IAM & Enterprise Application Engineer
Coastal Community BankAbout the role
ABOUT US
Coastal is at the forefront of modern banking, combining strong financial infrastructure with cutting-edge Banking-as-a-Service (BaaS) and fintech enablement strategies. We support not only individuals with their personal banking needs; we also empower businesses by integrating modern banking technology that drives growth, flexibility, and innovation.
At Coastal, we think and move like entrepreneurs; focused on impact, speed, and continuous improvement. We believe in working smart, collaborating deeply, and building solutions that unlock real potential. If you're someone who thrives in a fast-moving environment, loves solving complex problems, and wants to help shape the future of banking, we’d love to meet you.
Check out our video here!
RequirementsOVERVIEW
As an IAM & Enterprise Applications Engineer, you will own the end-to-end lifecycle for our COTS and SaaS application portfolio, as well as engineering security-first principles into Coastal’s core identity services. You will design and enforce access models that enable the business while maintaining least privilege and separation of duties (SoD), automate joiner-mover-leaver processes, and define standard access profiles aligned to roles across Coastal. This role blends business operations insight with technical depth. You’ll partner with HR, Finance, Risk/Compliance, Security, and business leaders to translate operating needs into scalable identity governance, robust authentication/federation, and friction-light access workflows that provide proper controls for a high security environment without interfering with user productivity.
RESPONSIBILITIES TO INCLUDE
Identity Governance & Lifecycle Automation
- Design and operate identity lifecycle automation across directories, SaaS apps, and groups using HRIS/source-of-truth and SCIM/API integrations.
- Define and maintain standard access profiles by role, job family, and team.
- Build and run access review campaigns both for ad-hoc access and the composition of standard access profiles. Ensure evidence of access review campaign preparation and completion is audit-ready.
Administer Directory and IdP Services
- Configure new applications and federated trusts (SAML/OIDC) in IdPs.
- Administer authentication, session, conditional access, and device trust policies, ensuring systems are hardened against unauthorized access and common threats, such as credential stuffing and session theft.
- Develop integrations and scripts (Python, TypeScript, and PowerShell preferred, with knowledge of APIs and webhooks a necessity)
- Adopt Infrastructure-as-Code where supported (e.g., Terraform for Okta and Entra).
Enterprise Application Ownership, especially SaaS
- Lead the COTS/SaaS application lifecycle: intake & vendor assessment, PoC, secure configuration, go-live, ongoing administration, license/usage optimization, and deprecation.
- Partner with the business unit driving the usage of each application define, document, implement, and administer the application’s access model.
- Integrate enterprise applications with central identity services (directory/IdP), enabling JIT/SCIM provisioning and deprovisioning.
- Integrate applications into standard security-relevant operational processes, such as asset management, configuration hardening, data loss prevention, change management, and security monitoring.
Compliance, Monitoring & Evidence
- Map identity and application controls to FFIEC, GLBA, SOX, PCI-DSS, and NIST CSF v2.0 requirements.
- Centralize application logs and admin activity, partner with business units and the Security Operations team to develop monitoring, and coordinate with Security Operations for incident response and forensics when required.
- Prepare audit evidence packages (config exports, campaign artifacts, approvals) and lead remediation of exceptions.
QUALIFICATIONS
Must-have a blend of business operations understanding and technical expertise. Demonstrated experience in several of the following:
- Identity Governance & Administration (e.g., Okta IGA/Workflows, SailPoint), directory/IdP (e.g., Entra ID, Okta).
- SSO & federation standards (SAML, OIDC, OAuth 2.0), MFA/conditional access, device trust.
- HRIS/ITSM integration (e.g., Workday/UKG/BambooHR; ServiceNow/Jira) and SCIM/JIT provisioning.
- RBAC/ABAC design, role mining, separation of duties modeling for financial/operational functions, p
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s