Remote - Lead IAM Engineer
Data Analysis IncorporatedAbout the role
About Us
Data Analysis Incorporated (DAI) is the controlling entity of the O’Neil family of businesses. DAI and its subsidiaries operate in diverse industries worldwide, including global equity markets, health care, financial services, digital news, and insurance. Our global footprint allows our teams to be responsive to customer needs in a timely and efficient manner. We are dedicated to using technology and innovation to bring change and growth to our businesses. We believe in a dynamic workplace, creating engaging, informative products and services that help our customers succeed. Integrity is an essential characteristic for our firms and our associates; if this describes you, please apply!
Summary
The Lead Identity and Access Management Engineer is responsible for designing, implementing, and continuously improving enterprise IAM platforms while providing technical leadership across authentication, authorization, identity governance, and lifecycle management. This role serves as the IAM technical lead, defining and enforcing the operating model, including oversight of offshore administration processes to ensure secure, consistent, and auditable execution. The position owns identity security across both human and non-human identities, including workforce, service, application, and API identities. It also governs authentication mechanisms, token-based access, and service-to-service interactions across cloud and enterprise environments. Strong ownership of platforms such as PingID, Auth0, Duo, and Microsoft Entra ID is required, with a focus on modern authentication, MFA, SSO, and scalable identity governance. This includes governance of identity and access within AWS environments, including IAM roles, policies, and federated access.
Duties and Responsibilities
- Design, implement, and maintain IAM solutions across PingID, Auth0, Duo, Microsoft Entra ID, and AWS IAM environments.
- Serve as the technical lead for IAM, defining architecture, standards, and the overall operating model.
- Develop and enforce IAM processes and governance frameworks, including oversight of offshore operations, SLAs, and quality controls.
- Own identity lifecycle management (joiner, mover, leaver), including automation of provisioning and deprovisioning.
- Lead identity governance efforts, including access reviews, RBAC/ABAC models, and compliance with regulatory requirements.
- Manage authentication and access controls, including SSO, MFA, conditional access, privileged access, and non-human identities (APIs, service accounts).
- Design, implement, and govern AWS IAM including roles, policies, permission boundaries, and identity federation.
- Manage AWS IAM roles for human and non-human identities, including service roles, cross-account access, and workload identities.
- Implement and enforce least privilege access within AWS through policy design and role scoping.
- Integrate AWS IAM with enterprise identity providers (Entra ID, Auth0) for federated access and SSO.
- Govern access to AWS resources including management of access keys, role assumption, and temporary credentials.
- Define and enforce controls for AWS service identities, including Lambda, EC2, and container-based workloads.
- API / Token / Secrets
- Align AWS IAM roles and temporary credential usage with token lifecycle and secrets management strategies.
- Priviledged Access Management
- The role includes ownership of cloud identity platforms, including AWS IAM, with responsibility for managing identities, roles, and access controls across multi-cloud environments.
- Partner cross-functionally to integrate modern authentication protocols (SAML, OAuth, OIDC, SCIM), drive automation, support audits, and mentor IAM team members.
Qualifications & Requirements
Required Education, Experience, Certification/Licensure
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or related technical field, or equivalent practical experience.
- 7+ years of experience in cybersecurity or IT, with at least 5 years focused on Identity and Access Management.
- Demonstrated hands on experience with PingID, Auth0, Duo, and Microsoft Entra ID.
- Proven experience designing and operating IAM programs, including governance, lifecycle management, and offshore operating models.
- Experience managing both human and non-human identities including service accounts, API identities, and application identities.
- Strong understanding of authentication and authorization protocols including SAML, OAuth 2.0, OIDC, LDAP, and Ker
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s