Senior IAM Engineer

Posted 4 Days Ago
Be an Early Applicant
Oklahoma City, OK, USA
In-Office
Senior level
Fintech • Software • Financial Services
The Role
Design and automate secure identity controls across environments, focusing on IAM solutions, access management, governance, and lifecycle automation to enable seamless and secure access for users and applications.
Summary Generated by Built In

Senior Identity and Access Management (IAM) Engineer
Department: Information Security
Reports to: Senior Director, Information Security
Role Summary
You will be a hands-on IAM engineer who designs, automates, and scales secure identity and access controls across cloud and enterprise environments. You’ll build paved-road patterns for identity federation, least privilege, and just-in-time access — ensuring that authentication and authorization boundaries are strong, measurable, and frictionless.
Success in this role means turning identity into an enabler: making secure access seamless for users, applications, and services while maintaining the highest standards of governance and compliance.
What You’ll Do (Core Responsibilities)Architect and Automate Identity Foundations
  • Design and maintain secure-by-default IAM architectures across Azure AD / Entra ID, AWS IAM, and hybrid enterprise systems.
  • Develop paved road templates for access control patterns (e.g., federated access, role assumption, service accounts, workload identity).
  • Automate provisioning and deprovisioning pipelines using identity APIs, SCIM, and workflow orchestration tools (e.g., SailPoint, Okta Workflows, Azure Automation, or Terraform).
  • Implement policy-as-code for IAM guardrails (e.g., least-privilege enforcement, conditional access, MFA requirements, privilege expiration).
Access Control, Federation, and Governance
  • Engineer federated identity solutions for users, applications, and partners using SAML, OIDC, and OAuth2.
  • Manage conditional access policiesadaptive authentication, and passwordless strategies to balance security with user experience.
  • Define and enforce least privilege for human and machine identities across AWS, Azure, and SaaS platforms.
  • Integrate IAM governance with enterprise GRC systems to ensure traceability and audit readiness.
  • Partner with AppSec and Cloud teams to secure authn/z boundaries across applications, APIs, and services.
Privileged Access Management (PAM)
  • Implement and maintain privileged access vaulting and session control using platforms like CyberArk, BeyondTrust, Delinea, or Azure PIM.
  • Automate just-in-time elevation for administrative roles and enforce time-bound access approvals.
  • Continuously monitor and remediate excessive privileges across cloud and on-prem accounts.
  • Integrate PAM telemetry with SIEM/SOAR for threat detection and behavioral analytics.
Lifecycle and Risk Management
  • Automate joiner/mover/leaver processes and identity lifecycle events through API-driven workflows and HR system integrations.
  • Conduct periodic access reviews and certifications; deliver evidence for SOC2, PCI, and ISO audits.
  • Develop and maintain dashboards for leading indicators (automated provisioning rate, MFA coverage, stale accounts) and lagging indicators (MTTR for access removal, orphaned identities, failed recertifications).
  • Prioritize remediation through risk scoring (criticality × exposure × privilege depth) and ensure compliance with internal SLAs.
Detection and Response Integration
  • Collaborate with Security Operations to define identity-related detections (impossible travel, lateral movement, privilege abuse).
  • Correlate identity events with endpoint and cloud telemetry to identify compromised accounts.
  • Assist in incident response for identity-based breaches, credential theft, and access abuse.
Minimum Qualifications
  • 5+ years of experience in Identity and Access Management engineering, including multi-cloud and hybrid enterprise environments.
  • Strong knowledge of Azure AD / Entra IDAWS IAM, and SAML / OIDC / OAuth2 / SCIM protocols.
  • Proficiency with identity automation using PowerShell, Python, Terraform, or APIs.
  • Experience with PAM platforms (CyberArk, BeyondTrust, or Azure PIM) and IGA tools (SailPoint, Saviynt, or Okta).
  • Familiarity with conditional accessMFA enforcement, and passwordless authentication in large-scale environments.
  • Understanding of zero trust architectureleast privilege design, and role-based access control (RBAC)principles.
  • Proven ability to interpret business access needs and translate them into secure, scalable IAM solutions.
Preferred Qualifications
  • Exposure to NIST 800-63CIS ControlsZero Trust Maturity Model, and NIST CSF.
  • Experience integrating IAM data with SIEM (e.g. Sentinel) and SOAR workflows.
  • Relevant certifications such as CISSPCISMAzure Security Engineer AssociateAWS Security – Specialty, or Okta Certified Professional.
Behavioral Competencies
  • Enablement first: You design access patterns that simplify compliance and make the secure option the default.
  • Automation mindset: You codify identity logic and guardrails, reducing manual effort and human error.
