- Company Name
- Vigilant Violet LLC
- Job Title
- Identity & Access Management (IAM) Engineer
- Job Description
-
Job Title: Identity & Access Management (IAM) Engineer
Role Summary: Design, implement, and maintain secure, scalable IAM solutions across cloud and hybrid environments, ensuring seamless user experiences while meeting security and compliance requirements.
Expectations: Deliver robust IAM architecture, manage identity lifecycle, support privileged access, automate workflows, and collaborate with cross‑functional teams to align IAM strategies with business objectives and regulatory frameworks.
Key Responsibilities
- Design, configure, and deploy IAM solutions (SSO, MFA, federation, identity governance).
- Manage identity lifecycle (provisioning, deprovisioning, access reviews, entitlements) in on‑prem and cloud settings.
- Administer directory services (AD, Entra ID, LDAP) and facilitate hybrid identity integration and migrations.
- Implement and support PAM platforms (CyberArk, BeyondTrust, Delinea, HashiCorp Vault).
- Collaborate with stakeholders to define IAM requirements, integrate solutions, and document policies/workflows.
- Maintain IAM infrastructure for reliability, scalability, and resiliency.
- Automate IAM processes using scripting/orchestration (PowerShell, Python, APIs, Terraform).
- Ensure alignment with security best practices, Zero Trust, and regulatory standards (SOX, HIPAA, PCI‑DSS, GDPR, NIST, ISO 27001).
- Participate in audits and security assessments related to IAM.
- Stay current with emerging IAM trends (passwordless, identity orchestration).
Required Skills
- 5+ years in IAM or related security domains.
- Strong grasp of identity lifecycle management, RBAC, credential management, and identity governance.
- Proficiency with IAM platforms (Okta, Microsoft Entra ID, Ping Identity, ForgeRock, etc.).
- Experience with cloud IAM (AWS IAM, GCP IAM, Azure AD Conditional Access).
- In-depth knowledge of authentication & directory protocols (SAML, OIDC, OAuth 2.0, SCIM, LDAP, Kerberos).
- Hands‑on with privileged access solutions (CyberArk, BeyondTrust, Delinea, Vault).
- Ability to automate with PowerShell, Python, APIs, Terraform.
- Excellent communication, documentation, and project collaboration skills.
Required Education & Certifications
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or equivalent experience.
- Preferred certifications: CISSP, CISM, CISA, Microsoft Certified: Identity & Access Administrator, Okta Certified Professional, Ping Certified Engineer, CyberArk Certified Trustee.