Identity & Access Management (IAM) Engineer
Job Summary
IT accelerates the success of IDEXX employees and customers by providing scalable and innovative solutions and leadership. We are a global organization that supports all technology needed to deliver products and solutions to customers enabling them to focus on delivering high quality patient care. We strive to provide exceptional customer service and experience in the most efficient means possible, requiring alignment and cross-functional communication. We are seeking an experienced Identity and Access Management (IAM) Engineer to lead the design, implementation, and operational maturity of Identity Governance and Administration (IGA) capabilities across the enterprise.
About the Role
This role focuses on securing and governing both human and non-human identities, including service accounts, managed identities, workload identities, automation accounts, API integrations, and AI agents. The IAM Engineer will be responsible for developing scalable identity governance processes, automating lifecycle management, enforcing least-privilege access, and reducing risk associated with service accounts and machine identities. This individual will work closely with Security, Infrastructure, Cloud Engineering, Application Owners, and Compliance teams to improve identity visibility, governance, and operational efficiency.
Responsibilities
- Implement and maintain enterprise Identity Governance and Administration (IGA) solutions.
- Design and manage access certification, access review, and entitlement management processes.
- Develop and optimize joiner, mover, and leaver workflows.
- Support role-based access control (RBAC) and access governance initiatives.
- Partner with business stakeholders to define access models and governance controls.
- Support audit, compliance, and regulatory requirements through reporting and attestation processes.
- Establish governance standards for service accounts across on-premises and cloud environments.
- Create and maintain inventory, ownership, classification, and lifecycle processes for service accounts.
- Reduce interactive use of service accounts and implement secure authentication methods.
- Design controls for credential rotation, privileged access management, and monitoring.
- Conduct periodic reviews to identify orphaned, stale, or over-privileged service accounts.
- Design and govern Azure Managed Identities and other cloud-native workload identities.
- Develop standards for application authentication and authorization.
- Partner with application teams to eliminate embedded credentials and secrets.
- Implement least-privilege access models for cloud workloads and services.
- Monitor and review workload identity permissions for excessive privilege.
- Define governance frameworks for AI agents, automation platforms, bots, APIs, and machine identities.
- Establish controls for identity creation, ownership, access reviews, and lifecycle management.
- Develop policies for agent-to-agent and agent-to-application access.
- Ensure visibility and traceability of non-human activity across enterprise systems.
- Partner with security teams to mitigate emerging risks associated with autonomous systems and AI-enabled workflows.
- Develop automation using PowerShell, Graph API, REST APIs, and cloud-native tooling.
- Automate provisioning, deprovisioning, access reviews, reporting, and governance workflows.
- Build integrations between IAM platforms, cloud providers, HR systems, ServiceNow, and enterprise applications.
- Continuously improve IAM operational efficiency through scripting and workflow optimization.
- Enforce least privilege and separation-of-duties controls.
- Support security assessments, audit requests, and compliance reviews.
- Develop metrics and reporting related to identity governance maturity.
- Participate in incident response and investigations involving identity-related risks.
- Maintain alignment with industry frameworks such as NIST, ISO 27001, SOC 2, and CIS controls.
Qualifications
- 5+ years of experience in Identity and Access Management, Identity Governance, or Security Engineering.
- Experience implementing or administering IGA platforms such as: Microsoft Entra ID Governance, SailPoint IdentityNow / IdentityIQ, Saviynt, Okta Identity Governance, Strong understanding of: RBAC, Access Certifications, Entitlement Management, Identity Lifecycle Management.
- Experience managing: Service Accounts, Managed Identities, Application Identities, API Credentials, Workload Identities.
- Proficiency with PowerShell, REST APIs, and automation scripting.
- Experience with: Microsoft Entra ID, Active Directory, Azure, AWS IAM, Google Cloud IAM.
- Experience with Privileged Access Management (CyberArk, BeyondTrust, Delinea, Microsoft PAM, etc.) preferred.
- Experience governing AI agents, automation platforms, and machine identities preferred.
- Knowledge of cloud-native authentication methods and secrets management preferred.
- Experience integrating IAM solutions with HR, ITSM, and enterprise application ecosystems preferred.
- Experience with Microsoft, SailPoint, CISSP, Security+ or relevant IAM certifications preferred.
What You Will Need To Succeed
- Location: Westbrook, Maine with a flexible hybrid requirement of only 8 days per month. Open to candidates in NH or MA who can come on site less frequently.
- Experience with Identity and Access Management, Identity Governance, or Security Engineering.
- Experience implementing or administering IGA platforms such as: Microsoft Entra ID Governance, SailPoint IdentityNow / IdentityIQ, Saviynt, Okta Identity Governance.
- Strong understanding of: RBAC, Access Certifications, Entitlement Management, Identity Lifecycle Management.
- Experience managing: Service Accounts, Managed Identities, Application Identities, API Credentials, Workload Identities.
- Proficiency with PowerShell, REST APIs, and automation scripting.
- Experience with: Microsoft Entra ID, Active Directory, Azure, AWS IAM, Google Cloud IAM.
- Experience with Privileged Access Management (CyberArk, BeyondTrust, Delinea, Microsoft PAM, etc.) preferred.
- Experience governing AI agents, automation platforms, and machine identities preferred.
- Knowledge of cloud-native authentication methods and secrets management preferred.
- Experience integrating IAM solutions with HR, ITSM, and enterprise application ecosystems preferred.
- Experience with Microsoft, SailPoint, CISSP, Security+ or relevant IAM certifications preferred.
What You Can Expect From Us
- Base annual salary target: $100,000 - $125,000 (flexible).
- Opportunity for annual cash bonus.
- Health / Dental / Vision Benefits.
- Day-One 5% matching 401k.
- Additional benefits including but not limited to financial support, pet insurance, mental health resources, volunteer paid days off, employee stock program, foundation donation matching, and much more!