  • System thinker: You see identity as the connective tissue between applications, infrastructure, and users.
  • Risk translator: You clearly articulate the business impact of over-privilege and authentication weaknesses.
Department: Information Security
Reports to: Senior Director, Information Security
Role Summary
You will be a hands-on IAM engineer who designs, automates, and scales secure identity and access controls across cloud and enterprise environments. You’ll build paved-road patterns for identity federation, least privilege, and just-in-time access — ensuring that authentication and authorization boundaries are strong, measurable, and frictionless.
Success in this role means turning identity into an enabler: making secure access seamless for users, applications, and services while maintaining the highest standards of governance and compliance.
What You’ll Do (Core Responsibilities)Architect and Automate Identity Foundations
  • Design and maintain secure-by-default IAM architectures across Azure AD / Entra ID, AWS IAM, and hybrid enterprise systems.
  • Develop paved road templates for access control patterns (e.g., federated access, role assumption, service accounts, workload identity).
  • Automate provisioning and deprovisioning pipelines using identity APIs, SCIM, and workflow orchestration tools (e.g., SailPoint, Okta Workflows, Azure Automation, or Terraform).
  • Implement policy-as-code for IAM guardrails (e.g., least-privilege enforcement, conditional access, MFA requirements, privilege expiration).
Access Control, Federation, and Governance
  • Engineer federated identity solutions for users, applications, and partners using SAML, OIDC, and OAuth2.
  • Manage conditional access policiesadaptive authentication, and passwordless strategies to balance security with user experience.
  • Define and enforce least privilege for human and machine identities across AWS, Azure, and SaaS platforms.
  • Integrate IAM governance with enterprise GRC systems to ensure traceability and audit readiness.
  • Partner with AppSec and Cloud teams to secure authn/z boundaries across applications, APIs, and services.
Privileged Access Management (PAM)
  • Implement and maintain privileged access vaulting and session control using platforms like CyberArk, BeyondTrust, Delinea, or Azure PIM.
  • Automate just-in-time elevation for administrative roles and enforce time-bound access approvals.
  • Continuously monitor and remediate excessive privileges across cloud and on-prem accounts.
  • Integrate PAM telemetry with SIEM/SOAR for threat detection and behavioral analytics.
Lifecycle and Risk Management
  • Automate joiner/mover/leaver processes and identity lifecycle events through API-driven workflows and HR system integrations.
  • Conduct periodic access reviews and certifications; deliver evidence for SOC2, PCI, and ISO audits.
  • Develop and maintain dashboards for leading indicators (automated provisioning rate, MFA coverage, stale accounts) and lagging indicators (MTTR for access removal, orphaned identities, failed recertifications).
  • Prioritize remediation through risk scoring (criticality × exposure × privilege depth) and ensure compliance with internal SLAs.
Detection and Response Integration
  • Collaborate with Security Operations to define identity-related detections (impossible travel, lateral movement, privilege abuse).
  • Correlate identity events with endpoint and cloud telemetry to identify compromised accounts.
  • Assist in incident response for identity-based breaches, credential theft, and access abuse.
Minimum Qualifications
  • 5+ years of experience in Identity and Access Management engineering, including multi-cloud and hybrid enterprise environments.
  • Strong knowledge of Azure AD / Entra IDAWS IAM, and SAML / OIDC / OAuth2 / SCIM protocols.
  • Proficiency with identity automation using PowerShell, Python, Terraform, or APIs.
  • Experience with PAM platforms (CyberArk, BeyondTrust, or Azure PIM) and IGA tools (SailPoint, Saviynt, or Okta).
  • Familiarity with conditional accessMFA enforcement, and passwordless authentication in large-scale environments.
  • Understanding of zero trust architectureleast privilege design, and role-based access control (RBAC)principles.
  • Proven ability to interpret business access needs and translate them into secure, scalable IAM solutions.
Preferred Qualifications
  • Exposure to NIST 800-63CIS ControlsZero Trust Maturity Model, and NIST CSF.
  • Experience integrating IAM data with SIEM (e.g. Sentinel) and SOAR workflows.
  • Relevant certifications such as CISSPCISMAzure Security Engineer AssociateAWS Security – Specialty, or Okta Certified Professional.
Behavioral Competencies
  • Enablement first: You design access patterns that simplify compliance and make the secure option the default.
  • Automation mindset: You codify identity logic and guardrails, reducing manual effort and human error.
  • System thinker: You see identity as the connective tissue between applications, infrastructure, and users.
  • Risk translator: You clearly articulate the business impact of over-privilege and authentication weaknesses.

