Skip to main content
Weightless
College Board
Engineering

Workforce IAM Engineer

College Board

Full-Time
Mid-Level
$128k – $139k/yr
Remote, US
Posted Today

Skills & tools

PythonAWSAzureGitCI/CD

Job Description

**College Board – Technology – Workforce IAM** **Location:** This is a remote role. Candidates who live near CB offices have the option of being fully remote or hybrid (Tuesday and Wednesday in office). All CB employees are required to occasionally travel to meet in person for business purposes. **Role Type**: This is a full\-time position **About the Team** The Workforce Identity and Access Management (WIAM) team is the identity control plane for College Board's enterprise. The team owns the full workforce identity lifecycle, from onboarding and provisioning through access governance, certification, and offboarding, and operates the platforms that enforce authentication, authorization, and privileged access management across the organization. WIAM's work spans six capability pillars: identity onboarding, provisioning, authentication and authorization, credential management, access certification, and identity offboarding. The team is the primary owner of College Board's enterprise IGA platform and PAM infrastructure, and it partners closely with Talent, ISGRC, and security peer teams to ensure identity services are reliable, auditable, and aligned to Zero Trust principles. The team operates at the intersection of security rigor and user experience; the controls WIAM builds directly affect how every College Board employee accesses systems and data every day. As College Board's workforce has grown and its cloud and SaaS footprint has expanded, WIAM's scope has grown to match: centralizing more applications, automating more lifecycle actions, and governing an increasingly complex mix of human and non\-human identities. **About the Opportunity** As a Workforce IAM Engineer on the WIAM team, you are a proactive, self\-directed identity engineer who tries a fix before asking for one. You bring real depth in Microsoft Entra ID, Active Directory, and Okta, and you spot what could be better before anyone complains. You will play a hands\-on role keeping identity access secure and reliable across a mix of cloud and hybrid platforms at enterprise scale, where clean role design, dependable provisioning, and strong documentation directly support College Board's Zero Trust strategy. This role exists to carry WIAM's persona\-based RBAC rollout forward and keep our standing identity platforms running well. With guidance from senior engineers, you will independently design, build, and ship pieces of the rollout, application by application and role by role, while owning day\-to\-day administration of our enterprise password management and hardware security key platforms. You will partner closely with senior WIAM engineers, security architects, and the application teams onboarding to Entra ID and Okta to keep access moving without last\-mile friction for end users. Success in this role means personas and applications onboarded on schedule, password and hardware key platforms that hold up under real operational load, and identity access that keeps pace as College Board grows. *In this role, you will:* Design, Build, and Maintain: Persona\-Based Access (RBAC) (50%) * Build, test, deploy, and maintain RBAC roles and access policies as new applications and personas are added to the program * Develop and evolve application logic and automations using well\-architected, scalable design patterns * Build and maintain Microsoft Entra ID and Okta integrations and workflows, including application onboarding, SSO/SCIM configuration, and automation via Microsoft Graph and Okta APIs * Write and maintain scripts and tooling (e.g., PowerShell) to automate role assignment, access provisioning, and reporting workflows * Maintain existing RBAC roles as organizational structures, entitlements, and applications change over time * Write, test, and document code according to team standards, including unit tests, and perform code reviews to help identify patterns for improvement Operate and Maintain: Password Management and Hardware Security Keys (30%) * Administer the enterprise password management platform: vault structure, policies, group and SCIM provisioning, onboarding/offboarding, and version upgrades * Support the hardware security key lifecycle: provisioning and enrollment, replacements, PIN resets, and lost/damaged key recovery * Coordinate with Asset Management on shipping logistics for hardware security key distribution to end users and reclamation upon offboarding, replacement, or role change * Monitor platform health, apply updates, and coordinate with vendors on issues as they arise * Contribute to runbooks, documentation, and knowledge\-based articles that reduce repeat issues and improve team efficiency Analysis and Support (20%) * Review requirements and identify design considerations, providing feedback on the design and implementation of features * Analyze authentication, authorization, and access data to support troubleshooting, audits, and continuous improvement * Troubleshoot and resolve application access issues, authentication errors, and integration failures, escalating as appropriate * Support end users and partner teams on identity\-related requests, RBAC questions, and platform features * Participate in the