Job Summary
The Senior Engineer, Identity & Access Management designs, implements, and operates secure, scalable identity solutions across the enterprise. This hands-on senior engineering role helps protect UFCU's digital ecosystem by ensuring that users and systems have appropriate access to resources at the right time. This role partners with Information Security, Platform Engineering, Product Engineering, Infrastructure, and Application teams to embed identity and access controls into UFCU's platforms, applications, and workflows.
The Senior Engineer, Identity & Access Management is an exempt position and reports to the Director, Information Security, and is part of the Information Security team at UFCU.
About UFCU
Our Credit Union was founded in 1936 and has grown to serve members throughout Texas and beyond. At UFCU, we are more than just a financial institution, and our people are more than just employees. We are dedicated to our purpose of empowering our Members to achieve financial success and build brighter futures.
In pursuit of our aspiration that UFCU is loved by millions of Members and built to thrive for generations, we are guided by our values:
- Purposefully Member-Obsessed: We are driven by a profound sense of empathy to deeply understand our Members’ needs and preferences, what brighter futures means to them, and the obstacles in their way. We act in our Members’ best interests, forever seeking to empower their financial success.
- Possibilities Reimagined: We are inspired to courageously experiment, learn, and iterate in pursuit of positive impact for our Members, UFCU, and coworkers. We challenge assumptions, embrace diverse perspectives, and make use of data and insights.
- Performance Excellence Rooted in Unwavering Integrity: We do the right thing, always. We champion teamwork, accountability, continuous improvement, and celebrate successful outcomes of others, fostering an inclusive environment of excellence and collaboration.
Essential Functions
Identity & Access Management Engineering and Architecture
- Design, implement, and support enterprise identity and access management solutions across workforce, Member, third-party, and non-human identities, including service accounts, workload identities, and artificial intelligence agents.
- Engineer secure authentication and authorization mechanisms, including single sign-on, multifactor authentication, passwordless authentication using Fast Identity Online 2 and passkeys, credential sharding, including conditional and risk-based access schemas.
- Implement and maintain role-based access control and attribute-based access control aligned with least privilege, least agency, and separation-of-duties principles.
- Support the key management program, including certificate lifecycle management, secrets management, and application programming interfaces and model context protocol (MCP) client and server access.
- Embed identity controls and secure protocols into continuous integration and continuous delivery pipelines, Infrastructure as Code, and modern application architectures.
Identity Governance, Privileged Access, and Threat Response
- Deploy and manage leading-edge Identity Governance and Administration platforms.
- Conduct access certifications for regulatory compliance and manage access-request workflows, entitlement management, and role-lifecycle governance.
- Develop centralized, cross-team processes and procedures related to all joiner, mover, and leaver activities.
- Implement and manage Privileged Access Management solutions using just-in-time and just-enough-access models; monitor and audit privileged activity and session recording.
- Deploy Identity Threat Detection and Response capabilities; monitor identity-related threats and anomalous behavior and integrate identity threat signals with security information and event management, security orchestration, automation, and response, and incident-response workflows.
Platform Resilience, Compliance, and Risk Management
- Design and maintain highly available identity and access management infrastructure with disaster-recovery capabilities, including redundancy, failover mechanisms, and break-glass access protocols.
- Align identity and access management controls with the National Institute of Standards and Technology Cybersecurity Framework 2.0 and applicable National Credit Union Administration, Gramm-Leach-Bliley Act, Federal Financial Institutions Examination Council, System and Organization Controls 2, and Payment Card Industry Data Security Standard requirements.
- Provide audit evidence, documentation, and control explanations for internal and external audits; continuously assess and improve identity and access management controls to reduce identity-related risk.
- Implement privacy-by-design principles in identity architectures, including data minimization, and support privacy impact assessments.
Operational Autonomy and Stakeholder Engagement
- Support the development and maintenance of a multi-year identity and access management strategy and roadmap aligned with organizational objectives, regulatory requirements, and Zero Trust maturity progression.
- Present identity risk posture, architecture decisions, and compliance status to the Director, Information Security, executive leadership, and audit committees using business-focused risk language.
- Lead and facilitate identity governance activities with stakeholders from Technology, Information Security, Risk Management, Human Resources, Legal, Compliance, and business units.
- Evaluate emerging identity technologies, conduct total-cost-of-ownership analysis for platform investments, and lead vendor selection, requests for proposal, and proof-of-concept evaluations.
- Partner with application, infrastructure, and product teams to design secure access patterns and educate teams on identity and access management best practices and regulatory requirements.
Other
- Adheres to all company policies, procedures, and business ethics codes.
- Completes required regulatory training as assigned.
- Maintains strict adherence to and compliance with all laws, rules, regulations, and internal controls specific to the role, including but not limited to Bank Secrecy Act, Anti-Money Laundering, USA Patriot Act, Office of Foreign Assets Control, and Fair Lending regulations.
Knowledge/Skills/Abilities
This is a senior-level role and requires an advanced level of knowledge, skill, and ability.
