Identity and Access Management (IAM) Engineer
The job description
Tech stack. Okta or Microsoft Entra ID, SAML, OIDC, and OAuth2, SCIM provisioning, CyberArk or Delinea PAM, RBAC design, PowerShell or Python, access review tooling
About the role
You will run the identity fabric for a technology company where every access decision begins with who someone is and the health of the device they use. The IAM team owns single sign-on, lifecycle automation, privileged access management, and access reviews across hundreds of connected applications. You will automate provisioning, harden authentication, and make least privilege the default rather than the exception. This role matters because compromised credentials drive the majority of breaches, well-engineered identity is the highest-leverage defense the company possesses, and your automation determines whether access hygiene is effortless or a constant uphill struggle. You will measure success in revoked entitlements, closed gaps, and steadily shrinking attack paths. You will also own the access-review automation that continuously recertifies entitlements, so stale privileges expire on schedule instead of accumulating into standing risk.
What you will achieve
- Automate joiner-mover-leaver provisioning so access is granted and revoked within hours of HR system events instead of weeks of manual tickets.
- Roll out phishing-resistant MFA to 100 percent of the workforce, fully eliminating SMS-based and other phishable factors.
- Cut standing privileged access 70 percent through just-in-time elevation workflows paired with comprehensive session recording.
- Run quarterly access certifications where managers genuinely review and revoke unnecessary entitlements, hitting 95 percent completion.
- Reduce SSO integration time for new applications from weeks to days with standardized, well-documented integration patterns.
What you will bring
Must-haves
- 2 to 5 years in IAM engineering, identity administration, or related infrastructure roles.
- Deep hands-on experience with Okta, Entra ID, or a comparable enterprise identity provider platform.
- Strong grasp of SAML, OIDC, OAuth2, and SCIM protocols including their common real-world failure modes.
- Experience with privileged access management tools, vaulting patterns, and session isolation.
- Scripting ability in PowerShell or Python for provisioning automation, reporting, and bulk remediation.
- Understanding of RBAC design principles and least-privilege enforcement applied at enterprise scale.
- Patience for the long grind of identity hygiene: small wins compound into major risk reduction.
Nice-to-haves
- Experience with identity governance platforms such as SailPoint or Saviynt.
- Familiarity with CIEM tools for cloud entitlement and permission management.
- Knowledge of passwordless authentication standards like FIDO2 and passkeys.
- Background in directory services such as Active Directory or LDAP.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta