Systems Engineer, IAM

Riot Platforms

  • Castle Rock, Colorado
  • 3 days ago

    Highlights

    This is a role for someone equally comfortable administering identity and access today and automating it as code tomorrow – managing Entra ID, conditional access, endpoints, and Microsoft 365, while applying infrastructure as code, CI/CD, and modern DevOps practices in equal measure. Manage access and privileged identity – Build and maintain conditional access policies, Privileged Identity Management (PIM), MFA, and just-in-time access workflows (including StrongDM) to enforce least privilege.

    Numbers & Facts

    LocationCastle Rock, Colorado

    Description

    About The Role

    Riot Platforms is looking for a Systems Engineer, IAM to own our Microsoft Entra and identity environment and engineer how we run it. This is a role for someone equally comfortable administering identity and access today and automating it as code tomorrow – managing Entra ID, conditional access, endpoints, and Microsoft 365, while applying infrastructure as code, CI/CD, and modern DevOps practices in equal measure.


    This position sits at the center of our shift from traditional system administration to a DevOps operating model. You’ll keep our identity, device, and Microsoft 365 environment secure and reliable, and progressively replace manual processes with automation, version-controlled configuration, and repeatable pipelines. You’ll work closely with software engineering, IT, and cyber security, and provide visibility across our Data Center, Bitcoin Mining, and Manufacturing operations.

    What You'll Do

    • Administer Microsoft Entra ID – Manage users, groups, roles, application registrations, and enterprise SSO (SAML/OIDC) across the organization.
    • Manage access and privileged identity – Build and maintain conditional access policies, Privileged Identity Management (PIM), MFA, and just-in-time access workflows (including StrongDM) to enforce least privilege.
    • Operate hybrid identity – Maintain on-premises Active Directory, Entra Connect synchronization, and hybrid identity across cloud and on-premises environments.
    • Manage endpoints with Intune and Jamf – Configure device management, compliance, and endpoint security policies through Microsoft Intune and Jamf.
    • Administer Microsoft 365 – Manage Exchange Online, licensing, and broader Microsoft 365 services to keep collaboration secure and reliable.
    • Automate configuration as code – Define and manage identity and infrastructure configuration using tools such as Terraform, AWS CDK, and SaltStack to make environments repeatable and auditable.
    • Build CI/CD and automation pipelines – Replace manual administrative tasks with version-controlled automation and CI/CD pipelines (GitLab CI/CD, GitHub Actions).
    • Script and build tooling – Develop automation in PowerShell, Python, or C# to streamline provisioning, reporting, and routine operations.
    • Implement monitoring, alerting, and logging – Stand up observability and audit logging across identity, endpoints, and infrastructure using tools such as Prometheus and Grafana and native cloud tooling.
    • Advance the DevOps operating model – Help mature standards, documentation, and engineering practices as the team moves from manual administration toward a DevOps operating model.

    Knowledge, Skills, and Abilities

    • Microsoft Entra ID – Strong hands-on experience administering Entra ID (Azure AD): users, groups, roles, app registrations, and SSO.
    • Access and identity security – Experience with conditional access, MFA, Privileged Identity Management (PIM), and just-in-time/privileged access tooling such as StrongDM.
    • Hybrid identity – Experience with on-premises Active Directory and Entra Connect synchronization.
    • Endpoint management – Hands-on experience with Microsoft Intune for device management and compliance.
    • Microsoft 365 administration – Experience administering Microsoft 365, including Exchange Online and licensing.
    • Infrastructure as code – Experience with, or a strong drive to grow into, IaC tools such as Terraform, AWS CDK, or SaltStack.
    • CI/CD and version control – Familiarity with Git and CI/CD tooling (GitLab CI/CD, GitHub Actions) for automating configuration and deployments.
    • Scripting and automation – Proficiency in PowerShell and at least one of Python or C# (C# preferred).
    • Security mindset – Strong understanding of identity, access, and infrastructure security best practices.
    • Problem-solving and communication – Excellent problem-solving skills and the ability to communicate clearly with both technical and non-technical stakeholders.

    Nice to Have

    • Relevant Microsoft certifications (e.g., SC-300 Identity and Access Administrator, AZ-104, or equivalent)Experience automating
    • Entra and Microsoft 365 administration with Microsoft Graph (PowerShell SDK or API)
    • Experience supporting a transition from manual system administration to a DevOps / infrastructure-as-code model
    • Exposure to AWS or other multi-cloud environments
    • Experience with cryptocurrency, blockchain, or high-performance computing environments
    • Experience in manufacturing, construction, energy, mining, data center, or other capital-intensive industries

    What You'll Bring

    • Bachelor’s degree in Computer Science, Information Technology, Engineering, or a related field – equivalent experience considered.
    • 4+ years of experience in systems engineering, system administration, or identity and access administration.
    • Hands-on experience with Microsoft Entra ID and/or Active Directory required.
    • Microsoft or cloud certification preferred.

    Why This Role Matters

    This role is how Riot modernizes the way it runs systems. You won’t just keep identity and devices running – you’ll engineer them, turning manual administration into automated, version-controlled infrastructure. If you want to deepen your identity expertise while building real DevOps and automation skills, this role offers a clear path to do both and make a visible impact.

    Compensation and Benefits

    • Competitive Salary: $115,000 - $135,000 (commensurate with experience) + bonus + sign-on equity grant
    • 401(k) plan with company matching
    • Great medical, vision, and dental plans to choose from
    • Long-term and short-term disability
    • Additional benefit options (Employee Assistance Program, Pet Insurance, and more)
    • Flexible Spending Accounts
    • Generous PTO and Paid Holidays
    • A fun company culture with tremendous growth opportunities


    Riot is an equal opportunity employer. We are committed to creating an inclusive environment for all employees.

    Similar Jobs

    See more jobs