team's on\-call rotation, responding to identity platform incidents and following established escalation procedures **About You** *To qualify for this role, you must have:* * 3\+ years of IT engineering experience, including at least 1 year administering an enterprise password management platform (1Password preferred; Keeper and Bitwarden also considered) * Hands\-on experience with Active Directory, Microsoft Entra ID, and Okta, including application onboarding and SSO/SCIM configuration * A strong understanding of hardware security tokens such as YubiKey, Google Titan, and Feitian * Working knowledge of identity and access management concepts such as role\-based access control (RBAC), SSO, SAML/OIDC, and MFA * Scripting experience with PowerShell, Python, or both, ideally including automation through the Microsoft Graph API and Entra ID app registrations * Working knowledge of ITIL or other change management frameworks, including change requests, incident management, and release processes * Experience with cloud platforms, with Azure required and AWS strongly preferred, and with modern development practices such as version control (Git), CI/CD, and code review * Exposure to privileged access management (PAM) platforms, such as CyberArk (strongly preferred) * A proactive, self\-directed approach: you try first, bring what you tried and where you landed when you ask for help, and spot improvements before anyone asks * Enthusiasm for learning new technologies, ideally shown through enterprise security certifications or coursework, completed or in progress (e.g., CISSP, CISA, SC\-300, AZ\-900, Security\+, or AI governance) * Practical decision\-making and a belief in good comments and documentation, reflected in runbooks and knowledge\-based articles that others can pick up and use *All roles at College Board require:* * A passion for expanding educational and career opportunities and mission\-driven work * Authorization to work in the United States for any employer * Curiosity and enthusiasm for emerging technologies, with a willingness to experiment with and adopt new AI\-driven solutions and comfort learning and applying new digital tools independently and proactively. * Clear and concise communication skills, written and verbal * A learner's mindset and a commitment to growth: welcoming diverse perspectives, giving and receiving timely, respectful feedback, and continuously improving through iterative learning and user input * A drive for impact and excellence: solving complex problems, making data\-informed decisions, prioritizing what matters most, and continuously improving through learning, user input, and external benchmarking * A collaborative and empathetic approach: working across differences, fostering trust, and contributing to a culture of shared success **About Our Process** * Application review will begin immediately and will continue until the position is filled. This role is expected to accept applications for a minimum of 5 business days. * While the hiring process may vary, it generally includes: resume and application submission, recruiter phone/video screen, hiring manager interview, performance exercise such as live coding, a panel interview, a conversation with leadership and reference checks. **What We Offer** At College Board, we offer more than just a paycheck—we provide a meaningful career, a supportive team, and a comprehensive package designed to help you thrive. We’re a self\-sustaining nonprofit that believes in fair and competitive compensation, grounded in your qualifications, experience, impact, and the market. ***A Thoughtful Approach to Compensation*** * The hiring range for this role is **$128,000 – $139,000**. * Your exact salary will depend on your location, experience, and how your background compares to others in similar roles at College Board. * We aim to make our best offer upfront—rooted in fairness, transparency, and market data. * We adjust salaries by location to ensure fairness, no matter where you live. You’ll have open, transparent conversations about compensation, benefits, and what it’s like to work at College Board throughout your hiring process. Check out our careers page for more. \#LI\-MS1 \#LI\-REMOTE

Get jobs like this in your inbox

A free weekly email with new remote jobs from the board. Unsubscribe from any email.

Before you apply

Similar Jobs

GitLab Inc

Senior Director, Global SME Solutions Architecture

GitLab Inc
$244k – $410kToday
College Board

Senior Engineer, AI Product Security

College Board
$153k – $166kToday
GitLab Inc

Senior Security Detection Engineer

GitLab Inc
$139k – $190kToday
BV Teck

Middleware System Administrator

BV Teck
$104k – $114kYesterday
MeridianLink

AI Architect - Internal Business Applications

MeridianLink
$150k – $200kYesterday
Merck

US Director of Medical Affairs (US DMA) – Infectious Diseases and Vaccines (Respiratory), Remote

Merck
$191k – $300kToday
BeOne Medicines

Director, Global Medical Affairs - Hematology (zanubrutinib)

BeOne Medicines
$192k – $252kYesterday
General Dynamics Information Technology

Provider Relations Specialist – CCE & Network Support

General Dynamics Information Technology
$85k – $98kYesterday
BeOne Medicines

Director, Global Medical Affairs – Hematology (sonrotoclax)

BeOne Medicines
$192k – $252kYesterday
Workday

Principal Enablement Architect

Workday
$156k – $235kYesterday