Systems Engineer, IAM at Riot Platforms, Inc.
Castle Rock, CO
$115,000–$135,000from the description
Aug 10, 2026
Castle Rock, CO
Sep 24, 2026
What this job asks for AI summary
A Systems Engineer focused on identity and access management, responsible for administering and progressively automating Riot Platforms' Microsoft Entra ID environment, hybrid Active Directory, endpoint management (Intune/Jamf), and Microsoft 365 services. The role bridges traditional system administration and DevOps, applying infrastructure-as-code, CI/CD pipelines, and scripting to replace manual processes with repeatable, version-controlled automation across identity, devices, and cloud infrastructure.
Mid level · 4+ years · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $101,310 (middle half $79,725–$129,425). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 12, 2026. It is a model, not a headcount.
Why we read it this way (12)
No work location is specified in the posting; the CBSA and state fields are left blank. The role does not appear to be advertised as remote.
The posting titles this role 'Systems Engineer, IAM' with no seniority level in the title. The 4+ years requirement and scope of work (owning an identity environment, building automation) support a Mid-level classification rather than Senior, as the role does not describe org-wide architectural authority.
SOC classification is a genuine judgment call: the role primarily operates and administers identity/endpoint infrastructure (15-1244) but has a meaningful software/automation engineering component — writing IaC, CI/CD pipelines, and scripting — that could support 15-1252. 15-1244 was chosen because the primary day-to-day work is administering and securing existing systems (Entra ID, AD, Intune, M365), with automation as a growth objective rather than the core deliverable.
Terraform, AWS CDK, and SaltStack are listed together as interchangeable IaC options under the requirements section; Terraform is named first and the others are captured as alternatives.
GitLab CI/CD and GitHub Actions are listed as interchangeable CI/CD options in the requirements section.
Python and C# are listed as interchangeable scripting alternatives (C# preferred per the posting); PowerShell is a separate, standalone requirement.
Prometheus and Grafana appear in the 'What You'll Do' narrative section rather than a formal requirements block, so they are marked as preferred.
Jamf appears in the 'What You'll Do' section alongside Intune; Intune is explicitly required in the Knowledge/Skills section while Jamf is not, so Jamf is marked preferred.
StrongDM is listed in the requirements section as an example of just-in-time/privileged access tooling and is marked required accordingly.
Microsoft Graph, AWS, and cryptocurrency/blockchain/HPC experience all appear under the 'Nice to Have' section.
The degree requirement states 'Bachelor's degree… equivalent experience considered,' which means no formal degree is hard-gated.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Privileged Identity Management.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.