Knowledge
- Advanced knowledge of Identity Lifecycle Management and Zero Trust principles.
- Advanced knowledge of modern authentication and federation standards, including Security Assertion Markup Language, OAuth 2.0, OpenID Connect, mutual Transport Layer Security, JSON Web Token, and Fast Identity Online 2.
- Familiar with IAM requirements for Payment Card Industry Data Security Standard (PCI-DSS).
Skills
- Configuring and administering IAM platforms, such as Microsoft Entra, Okta, Sailpoint, and Savyint.
- Experience with administering conditional access and privileged access policies.
- Familiarity with supporting SecDevOps integration efforts for IAM controls validation.
- Scripting and automation using PowerShell, Python, and Microsoft Graph.
Abilities
- Ability to diagnose complex identity issues, evaluate technical tradeoffs, and develop secure, supportable solutions.
- Ability to drive change-management efforts for identity and access management adoption and transformation.
- Ability to lead and influence cross-functional stakeholders without direct authority.
- Ability to mentor and share knowledge with engineers, business partners, and executives.
Core Competencies
Demonstrating Member Obsession
- Puts themselves in the Member’s shoes
- Looks for friction points
- Makes it personalized and easy
Demonstrating Performance Excellence
- Sets standards for elevating excellence
- Ensures elevated quality
- Takes responsibility
- Conducts continuous improvement
Demonstrating Innovation
- Challenges current thinking
- Approaches change with a positive mindset
Experience
Minimum Requirements
- 4+ years experience in IAM architecture or engineering
- Experience managing non-human identities at-scale.
- Bachelor’s degree in computer science, cybersecurity, engineering, or a related field or equivalent years of experience
- Must be bondable.
Preferred Requirements
- Experience in financial services, fintech, credit unions, or another regulated industry.
- 2+ years in an operations or administration capacity
- Familiarity with Gramm-Leach-Bliley Act, National Credit Union Administration, and Federal Financial Institutions Examination Council cybersecurity guidance.
- Relevant certification, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Cloud Security Professional (CCSP).
Physical Demands
The physical demands described are representative of those that must be met by an employee, with or without accommodation, to successfully perform the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
Frequent
- While performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle or feel; reach with hands and arms; and talk or hear.
- Specific vision abilities required by this job include close vision, distance vision, peripheral vision, and ability to adjust focus.
- Employee will make extensive use of the telephone and virtual communications requiring the ability to explain complex information effectively and accurately.
Work Environment
The work environment characteristics described are representative of those an employee encounters while performing the essential functions of this job.
- This position is hybrid, requiring working onsite at UFCU Plaza in Austin, Texas approximately two days per week, with the remaining days worked remotely.
- This position may involve periodic stressful conditions.
- May occasionally require an adjusted work schedule, overtime, and evening or weekend hours.
- May occasionally move from one work location or branch to another.
- Public contact position, requiring appropriate professional appearance.
- Frequent computer use at a workstation of up to two hours at a time.
- The noise level in the work environment is usually moderate.
#INDUFCU
Equal Opportunity Employer/Protected Veterans/Individuals with DisabilitiesThis employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
Skills Required
- 4+ years of experience in identity and access management architecture or engineering
- Experience managing non-human identities at scale
- Bachelor's degree in computer science, cybersecurity, engineering, or a related field, or equivalent years of experience
- Must be bondable
- Experience in financial services, fintech, credit unions, or another regulated industry
- 2+ years in an operations or administration capacity
- Familiarity with the Gramm-Leach-Bliley Act, National Credit Union Administration, and Federal Financial Institutions Examination Council cybersecurity guidance
- Relevant certification such as CISSP, CISM, or CCSP
What We Do
University Federal Credit Union (UFCU) was chartered in 1936, and it has grown into a strong, healthy, and growing financial cooperative, serving more than 250 universities, associations, and employers in Central Texas, Harris County, and Galveston County. We’re guided by the credit union motto of “Not for profit, not for charity, but for service,” and you’ll see it reflected every day throughout our organization as we empower our Members to achieve financial success and brighter futures. Our Future Starts with U. Join a purpose-driven, digitally designed organization, where people are at the heart of everything we do. We’re redefining the future of financial services through digital transformation while empowering you with growth opportunities in a collaborative, innovative environment. Be part of a community that leads with empathy, integrity, and excellence. At UFCU, you shape your own growth, supported by leaders who invest in your development and a culture built on collaboration, inclusion, and being uniquely human. We welcome diverse perspectives and value curiosity and the drive to make a difference, no matter where you are in your career journey. We put our values into action through competitive pay, meaningful benefits, paid volunteer time, and award-winning workplace programs. As a Member-owned not-for-profit cooperative, we invest in tools and opportunities that empower our Members to achieve financial success and brighter futures. When you accept a job at UFCU, you join a community that cares deeply about its Members and about each other, keeping people at the heart of everything we do. UFCU is an Equal Opportunity Employer, including protected veterans and individuals with disabilities. Equal Housing Opportunity. Federally Insured by NCUA.
UFCU Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
