Lead Identity & Access Management

Reposted 9 Days Ago
Be an Early Applicant
Long Island, AL, USA
In-Office
155K-172K Annually
Senior level
Financial Services
The Role
The IAM Lead Engineer will oversee identity and access management processes, handle risk-based access control, and ensure secure data practices while collaborating with security teams.
Summary Generated by Built In

Become an everyday champion — and build a career where your impact fuels financial progress.


What We Do

CardWorks Financial Group is a diversified financial services platform building ethical solutions across credit, lending, and the full customer lifecycle. Through our family of companies, CardWorks Financial Group tackles the complex challenges that larger financial institutions leave behind. We’re embedded throughout the credit card ecosystem as a lender, servicer, and merchant acquirer.


Who We Are

  • Merrick Bank: The bank that builds
  • CardWorks Servicing: One partner, total performance
  • Carson Smithfield: Resolution with respect

With nearly 40 years of operating history, our track record is solid: disciplined in downturns and built to accelerate in recovery. The CardWorks Financial Group companies take precise approach in complex markets, as a top three non-prime focused general purpose card issuer and a top fifteen U.S. merchant acquirer. 


Our team tackles the industry’s most complex credit and payment challenges. And we believe that excellent work starts with a team that feels supported, respected, and empowered to grow.

CardWorks Servicing, LLC provides end-to end operational servicing functions for credit cards, secured cards, and installment loans.  We service consumer and small business loans across the credit spectrum and offers backup servicing and due diligence services to capital providers and trustees.


Founded in 1997, Merrick Bank is an FDIC®-insured financial institution headquartered in South Jordan, Utah, with over $10 billion in assets. A wholly owned subsidiary of CardWorks Financial Group, Merrick Bank serves roughly five million cardmembers and more than 100,000 merchant customers, offering credit cards, recreational loans, deposit accounts, merchant services and bank sponsorships to consumers and businesses.

Carson Smithfield, LLC provides a variety of post-charge-off debt recovery services, including digital self-service, IVR, live agent, and external agency management.

Position Summary:

The Identity and Access Management (IAM) Lead Engineer will work in the Merrick Bank and CardWorks security team. They will responsible for day-to-day activities regarding identity and access creation, risk-based access control, attribute-based access control, role-based access control, privileged access management, access modifications, and access terminations. They will be the primary contact for support of tools within the information security team from an IAM perspective. 

The IAM Lead Engineer will design solutions, engineer integrations, set up processes, provide reporting, instruct other teams on said processes and integrations, and manage tools and data. 

They implement, operate, monitor, and improve information security processes and systems that protect the companies’ data, customers, and computer systems from business disruption, data/identity compromise, cyber fraud, and regulatory criticism.

Essential Functions:

Privileged Access Management (PAM) Tool Ownership & Administration 

Expectation: Serves as the primary engineer responsible for the PAM platform’s daily function, configuration, and reliability. 

  • Administer access to the PAM platforms, including onboarding users, roles, and entitlements within the tools 

  • Configure privileged access workflows, credential vaulting, rotation, session controls, and integrations 

  • Monitor PAM system performance, availability, errors, and audit logs 

  • Troubleshoot and remediate PAM‑related issues affecting access, automation, or integrations 

  • Partner with business and infrastructure teams to onboard new privileged use cases into PAM 

 

IAM Platform Support & Engineering Enablement 

Expectation: Serves as the primary engineer responsible for the PAM platform’s daily function, configuration, and reliability. 

  • Be the day to day technology owner of identity governance, lifecycle, and authentication platforms by leading:  

  • Troubleshooting 

  • Integration validation 

  • Operational execution 

  • Execute IAM tasks according to established processes and approvals 

  • Lead application and service integrations with IAM tooling 

  • Utilize scripting, APIs, and automation to improve IAM operational efficiency 

  • Assist with configuration changes and platform enhancements under established governance 

 

Detective IAM Controls & Security Operations Support 

Expectation: Actively supports monitoring, investigation, and response activities related to IAM security signals. 

  • Support detective IAM controls, including logging, alerting, and access review evidence collection 

  • Configure and monitor IAM and PAM log activity for anomalous or unauthorized behavior 

  • Lead identity‑related investigations, incidents, and penetration testing efforts 

  • Gather and analyze IAM and PAM data for audits, incident response, and forensic activities 

  • Collaborate with security teams during access‑related security events to assess impact and remediate issues 

 

Collaboration, Documentation & Continuous Improvement 

Expectation: Operates as a dependable engineering partner who improves IAM services through execution and feedback. 

  • Collaborate with application, infrastructure, and security teams and drive projects to implement standardized IAM and PAM practices 

  • Provide IAM and PAM design input as part of discussions based on operational experience 

  • Document configurations, procedures, troubleshooting steps, and known issues 

  • Create and disseminate operational metrics, observations, and improvement recommendations 

  • Identify recurring issues and propose pragmatic improvements to tooling or processes 

Education and Experience 

  • 8+ years of experience in Identity & Access Management, Information Security, Cybersecurity Engineering 

  • Hands‑on experience architecting and engineering IAM solutions in large, complex environments. 

  • Technical knowledge of IAM concepts including authentication, authorization, federation, directory services, identity lifecycle, access governance, and privileged access. 

