Jobs and Careers
AC

Senior IAM Engineer

Acrisure
Oklahoma City, United Statesfull_timeVerifiedPosted 19 Mar 2026

About the role

Senior Identity and Access Management (IAM) Engineer Department: Information SecurityReports to: Senior Director, Information Security

Role Summary

You will be a hands-on IAM engineer who designs, automates, and scales secure identity and access controls across cloud and enterprise environments. You’ll build paved-road patterns for identity federation, least privilege, and just-in-time access — ensuring that authentication and authorization boundaries are strong, measurable, and frictionless.Success in this role means turning identity into an enabler: making secure access seamless for users, applications, and services while maintaining the highest standards of governance and compliance.

What You’ll Do (Core Responsibilities)

Architect and Automate Identity Foundations

  • Design and maintain secure-by-default IAM architectures across Azure AD / Entra ID, AWS IAM, and hybrid enterprise systems.
  • Develop paved road templates for access control patterns (e.g., federated access, role assumption, service accounts, workload identity).
  • Automate provisioning and deprovisioning pipelines using identity APIs, SCIM, and workflow orchestration tools (e.g., SailPoint, Okta Workflows, Azure Automation, or Terraform).
  • Implement policy-as-code for IAM guardrails (e.g., least-privilege enforcement, conditional access, MFA requirements, privilege expiration).

Access Control, Federation, and Governance

  • Engineer federated identity solutions for users, applications, and partners using SAML, OIDC, and OAuth2.
  • Manage conditional access policiesadaptive authentication, and passwordless strategies to balance security with user experience.
  • Define and enforce least privilege for human and machine identities across AWS, Azure, and SaaS platforms.
  • Integrate IAM governance with enterprise GRC systems to ensure traceability and audit readiness.
  • Partner with AppSec and Cloud teams to secure authn/z boundaries across applications, APIs, and services.

Privileged Access Management (PAM)

  • Implement and maintain privileged access vaulting and session control using platforms like CyberArk, BeyondTrust, Delinea, or Azure PIM.
  • Automate just-in-time elevation for administrative roles and enforce time-bound access approvals.
  • Continuously monitor and remediate excessive privileges across cloud and on-prem accounts.
  • Integrate PAM telemetry with SIEM/SOAR for threat detection and behavioral analytics.

Lifecycle and Risk Management

  • Automate joiner/mover/leaver processes and identity lifecycle events through API-driven workflows and HR system integrations.
  • Conduct periodic access reviews and certifications; deliver evidence for SOC2, PCI, and ISO audits.
  • Develop and maintain dashboards for leading indicators (automated provisioning rate, MFA coverage, stale accounts) and lagging indicators (MTTR for access removal, orphaned identities, failed recertifications).
  • Prioritize remediation through risk scoring (criticality × exposure × privilege depth) and ensure compliance with internal SLAs.

Detection and Response Integration

  • Collaborate with Security Operations to define identity-related detections (impossible travel, lateral movement, privilege abuse).
  • Correlate identity events with endpoint and cloud telemetry to identify compromised accounts.
  • Assist in incident response for identity-based breaches, credential the

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Acrisure

View company profile →