Information Security Identity & Access Management Engineer
Listed on 2026-09-14
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Systems Engineer
Overview
The Information Security Identity & Access Management (IAM) Engineer is responsible for engineering, implementing, and supporting enterprise identity and access capabilities that protect JFG systems and data through strong authentication, authorization, and access governance. Working under the direction of the Information Security Engineer & Operations Manager, this position focuses on Identity Lifecycle Management, Identity Governance & Administration (IGA), and Privileged Access Management (PAM) to ensure timely, appropriate, and auditable access aligned to business roles and the principle of least privilege.
The engineer partners cross-functionally with IT, architecture, HR, and business stakeholders to deliver scalable identity solutions that enable secure business operations. Consistent with industry trends, this role requires a broad, cross-functional skillset across IAM, security architecture & engineering, and data protection, rather than deep specialization in a single domain. The role contributes to the design and continuous improvement of zero trust-aligned access controls, ensuring integration with cloud, on-prem, and customer identity platforms.
This is an individual contributor role that may provide technical leadership and mentorship. Occasional off-hour and on-call support may be required. Less than 5% travel expected.
- Design, implement, and maintain enterprise IAM solutions, including identity lifecycle, authentication, authorization, and federation
- Engineer and operate Identity Governance & Administration (IGA) capabilities such as provisioning/deprovisioning, access certifications, and role-based access control (RBAC)
- Implement and support Privileged Access Management (PAM) controls including vaulting, session management, and least privilege enforcement
- Support both enterprise identity (EIAM) and customer identity (CIAM) solutions across cloud and hybrid environments
- Operate and enhance user access reviews (UARs) and certification processes to ensure appropriate access and audit compliance
- Maintain visibility and reporting on user access activity, entitlements, and privileged usage
- Partner with Risk and Audit functions to support controls testing, evidence collection, and regulatory requirements
- Collaborate with IT Architects to design scalable IAM architectures aligned to modern zero trust principles
- Integrate IAM capabilities with enterprise platforms (e.g., Microsoft Entra , SaaS applications, on-prem AD)
- Contribute to security architecture & engineering initiatives, ensuring identity is embedded into system designs
- Build and maintain automation for identity provisioning workflows, access enforcement, and reporting
- Develop and maintain runbooks, workflows, and standard operating procedures
- Drive continuous improvement through process optimization and measurable efficiency gains
- Partner with HR, IT, application owners, and business units to align access models to job functions (“need-to-know”)
- Act as a technical SME for IAM, translating security requirements into business-aligned solutions
- Demonstrate strong communication and stakeholder management skills, enabling adoption across non-technical teams
- Support and deliver IAM operational metrics, dashboards, and KPIs
- Contribute to program maturity improvements across Identity & Access Management services
- Provide technical leadership and mentorship to junior engineers or project team members
- Lead IAM-related initiatives or work streams to ensure delivery of Info Sec services
- Bachelor’s Degree in Information Security, Cybersecurity, Computer Science, Information Systems, or related field
- 5-8 years' experience
- Cybersecurity Certifications preferred:
Microsoft AZ-500, Security+,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).