hirly

College Board

Workforce IAM Engineer

Remote - USA

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at College Board first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included
Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Mid level
Country
US
Work mode
Remote-friendly
First seen by hirly
8 Oct 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

College Board – Technology – Workforce IAM

Location: This is a remote role. Candidates who live near CB offices have the option of being fully remote or hybrid (Tuesday and Wednesday in office). All CB employees are required to occasionally travel to meet in person for business purposes.

Role Type : This is a full-time position

About the Team

The Workforce Identity and Access Management (WIAM) team is the identity control plane for College Board's enterprise. The team owns the full workforce identity lifecycle, from onboarding and provisioning through access governance, certification, and offboarding, and operates the platforms that enforce authentication, authorization, and privileged access management across the organization.

WIAM's work spans six capability pillars: identity onboarding, provisioning, authentication and authorization, credential management, access certification, and identity offboarding. The team is the primary owner of College Board's enterprise IGA platform and PAM infrastructure, and it partners closely with Talent, ISGRC, and security peer teams to ensure identity services are reliable, auditable, and aligned to Zero Trust principles.

The team operates at the intersection of security rigor and user experience; the controls WIAM builds directly affect how every College Board employee accesses systems and data every day. As College Board's workforce has grown and its cloud and SaaS footprint has expanded, WIAM's scope has grown to match: centralizing more applications, automating more lifecycle actions, and governing an increasingly complex mix of human and non-human identities.

About the Opportunity

As a Workforce IAM Engineer on the WIAM team, you are a proactive, self-directed identity engineer who tries a fix before asking for one. You bring real depth in Microsoft Entra ID, Active Directory, and Okta, and you spot what could be better before anyone complains. You will play a hands-on role keeping identity access secure and reliable across a mix of cloud and hybrid platforms at enterprise scale, where clean role design, dependable provisioning, and strong documentation directly support College Board's Zero Trust strategy. This role exists to carry WIAM's persona-based RBAC rollout forward and keep our standing identity platforms running well. With guidance from senior engineers, you will independently design, build, and ship pieces of the rollout, application by application and role by role, while owning day-to-day administration of our enterprise password management and hardware security key platforms.

You will partner closely with senior WIAM engineers, security architects, and the application teams onboarding to Entra ID and Okta to keep access moving without last-mile friction for end users. Success in this role means personas and applications onboarded on schedule, password and hardware key platforms that hold up under real operational load, and identity access that keeps pace as College Board grows.

In this role, you will:

Design, Build, and Maintain: Persona-Based Access (RBAC) (50%)

Build, test, deploy, and maintain RBAC roles and access policies as new applications and personas are added to the program

Develop and evolve application logic and automations using well-architected, scalable design patterns

Build and maintain Microsoft Entra ID and Okta integrations and workflows, including application onboarding, SSO/SCIM configuration, and automation via Microsoft Graph and Okta APIs

Write and maintain scripts and tooling (e.g., PowerShell) to automate role assignment, access provisioning, and reporting workflows

Maintain existing RBAC roles as organizational structures, entitlements, and applications change over time

Write, test, and document code according to team standards, including unit tests, and perform code reviews to help identify patterns for improvement

Operate and Maintain: Password Management and Hardware Security Keys (30%)

Administer the enterprise password management platform: vault structure, policies, group and SCIM provisioning, onboarding/offboarding, and version upgrades

Support the hardware security key lifecycle: provisioning and enrollment, replacements, PIN resets, and lost/damaged key recovery

Coordinate with Asset Management on shipping logistics for hardware security key distribution to end users and reclamation upon offboarding, replacement, or role change

Monitor platform health, apply updates, and coordinate with vendors on issues as they arise

Contribute to runbooks, documentation, and knowledge-based articles that reduce repeat issues and improve team efficiency

Analysis and Support (20%)

Review requirements and identify design considerations, providing feedback on the design and implementation of features

Analyze authentication, authorization, and access data to support troubleshooting, audits, and continuous improvement

Troubleshoot and resolve application access issues, authentication errors, and integration failures, escalating as appropriate

Support end users and partner teams on identity-related requests, RBAC questions, and platform features

Participate in the team's on-call rotation, responding to identity platform incidents and following established escalation procedures

About You

To qualify for this role, you must have:

3+ years of IT engineering experience, including at least 1 year administering an enterprise password management platform (1Password preferred; Keeper and Bitwarden also considered)

Hands-on experience with Active Directory, Microsoft Entra ID, and Okta, including application onboarding and SSO/SCIM configuration

A strong understanding of hardware security tokens such as YubiKey, Google Titan, and Feitian

Working knowledge of identity and access management concepts such as role-based access control (RBAC), SSO, SAML/OIDC, and MFA

Scripting experience with PowerShell, Python, or both, ideally including automation through the Microsoft Graph API and Entra ID app registrations

Working knowledge of ITIL or other change management frameworks, including change requests, incident management, and release processes

Experience with cloud platforms, with Azure required and AWS strongly preferred, and with modern development practices such as version control (Git), CI/CD, and code review

Exposure to privileged access management (PAM) platforms, such as CyberArk (strongly preferred)

A proactive, self-directed approach: you try first, bring what you tried and where you landed when you ask for help, and spot improvements before anyone asks

Enthusiasm for learning new technologies, ideally shown through enterprise security certifications or coursework, completed or in progress (e.g., CISSP, CISA, SC-300, AZ-900, Security+, or AI governance)

Practical decision-making and a belief in good comments and documentation, reflected in runbooks and knowledge-based articles that others can pick up and use

All roles at College Board require:

A passion for expanding educational and career opportunities and mission-driven work

Authorization to work in the United States for any employer

Curiosity and enthusiasm for emerging technologies, with a willingness to experiment with and adopt new AI-driven solutions and comfort learning and applying new digital tools independently and proactively.

Clear and concise communication skills, written and verbal

A learner's mindset and a commitment to growth: welcoming diverse perspectives, giving and receiving timely, respectful feedback, and continuously improving through iterative learning and user input

A drive for impact and excellence: solving complex problems, making data-informed decisions, prioritizing what matters most, and continuously improving through learning, user input, and external benchmarking

A collaborative and empathetic approach: working across differences, fostering trust, and contributing to a culture of sh

Original posting on College Board's site ↗

Listed on hirly, a job board. hirly is not the employer: College Board is hiring for this role.

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job