IAM Engineer at iManage
Chicago, IL
$90,000–$115,000
Jul 7, 2026
Chicago, IL
Jul 21, 2026
What this job asks for AI summary
This role centers on owning and operating identity and access management infrastructure within a Microsoft-heavy environment, with Entra ID as the primary focus. Day-to-day work spans SSO integrations for SaaS applications, PAM via CyberArk, IAM automation through PowerShell and Graph API, and enforcing zero-trust and least-privilege policies. Secondary responsibilities include light network infrastructure coverage. It suits an experienced IAM engineer comfortable working as an individual contributor across globally distributed teams.
Senior level · 5+ years · Chicago-Naperville-Elgin, IL · Full-time
Pay in the description: $90,000–$115,000
“or” means any one of them counts — you don't need all of them.
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 15 people in the Chicago-Naperville-Elgin, IL area plausibly meet what this posting asks for (information security analysts). range 3–20
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $128,066 (middle half $101,954–$161,689). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
SOC classification is a genuine judgment call: the role is primarily IAM-focused (identity federation, SSO, PAM, zero-trust enforcement) which aligns with 15-1212 Information Security Analysts, but it also involves substantial infrastructure/systems administration work (directory services, network secondary coverage, lifecycle automation), making 15-1244 a credible runner-up.
The title contains no seniority level word, so advertised seniority is Unspecified; the 5+ years requirement and end-to-end ownership of IAM infrastructure support a Senior classification.
CyberArk is listed under the requirements section but explicitly qualified as 'preferred', so it is treated as preferred rather than a hard gate.
Python/Bash appear in the requirements section with the qualifier 'a plus', so they are treated as preferred. They are combined into one skill entry with Bash as an alternative since the JD presents them as interchangeable scripting options.
Microsoft 365 E5 security tooling (Defender for Identity, Sentinel, Purview) and Palo Alto are listed in the requirements section but each qualified with 'familiarity with' or 'a plus', so they are treated as preferred.
Dayforce appears only in the responsibilities narrative (not the qualifications section) as an integration partner for JML automation and stale account detection; treated as preferred context rather than a hard gate.
The role is hybrid (in-office Tuesdays & Thursdays in Chicago); remote is set to false.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Microsoft Defender for Identity.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.