Identity Management Consultant (Denver) Job at InfoVision Inc., Denver, CO

dVVsVFFTREFRNlg5bDY1cWw0bWtBdmRnOGc9PQ==
  • InfoVision Inc.
  • Denver, CO

Job Description

Job title: IAM Engineer

Location: Denver, CO

Duration: Long-term

Key Responsibilities:

Identity and Access Management (IAM) Migration:

  • Lead IAM migration from AWS IAM policies, roles, and groups to Azure Active Directory, Azure RBAC, and GCP IAM roles and bindings.
  • Develop Terraform IaC modules to automate IAM resource creation across Azure and GCP environments.
  • Ensure the least privilege and separation of duties principles are enforced in all IAM configurations.
  • Integrate cloud identity providers (Azure AD, Cloud Identity) with corporate SS(SAML/OIDC).
  • Establish service identities, workload identities, and managed identities for CI/CD and application workloads.

Policy-as-Code (PaC) Governance:

  • Define and implement Policy-as-Code frameworks to enforce cloud governance and compliance baselines in Azure and GCP.
  • Develop and maintain PaC pipelines using Terraform Sentinel, OPA (Open Policy Agent), or Azure Policy.
  • Establish CI/CD pipelines for Policy-as-Code validation, testing, and deployment.
  • Provide guidance and best practices for developing reusable and scalable PaC modules.
  • Implement policy version control, exception management, and automated compliance enforcement.
  • Collaborate with security architects to define policy coverage requirements (IAM, networking, encryption, storage, and tagging).

CI/CD and Automation for Security & IAM:

  • Design and establish CI/CD pipelines for IAM IaC and Policy-as-Code deployments across Azure DevOps, GitHub Actions, and Google Cloud Build.
  • Automate security control deployments using Terraform, including IAM roles, key management, and network policies.
  • Integrate policy compliance checks in the CI/CD flow for both infrastructure and application security pipelines.
  • Build reusable Terraform pipelines to enforce consistent security posture across environments.
  • Establish pipeline security gates (pre-deployment and post-deployment) for IAM and PaC changes.

Security Workload Migration (AWS Azure & GCP):

  • Migrate security workloads such as WAF configurations, key management (KMS), and security analytics from AWS to Azure and GCP.
  • Develop IaC for host infrastructure and application security controls in target clouds.
  • Map AWS security services (IAM, KMS, WAF, GuardDuty) t0 Azure Security Center, Defender for Cloud, and GCP Security Command Center equivalents.
  • Recreate AWS Config Rules and SCPs as Azure Policies and GCP Organization Policies.
  • Ensure encryption, secrets management, and logging solutions are replicated or enhanced in target platforms.
  • Participate in testing, validation, and audit readiness for migrated security components.

Security Monitoring, Compliance & DR Integration:

  • Integrate monitoring and alerting with Azure Monitor, GCP Operations Suite, and SIEM tools.
  • Enable IAM and security event logging via Azure Activity Logs, GCP Audit Logs, and Cloud Logging.
  • Contribute to Disaster Recovery (DR) security alignmentensuring IAM, policy, and encryption configurations are recoverable and consistent across regions.
  • Maintain auditability and compliance mapping (IS27001, NIST, SOC 2)

Required Qualifications:

  • 5+ years of experience in cloud security engineering or IAM governance roles.
  • Proven experience with:
  • AWS IAM, KMS, WAF, Config, and GuardDuty
  • Azure AD, RBAC, Policy, and Defender for Cloud
  • GCP IAM, Cloud KMS, Organization Policies, and SCC
  • Terraform / Terragrunt for IaC and policy automation
  • Hands-on experience with Ping Identity (PingFederate, PingAccess, PingOne).
  • Experience implementing and managing Okta (Workforce or CIAM).
  • OPA / Sentinel / Azure Policy for Policy-as-Code
  • CI/CD systems Azure DevOps, GitHub Actions, or Cloud Build
  • Strong understanding of ZerTrust principles, encryption lifecycle management, and multi-cloud governance.

Preferred Skills:

  • Experience with Azure Blueprints, GCP Forseti Config Validator, or OPA Conftest.
  • Familiarity with cross-cloud SSand federated identity models.
  • Strong scripting background (Python, PowerShell, or Bash).
  • Prior experience migrating workloads from AWS Azure and AWS GCP.

Job Tags

Part time,

Similar Jobs

Forefront Healthcare & Culinary Services

Food Service Delivery Driver Job at Forefront Healthcare & Culinary Services

 ...Forefront Healthcare is looking for a Food Service Delivery Driverin Grand Rapids, Michigan. We aregrowing quickly. Come elevate your career with our company that has won the #1 Best places to work byModern Healthcare. You will be on a team of people that will... 

Braven

Chief Higher Education Partnerships (Chicago) Job at Braven

 ...Job Title : Chief Higher Education Partnerships Team : Higher Education Partnerships Location : Hybrid in Atlanta (GA), Chicago (IL), New York (NYC), or Newark (NJ) Employment Type : Full-time FLSA Classification : Exempt Start Date : ASAP About... 

Aflac, Incorporated

2026 Summer Brand Intern Job at Aflac, Incorporated

 ...offices located in Columbus, Ga for at least 60% of the work week. You will work from your home (within the continental US) for the remaining portion...  ...Education & Experience Required Current undergraduate student (junior or senior) or graduate student in Marketing,... 

Sound Physicians - Dallas, TX - Sound Physicians

Hospitalist - Physician Job at Sound Physicians - Dallas, TX - Sound Physicians

 ...Hospitalist - Physician at Sound Physicians - Dallas, TX - Sound Physicians summary: This role is for a nocturnist hospital medicine physician working overnight shifts at Texas Health Presbyterian Dallas, focusing on patient admissions and collaborative care. The position... 

Revolution Technologies

Clinical Documentation Specialist - Remote (Must have CCDS OR CDIP) (Elgin) Job at Revolution Technologies

 ...established policies/procedures, responsible for improving the overall quality and completeness of clinical documentation in the legal medical record. Facilitates necessary documentation in the medical record through extensive interaction with physicians, HIM and...