IAM Senior Engineer

Responsibilities

1. IAM architecture & engineering
Design and implement IAM architectures, including:

  • Identity lifecycle management
  • Authentication and authorization models
  • Access governance and role-based access control (RBAC/ABAC)
  • Privileged access management (PAM)

Implement zero-trust aligned identity controls.
Develop system integrations using APIs, SSO, federation (SAML, OAuth, OIDC), and SCIM provisioning.

2. Identity lifecycle & automation
Automate joiner/mover/leaver (JML) workflows.
Build custom connectors, provisioning scripts, and automation pipelines using PowerShell and Windows scripting.
Optimize identity data flows between HR systems, directories, and applications.

3. Directory & authentication services
Manage enterprise identity directories (e.g., Active Directory, Entra ID, LDAP).
Implement MFA, passwordless authentication, and adaptive access policies.
Troubleshoot authentication issues across protocols: Kerberos, LDAP, SAML, OAuth 2.0, OIDC.

4. Access governance & compliance
Ensure adherence to access policies and regulatory requirements (ISO 27001, SOX, HIPAA, PCI, etc.).
Support access certifications and attestations.
Develop and maintain IAM standards, patterns, and playbooks.
Conduct periodic access reviews and risk analysis.

5. Privileged access management (PAM)
Administer PAM platforms (CyberArk, BeyondTrust, Delinea, etc.).
Implement vaulting, credential rotation, session monitoring, and just-in-time access.
Reduce standing privileges and legacy admin accounts.

6. Application integration
Onboard applications for SSO and provisioning using SAML, OAuth, and SCIM.
Work with developers and product teams to implement secure, modern identity patterns.

7. Incident response & troubleshooting
Investigate and resolve IAM-related security incidents.
Support SOC with identity-specific detection, alerts, and forensics.
Perform root-cause analysis for identity access failures.

Requirements

Technical skills

  • 6 to 8 years of experience in identity and access management (IAM) engineering.
  • Bachelor’s degree in computer science, information security, or a related field.
  • Strong expertise in:
    • IAM platforms: Okta, Azure AD/Entra ID, Ping, ForgeRock, SailPoint, etc.
    • Directory services (Active Directory, LDAP)
    • SSO/Federation (SAML, OIDC, OAuth)
    • SCIM provisioning
  • Experience designing and implementing enterprise IAM architectures, including identity lifecycle management, authentication and authorization models, access governance, and privileged access management.
  • Experience automating joiner/mover/leaver (JML) workflows and identity lifecycle processes.
  • Ability to build custom connectors, provisioning scripts, and automation pipelines using PowerShell and Windows scripting.
  • Experience with privileged access technologies, including administering PAM platforms such as CyberArk, BeyondTrust, or Delinea for vaulting, credential rotation, session monitoring, and just-in-time access.
  • Familiarity with zero trust principles.
  • Understanding of cloud platforms: Azure, AWS, or GCP.
  • Experience implementing MFA, passwordless authentication, and conditional/adaptive access policies.
  • Experience troubleshooting authentication issues across Kerberos, LDAP, SAML, OAuth 2.0, and OIDC.
  • Experience supporting access governance processes such as access reviews and access certifications/attestations.
  • Experience working in environments aligned with ISO 27001; experience with SOX, HIPAA, or PCI is a plus.

Soft skills

  • Strong problem-solving and analytical mindset.
  • Ability to communicate with both technical and non-technical stakeholders.
  • Experience leading technical projects and delivering enterprise-grade solutions.
  • Experience partnering with SOC, security, infrastructure, and application teams to deliver IAM integrations and resolve incidents.
  • Experience investigating and resolving IAM-related security incidents and performing root-cause analysis.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available