waypointjobs

Sphere, Inc.

Systems Engineer – Identity & Access Management (IAM)

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

The Opportunity:

We welcome experienced systems administrators and infrastructure engineers who combine strong directory, automation, and troubleshooting skills with a friendly, customer-first approach.

The Systems Engineer – Identity & Access Management (IAM) is a hands-on, customer-facing role responsible for deploying, integrating, supporting, and improving identity-focused infrastructure and SPHEREboard solutions. The engineer combines strong systems-administration fundamentals with identity, data, automation, and interpersonal skills to resolve complex issues and deliver reliable customer outcomes.

This role is well suited to a systems administrator or infrastructure engineer who has owned Active Directory, authentication services, Windows or Linux platforms, scripting, and production troubleshooting—and who wants to build deeper expertise across IAM and identity security.

Essential Functions:

Engineer and administer identity infrastructure. Configure, maintain, and troubleshoot Active Directory, Microsoft Entra ID, LDAP, authentication services, service accounts, certificates, DNS, and related Windows or Linux components.

Deploy and support SPHEREboard. Install and configure application, database, and scan-server components; enable connectors; validate services and access; establish schedules; and support operational handoff.

Integrate enterprise data sources. Connect directories, servers, databases, PAM platforms, HR sources, and other systems using native connectors, SQL, PowerShell, REST APIs, and structured data formats.

Automate repeatable work. Build and maintain PowerShell-based automation for data collection, transformation, validation, monitoring, and operational support.

Work confidently with data. Develop and troubleshoot SQL queries, views, stored procedures, and data mappings; reconcile source inventories and validate completeness and accuracy.

Troubleshoot end to end. Diagnose issues across identity, operating systems, networks, permissions, certificates, application services, databases, connectors, and source data.

Build trusted customer relationships. Demonstrate strong customer-facing skills by partnering with clients to understand business needs, translate technical concepts into clear communications, and deliver timely resolution of system administration requests.

Operationalize deployments. Create runbooks, configuration records, test evidence, support procedures, and training materials that enable reliable customer ownership.

Apply secure engineering practices. Use least privilege, controlled change, secure credential handling, logging, validation, and clear escalation paths throughout implementation and support.

Improve the product and practice. Partner with Engineering, Product, Support, and Services to identify defects, close documentation gaps, improve deployment patterns, and share field learning.

Requirements:

3–5+ years of hands-on experience in systems administration, systems engineering, infrastructure engineering, IAM engineering, or a closely related role.

Strong administration and troubleshooting experience with Windows Server and Active Directory; working knowledge of Linux/Unix administration.

Practical understanding of DNS, TCP/IP, firewalls, ports, proxies, certificates, service accounts, permissions, scheduled services, and remote connectivity.

Proficiency with PowerShell for administration and automation.

Working SQL skills, including joins, filtering, data validation, and troubleshooting; ability to grow into stored procedures, views, indexing, and performance analysis.

Experience supporting production applications or infrastructure and diagnosing multi-system issues from symptoms through root cause.

Familiarity with identity and authentication concepts such as directory services, group membership, role-based access, SSO, MFA, SAML, OAuth/OIDC, or Kerberos.

Demonstrated customer-facing experience; able to build rapport, listen carefully, explain technical findings, manage expectations, and remain professional under pressure.

A security-minded approach to privileged access, credentials, change control, data handling, and operational reliability.

Preferred Experience:

Microsoft Entra ID, hybrid identity, Group Policy, federation, or enterprise SSO administration.

Microsoft SQL Server administration and advanced SQL development, including stored procedures, views, indexing, and query optimization.

IAM, IGA, or PAM platforms such as SailPoint, Okta, CyberArk, or comparable technologies.

Cloud platforms and identity services in Azure, AWS, or Google Cloud.

REST APIs, JSON, XML, Python, Bash, Git, or infrastructure-as-code practices.

Experience deploying enterprise software or delivering technical solutions in customer environments.

Relevant Microsoft, Linux, cloud, security, or identity certifications.

Core Capabilities:

Technical

Systems thinking and disciplined troubleshooting

Identity and directory fundamentals

Automation and data fluency

Secure, supportable solution design

Delivery

Friendly, responsive customer partnership

Clear communication and expectation management

Ownership from discovery through handoff

Practical documentation and knowledge transfer

What Success Looks Like:

Deployments and integrations are delivered securely, accurately, and with clear acceptance evidence.

Identity, infrastructure, connector, and data issues are diagnosed methodically and resolved with minimal escalation.

Automations and technical solutions are reliable, maintainable, documented, and appropriate for production use.

Customers trust the engineer’s technical judgment, approachable style, clear communication, follow-through, and ownership.

Field experience becomes reusable documentation, stronger deployment standards, and actionable product feedback.

Why Join Us:

Apply broad systems-engineering skills to identity security while building deep SPHEREboard expertise and helping large organizations reduce access risk.

Join a high-growth company shaping the future of identity security.

Be part of a collaborative culture that values innovation, transparency, and teamwork.

Work in a dynamic environment alongside talented colleagues, customers, and industry partners.

Enjoy a competitive compensation and benefits package with opportunities for professional growth.

About Sphere:

SPHERE is the global leader in Identity Hygiene. We are dedicated to reshaping modern identity programs by embedding this foundational fabric, enabling organizations to quickly reduce risks. We work through an identity lens that protects an organization’s accounts, data, and infrastructure. Our solutions deliver immediate time-to-value by leveraging automation to discover, remediate and secure identities, now and forever.Driven by our core values of passion, empathy, and authenticity, our vision drives us to continually innovate, helping our clients to sleep better knowing their attack surface is drastically reduced, thwarting the plans of bad actors every single day.

To find out more about SPHERE and our solutions, please visit

SPHERE is an equal-opportunity employer. Applicants will be evaluated without regard to race, color, religion, sex, national origin, disability, veteran status, and other legally protected characteristics.

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

Red Wine and Blue

Himalayas

General Interest Application

Remote — United States (see country and timezone requirements)

Salary not specifiedfull timeRemote

WHO THE HECK ARE WE? Red Wine & Blue is a national community of over 600,000 diverse suburban women working together to defeat extremism, one fr…

Listing expires 2026-12-04View job

Carle Health

Himalayas

Finance Systems Analyst

Remote — United States (see country and timezone requirements)

$26.41 – $44.10 per hourfull timeRemote

OverviewThe Finance Systems Analyst assists with supporting assigned finance/accounting applications for the enterprise such as costing, producti…

Listing expires 2026-12-04View job

Kyowa Kirin

Himalayas

Scientific Relations Manager

Remote — Worldwide (see timezone requirements)

Salary not specifiedfull timeRemote

OverviewWE PUSH THE BOUNDARIES OF MEDICINE. LEAPING FORWARD TO MAKE PEOPLE SMILE At Kyowa Kirin International (KKI), our purpose is to make peop…

Listing expires 2026-12-04View job

Belden, Inc

Himalayas

Solution Consultant - Cybersecurity Practice (US)

Remote — United States (see country and timezone requirements)

$125,000.00 – $160,000.00 per yearfull timeRemote

Innovation Starts With YouPropel your career at Belden, where innovation creates possibilities—for our people, our customers, and the communities…

Listing expires 2026-12-04View job