PowerShell, Azure CLI, and Microsoft Graph API; working knowledge of Azure services such as Function Apps and Logic Apps
- Familiarity with Jira and Confluence
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring