Senior IAM Engineer
About the role
The Senior IAM Engineer is a senior individual contributor responsible for designing, implementing, and maintaining identity and access management solutions across the enterprise. This role ensures that access to corporate systems and applications is secure, efficient, and aligned with corporate policies. Additionally, this role will partner with IT, Security, and Application teams to enforce secure access patterns, automate identity lifecycle processes, and reduce operational risk. This role requires hands-on expertise, technical leadership, and the ability to influence cross-functional teams without direct reports.
Responsibilities
- Access Governance and Role Design:
- Develop new access governance processes in line with industry best practices.
- Design roles (RBAC), workflows, and certifications for implementation in IAM systems and Privileged Access Management (PAM) solutions.
- Define and control identification, authentication, and privileges in IAM systems.
- Identity Lifecycle & Access Management:
- Implement and maintain user provisioning, access modification, and de-provisioning based on joiner/mover/leaver status.
- Automate workflows to improve accuracy, efficiency, and compliance.
- Authentication & Authorization:
- Implement and maintain authentication methods (SSO, MFA, password policies).
- Partner with application and infrastructure teams to integrate access controls.
- Troubleshoot and resolve complex identity or access issues.
- System Configuration and Integration:
- Configure out-of-the-box connectors and write code for custom connectors within the IAM system.
- Configure SAML for third-party applications to integrate with the Identity Governance and Administration (IGA) system.
- Modernize application identity management for integration into the IAM system, coordinating closely with stakeholders.
- Privileged Access Management (PAM):
- Support PAM platform operations, including vault management, session monitoring, and policy enforcement.
- Ensure privileged accounts are properly controlled, monitored, and audited.
- Cross-Functional Collaboration:
- Partner with Security Operations, Application Security, and IT teams to ensure identity solutions meet security and business requirements.
- Advise stakeholders on secure access patterns and risk mitigation strategies.
- Participate in architecture discussions and provide technical guidance.
- Documentation and Reporting:
- Translate business processes and legacy processes into functionality within IAM systems.
- Create and maintain up-to-date documentation to support IAM solutions and their configuration.
- Develop user access/activity reports to support access recertification, business unit, and regulatory requests.
- Continuous Improvement:
- Recommend and implement enhancements to IAM tooling, policies, and processes.
- Identify opportunities to reduce manual effort and operational risk through automation.
- Training and Support:
- Provide training and support to internal teams and end-users on IAM processes and tools.
- Mentor and support other IAM engineers and IAM analysts.
- Review IT tickets to address and resolve access problems promptly.
- Risk Management:
- Limit security risks by setting access boundaries for accounts and restricting highly privileged access.
Requirements
- Bachelor's degree in computer science, technology, or a related field.
- 5 years working with an IGA solution (SailPoint, Saviynt, Okta) experience required.
- 5 years administrating Active Directory and/or Entra ID experience required.
- 2 years object-oriented programming (Java, C#, Python) or scripting (PowerShell) experience required.
- 2 years working with a Privileged Access Management suite (e.g., Entra PIM, CyberArk, PAM 360) experience required.
- 2 years planning and implementing advanced system administration tasks experience preferred, including hands-on involvement in setting up, configuring, and optimizing new systems to meet organizational needs.
- 2 years developing integrations that consume APIs (SOAP/RESTful) experience preferred.
- 2 years of customer-facing IT service experience preferred (e.g., Help Desk, Desktop Engineering).
- Demonstrate a genuine curiosity for understanding systems both independently and in relation to other interconnected systems.
- Exhibit a passion for problem-solving in ambiguous situations, including researching solutions or conducting independent testing.
- Deep understanding of IAM principles, methodologies, and solutions, including access control (role-based and discretionary), authentication, authorization, provisioning, approvals, and workflows.
- Excellent written, verbal, and presentation skills; ability to effectively explain complex technical concepts to both technical and non-technical stakeholders.
Employment visa sponsorship is unavailable for this position.
Benefits
- Competitive base salary and bonuses
- Hybrid work environment with the ability to work remotely 40 hours per month
- Comprehensive benefits package:
- Health, dental, and vision coverage
- 401(k) with company match
- Perks including employee discounts, financial wellness planning, tuition reimbursement, and more
- Access to the latest emerging technologies
- Culture of continuous education and technical training (and reimbursements for the same)
- Certified Great Place to Work and voted a 2019-2026 Computerworld Best Places to Work in IT
Schedule
Position based in Cincinnati, OH, Charlotte, NC, or Tampa, FL (relocation assistance provided).