
AWS DevOps / Reliability & Optimization Engineer Kforce Inc.
- $57.16–$73.63
| Location | Denver, Colorado |
| Salary | $75–$85 Per Hour |
This is a hands-on IAM Automation Engineer role within the Information Security team of a leading healthcare technology company, designing, building, and supporting automation across the full identity and access management ecosystem rather than any single platform. This seat requires broad IAM engineering experience across identity governance, directories, privileged access management, authentication and authorization, ITSM workflows, cloud IAM, and SaaS and enterprise integrations, calling for a versatile engineer who can code and automate across multiple platforms and languages rather than a single-platform specialist. A companion, more SailPoint-focused engineering role is also open on the same team. The role supports the organization's flagship identity platform, which secures more than five million members and other external identities across all digital portals.
NOTE: *Must be eligible to work on W2 without sponsorship. Not eligible for C2C.
Access Pattern Discovery: identify and document how access actually works across cloud, on-premises, and legacy applications, including systems without an existing API or Active Directory connector, as the foundation for automating them
IAM Automation Engineering: design, build, test, and maintain automation for identity lifecycle, provisioning/deprovisioning, access requests, approvals, and access reviews
Directory & PAM Operations: configure and support Active Directory, Microsoft Entra ID, and CyberArk (or equivalent PAM tooling) as core platforms
Authentication & Authorization: own multi-factor authentication and single sign-on workflows; Okta experience preferred, Ping experience is considered transferable
Coding, APIs & Integration: develop scripts, services, API integrations, workflow automations, and reusable utilities (PowerShell, Python, or similar)
Hands-On DevOps Ownership: set up and own CI/CD pipelines directly — a working method here, not a toolset managed by an adjacent team
Operational Support & Reliability: troubleshoot automation, integration, and access issues; resolve incidents; improve reliability via monitoring and logging
Documentation & Runbooks: maintain process flows, automation logic, runbooks, and support procedures
Experience: 7+ years in identity and access management or automation engineering, at a senior/consultant level of seniority
Required platforms: Active Directory, Microsoft Entra ID, CyberArk (or equivalent PAM)
Required skill: multi-factor authentication and single sign-on configuration and troubleshooting
Preferred: SailPoint experience; Okta (Ping experience is transferable); ServiceNow development capability
Coding/Scripting: PowerShell, Python, REST APIs, or similar, with the ability to set up and own CI/CD pipelines hands-on
Professional skills: strong communication across levels, accountability, ownership, self-motivation, and the ability to prioritize independently — treated as hard requirements, not soft preferences