  • Strong experience with at least several of the following technologies/tools:  

  • Delinea / Thycotic / Centrify 

  • Azure AD / Entra ID 

  • Active Directory, Group Policy, Kerberos, LDAP, Windows Server 

  • SSO, SAML, OAuth, OIDC 

  • Automation/Scripting: PowerShell, Python 

  • Experience with the following preferred but not required: 

  • SailPoint Identity Security Cloud (ISC) 

  • Microsoft Identity Products (MIM PAM, PIM, etc.) 

  • Experience working in regulated industries preferred (financial services, healthcare, etc.). 

  • Bachelor’s degree in Computer Science, Information Systems, or related field preferred. 

  • Preferred certifications: CISSP, CISM, Microsoft Identity certifications, or vendor certifications (SailPoint, Delinea). 

 

Summary of Qualifications 

  • Ability to support integrations into Delinea, SailPoint, and Azure AD/Entra ID with a strong skill set for API development and integration. 

  • Ability to analyze, interpret, and correct data inconsistencies, errors, gaps, and inaccuracies for impact. 

  • Strong understanding of IAM principles, including details for least privileged, joiner, mover, and leaver operations. 

  • Strong understanding of workflows from systems of record through many different layers of IAM to application use. 

  • Strong understanding of Azure AD, including lifecycle management for all account types. 

  • Strong knowledge of AWS. 

  • Knowledge of client-server applications, multi-tier web applications, relational databases, and cloud IAM and security tools. 

  • Strong understanding of SSO, OAuth, OpenID, and SAML. 

  • Experience with Workday integrations. 

Ideally, the qualified candidate will work at the following location(s): Woodbury, NY; Pittsburgh, PA. A hybrid work model or fully remote model can be considered based on hiring manager decision and priorities of the role.

 

The salary range for this position, if located in NY Metro/NY State is $154,564 to $171,738. However, please note that the salary range will vary for other geographic areas.

#INDHP

Our Employee Value Proposition

  • Competitive Pay, including a Bonus Target or Variable Pay Incentive Program 
  • Benefits Package -Medical, Dental, and Vision (plus much more) 
  • 401(k) Plan with Company Match 
  • Short- & Long-Term Disability 
  • Wellness Programs 
  • Group Life and AD&D Insurance 
  • Paid Vacation, Sick Days and bank Holidays 
  • Employee Engagement Activities including Employee Appreciation Day, DEI Employee Resource Groups, Corporate Social Responsibility, Service Recognition


We offer a total rewards package comprised of a competitive base rate of pay, variable pay incentive programs based on the role, and a comprehensive benefit suite.  Offered rates of pay are determined based on job-related knowledge, relevant experience, skills, certifications, and geographic location.


We are proud to be an equal opportunity employer. All qualified applicants will receive consideration without regard to age, race, color, sex, or gender identity/expression (including pregnancy, childbirth, transgender status, or sexual orientation), religion or creed, ancestry, citizenship, national origin, disability, military or veteran status, marital status, genetic information, or any other characteristic protected by applicable law.

 

We do not tolerate discrimination, harassment, or retaliation. Employment decisions are based solely on qualifications, merit, and business needs. Everyone is welcome here, and we hire based on your ability to do the job, not any protected characteristics.

 

If you need help or reasonable accommodation during the application or hiring process, please let your TA Partner know.


Skills Required

  • 8+ years of experience in Identity & Access Management, Information Security, Cybersecurity Engineering
  • Hands-on experience architecting IAM solutions in large environments
  • Technical knowledge of IAM concepts including authentication, authorization, and identity lifecycle
  • Strong experience with Delinea, Azure AD, Active Directory, SSO, OAuth
  • Bachelor's degree in Computer Science, Information Systems, or related field preferred
  • Preferred certifications: CISSP, CISM, Microsoft Identity certifications
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Woodbury, NY
730 Employees
Year Founded: 1987

What We Do

Cardworks is one of the largest privately held providers of end-to-end operational servicing and support functions for credit card and installment loan products in North America. As a leading consumer firm, we service our consumer and small business loan clients across the credit spectrum, from super-prime to non-prime, and provide comprehensive support to bank and non-bank lenders in the United States and Canada. Our management expertise and customized servicing solutions enable banks and financial institutions to mitigate risk, increase profitability, and support their customers. Cardworks is also the parent of Merrick Bank Corporation, a top-15 issuer of credit cards, top 15 merchant acquiring bank, and leader in the recreational vehicle lending industry. As a CardWorks employee, you are at the very heart of all that we do. Our corporate success is based on your contributions. The most valuable resource we have at CardWorks is our employees. Each individual has an impact on how well we execute and on whether we achieve our enterprise objectives

Similar Jobs

HiBob Logo HiBob

Product Support Specialist

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
United States
1350 Employees
62K-75K Annually

Domino Data Lab Logo Domino Data Lab

Team Lead

Artificial Intelligence • Machine Learning
Easy Apply
Remote or Hybrid
US
200 Employees
175K-220K Annually

Domino Data Lab Logo Domino Data Lab

Staff Software Engineer

Artificial Intelligence • Machine Learning
Easy Apply
Remote or Hybrid
US
200 Employees
200K-250K Annually

Domino Data Lab Logo Domino Data Lab

Solutions Engineer

Artificial Intelligence • Machine Learning
Easy Apply
Remote or Hybrid
US
200 Employees
200K-250K Annually

Similar Companies Hiring

Granted Thumbnail
Mobile • Insurance • Healthtech • Financial Services • Artificial Intelligence
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
31 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account