Identity and Access Management Engineer- Senior Consultant
Crowe · New York, NY · Yesterday
Engineering$81k–$159k/yrFull-time
About the role
At Crowe, you can build a meaningful and rewarding career. With real flexibility to balance work with life moments, you’re trusted to deliver results and make an impact. We embrace you for who you are, care for your well-being, and nurture your career.
Responsibilities
- Design and implement IAM solutions across cloud (Azure, AWS, GCP), on-premises, and hybrid environments.
- Build and integrate IAM platforms with enterprise applications, directories, APIs, and DevOps pipelines.
- Support implementation of modern identity and authorization platforms, including fine-grained authorization and entitlement visibility solutions.
- Develop and guide API-driven integrations between IAM platforms and enterprise systems.
- Support onboarding and adoption of IAM and authorization capabilities, including requirements gathering, solution configuration, and deployment activities.
- Implement identity governance capabilities, including provisioning, access reviews, and privileged access controls.
- Provide guidance on authentication and authorization approaches (e.g., SSO, MFA, passwordless, RBAC, ABAC).
- Evaluate and support implementation of IAM technologies and tools (e.g., Entra ID/Azure AD, SailPoint, Saviynt, CyberArk, Ping Identity, Okta, or similar).
- Conduct IAM-related assessments, including control evaluations, configuration reviews, and remediation support.
- Support alignment with cybersecurity frameworks and regulatory requirements (e.g., NIST, ISO, CIS).
- Collaborate with cross-functional teams including security, cloud, application development, and risk/compliance.
- Contribute to broader cybersecurity engagements, including risk assessments and security program maturity efforts, as needed.
- Participate in client workshops, knowledge transfer sessions, and enablement activities.
Requirements
- Bachelor’s degree in Information Systems, Computer Science, Cybersecurity, Engineering, or related field.
- 4–7 years of experience in IAM, cybersecurity engineering, or related roles (consulting or industry).
- Experience implementing IAM solutions across cloud and/or hybrid environments.
- Strong knowledge of authentication and federation standards (OAuth2, OIDC, SAML, SCIM, LDAP).
- Experience with identity governance, provisioning, and access management processes.
- Hands-on experience with IAM tools such as Entra ID (Azure AD), SailPoint, Saviynt, CyberArk, Ping Identity, Okta, or similar.
- Experience with API-based integrations and identity data flows (e.g., REST APIs, JSON, SCIM).
- Familiarity with scripting or automation (e.g., Python, SQL, or similar) to support integrations and data analysis.
- Understanding of non-human identities (e.g., service accounts, APIs, workloads, AI agents) and their role in modern IAM environments.
- Strong analytical and problem-solving skills.
- Strong communication skills and ability to work directly with clients and technical teams.
Qualifications
- Preferred Qualifications:
- Experience supporting IAM implementations, onboarding efforts, or platform integrations.
- Experience in regulated industries (e.g., financial services, healthcare, government).
- Familiarity with AI/automation in cybersecurity or identity governance.
- Familiarity with workflow and governance platforms (e.g., ServiceNow) supporting identity-related processes such as access requests, approvals, and compliance workflows.
- Relevant certifications (e.g., vendor IAM certifications, progress toward CISSP/CISM).