#Auris

    Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.


    Why Join Us:

    At Acrisure, we’re building more than a business, we’re building a community where people can grow, thrive, and make an impact. Our benefits are designed to support every dimension of your life, from your health and finances to your family and future.

    Making a lasting impact on the communities it serves, Acrisure has pledged more than $22 million through its partnerships with Corewell Health Helen DeVos Children's Hospital in Grand Rapids, Michigan, UPMC Children's Hospital in Pittsburgh, Pennsylvania and Blythedale Children's Hospital in Valhalla, New York.


    Employee Benefits

    We also offer our employees a comprehensive suite of benefits and perks, including:

    • Physical Wellness: Comprehensive medical insurance, dental insurance, and vision insurance; life and disability insurance; fertility benefits; wellness resources; and paid sick time.

    • Mental Wellness: Generous paid time off and holidays; Employee Assistance Program (EAP); and a complimentary Calm app subscription.

    • Financial Wellness: Immediate vesting in a 401(k) plan; Health Savings Account (HSA) and Flexible Spending Account (FSA) options; commuter benefits; and employee discount programs.

    • Family Care: Paid maternity leave and paid paternity leave (including for adoptive parents); legal plan options; and pet insurance coverage.

    • … and so much more!

    This list is not exhaustive of all available benefits. Eligibility and waiting periods may apply to certain offerings. Benefits may vary based on subsidiary entity and geographic location.


    Acrisure is an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, disability, or protected veteran status. Applicants may request reasonable accommodation by contacting [email protected].

    Final candidates will be required to complete post-offer verification processes related to the role and in accordance with applicable laws.


    California Residents: Learn more about our privacy practices for applicants by visiting the Acrisure California Applicant Privacy Policy.


    Recruitment Fraud: Please visit here to learn more about our Recruitment Fraud Notice.


    Welcome, your new opportunity awaits you.

    Top Skills

    Aws Iam
    Azure Ad / Entra Id
    Beyondtrust
    Cyberark
    Oauth2
    Oidc
    Okta
    Powershell
    Python
    Sailpoint
    SAML
    Scim
    SIEM
    Soar
    Terraform
    Am I A Good Fit?
    beta
    Get Personalized Job Insights.
    Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

    The Company
    HQ: Grand Rapids, Michigan
    3,983 Employees

    What We Do

    Acrisure is a global Fintech leader that combines the best of humans and high tech to offer multiple financial products and services to millions of businesses and individual clients. We connect clients to solutions that help them protect and grow what matters, including Insurance, Reinsurance, Cyber Services, Mortgage Origination and more. Acrisure employs over 16,000 entrepreneurial colleagues in 21 countries and has grown from $38 million to $4 billion in revenue in just over ten years. Our culture is defined by our entrepreneurial spirit and all that comes with it: innovation, client centricity and an indomitable will to win. Additionally, Acrisure is committed to making an impact in our communities by giving back, as seen by our partnerships with Helen Devos Children’s Hospital and UPMC Children's Hospital. Discover more at www.Acrisure.com.

    Similar Jobs

    MongoDB Logo MongoDB

    Security Engineer

    Big Data • Cloud • Software • Database
    Easy Apply
    Remote or Hybrid
    5 Locations
    5550 Employees
    118K-231K Annually
    In-Office or Remote
    25 Locations
    1988 Employees
    92K-127K Annually

    Wipfli Logo Wipfli

    Senior Manager, Accounting Advisory - Tribal Government Industry

    Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
    Remote or Hybrid
    United States
    3000 Employees
    142K-195K Annually

    Wipfli Logo Wipfli

    Senior Manager/Director, Tax - Insurance

    Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
    Remote or Hybrid
    United States
    3000 Employees
    142K-192K Annually

    Similar Companies Hiring

    Milestone Systems Thumbnail
    Software • Security • Other • Big Data Analytics • Artificial Intelligence • Analytics
    Lake Oswego, OR
    1500 Employees
    Fairly Even Thumbnail
    Software • Sales • Robotics • Other • Hospitality • Hardware
    New York, NY
    Kepler  Thumbnail
    Fintech • Software
    New York, New York
    6 Employees

    Sign up now Access later

    Create Free Account

    Please log in or sign up to report this job.

    Create Free Account