Sphere logo
Sphere
Posted 52 days agoVerified live 1d ago

Systems Engineer – Identity & Access Management (IAM)

Brief overview

Remote
3+ yrsMinimum
Active DirectoryWindows Server AdministrationLinux/Unix AdministrationPowerShellSQLIdentity and Access ManagementDNSTCP/IPSAMLOAuth/OIDCKerberosMicrosoft Entra IDExpectation Management

Job description

Summary

SPHERE is a global identity security company focused on Identity Hygiene and helping organizations reduce access risk through automation. The Systems Engineer – Identity & Access Management (IAM) will deploy, integrate, support, and improve identity infrastructure and SPHEREboard solutions while troubleshooting complex systems and delivering customer-focused outcomes.

Responsibilities

  • Engineer and administer identity infrastructure. Configure, maintain, and troubleshoot Active Directory, Microsoft Entra ID, LDAP, authentication services, service accounts, certificates, DNS, and related Windows or Linux components
  • Deploy and support SPHEREboard. Install and configure application, database, and scan-server components; enable connectors; validate services and access; establish schedules; and support operational handoff
  • Integrate enterprise data sources. Connect directories, servers, databases, PAM platforms, HR sources, and other systems using native connectors, SQL, PowerShell, REST APIs, and structured data formats
  • Automate repeatable work. Build and maintain PowerShell-based automation for data collection, transformation, validation, monitoring, and operational support
  • Work confidently with data. Develop and troubleshoot SQL queries, views, stored procedures, and data mappings; reconcile source inventories and validate completeness and accuracy
  • Troubleshoot end to end. Diagnose issues across identity, operating systems, networks, permissions, certificates, application services, databases, connectors, and source data
  • Build trusted customer relationships. Demonstrate strong customer-facing skills by partnering with clients to understand business needs, translate technical concepts into clear communications, and deliver timely resolution of system administration requests
  • Operationalize deployments. Create runbooks, configuration records, test evidence, support procedures, and training materials that enable reliable customer ownership
  • Apply secure engineering practices. Use least privilege, controlled change, secure credential handling, logging, validation, and clear escalation paths throughout implementation and support
  • Improve the product and practice. Partner with Engineering, Product, Support, and Services to identify defects, close documentation gaps, improve deployment patterns, and share field learning

Skills

  • • 3–5+ years of hands-on experience in systems administration, systems engineering, infrastructure engineering, IAM engineering, or a closely related role
  • • Strong administration and troubleshooting experience with Windows Server and Active Directory; working knowledge of Linux/Unix administration
  • • Practical understanding of DNS, TCP/IP, firewalls, ports, proxies, certificates, service accounts, permissions, scheduled services, and remote connectivity
  • • Proficiency with PowerShell for administration and automation
  • • Working SQL skills, including joins, filtering, data validation, and troubleshooting; ability to grow into stored procedures, views, indexing, and performance analysis
  • • Experience supporting production applications or infrastructure and diagnosing multi-system issues from symptoms through root cause
  • • Familiarity with identity and authentication concepts such as directory services, group membership, role-based access, SSO, MFA, SAML, OAuth/OIDC, or Kerberos
  • • Demonstrated customer-facing experience; able to build rapport, listen carefully, explain technical findings, manage expectations, and remain professional under pressure
  • • A security-minded approach to privileged access, credentials, change control, data handling, and operational reliability
  • • Microsoft Entra ID, hybrid identity, Group Policy, federation, or enterprise SSO administration
  • • Microsoft SQL Server administration and advanced SQL development, including stored procedures, views, indexing, and query optimization
  • • IAM, IGA, or PAM platforms such as SailPoint, Okta, CyberArk, or comparable technologies
  • • Cloud platforms and identity services in Azure, AWS, or Google Cloud
  • • REST APIs, JSON, XML, Python, Bash, Git, or infrastructure-as-code practices
  • • Experience deploying enterprise software or delivering technical solutions in customer environments
  • • Relevant Microsoft, Linux, cloud, security, or identity certifications

Qualifications

Must Haves

  • • 3–5+ years of hands-on experience in systems administration, systems engineering, infrastructure engineering, IAM engineering, or a closely related role
  • • Strong administration and troubleshooting experience with Windows Server and Active Directory; working knowledge of Linux/Unix administration
  • • Practical understanding of DNS, TCP/IP, firewalls, ports, proxies, certificates, service accounts, permissions, scheduled services, and remote connectivity
  • • Proficiency with PowerShell for administration and automation
  • • Working SQL skills, including joins, filtering, data validation, and troubleshooting; ability to grow into stored procedures, views, indexing, and performance analysis
  • • Experience supporting production applications or infrastructure and diagnosing multi-system issues from symptoms through root cause
  • • Familiarity with identity and authentication concepts such as directory services, group membership, role-based access, SSO, MFA, SAML, OAuth/OIDC, or Kerberos
  • • Demonstrated customer-facing experience; able to build rapport, listen carefully, explain technical findings, manage expectations, and remain professional under pressure
  • • A security-minded approach to privileged access, credentials, change control, data handling, and operational reliability

Nice to Haves

  • • Microsoft Entra ID, hybrid identity, Group Policy, federation, or enterprise SSO administration
  • • Microsoft SQL Server administration and advanced SQL development, including stored procedures, views, indexing, and query optimization
  • • IAM, IGA, or PAM platforms such as SailPoint, Okta, CyberArk, or comparable technologies
  • • Cloud platforms and identity services in Azure, AWS, or Google Cloud
  • • REST APIs, JSON, XML, Python, Bash, Git, or infrastructure-as-code practices
  • • Experience deploying enterprise software or delivering technical solutions in customer environments
  • • Relevant Microsoft, Linux, cloud, security, or identity certifications

Benefits

  • Apply broad systems-engineering skills to identity security while building deep SPHEREboard expertise
  • Be part of a collaborative culture that values innovation, transparency, and teamwork.
  • Enjoy a competitive compensation and benefits package with opportunities for professional growth.

More jobs like this