Senior IAM Engineer
Listed on 2026-08-09
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security & Data Protection
Senior Identity & Access Management (IAM) Engineer
The Senior Identity & Access Management (IAM) Engineer is responsible for the implementation, operation, and continuous improvement of identity and access management capabilities across the enterprise. This role leads the design and enforcement of identity controls to ensure secure, efficient, and compliant access to systems and data. The position works closely with security leadership, IT teams, and application owners to implement scalable identity solutions, strengthen authentication and access controls, and support evolving business and security requirements.
Knowledge/Skills Required/Preferred
- Personal:
Detail-oriented with a focus on accuracy and consistency in access control implementation. Strong sense of ownership and accountability for assigned responsibilities. Curious and proactive in identifying opportunities to improve security and processes. Willingness to learn and adapt to evolving technologies and security threats. Collaborative mindset with a focus on enabling the business securely. Demonstrates accountability for outcomes and ability to operate with limited direction.
Comfortable working through ambiguity and making sound decisions.
Professional:
Ability to work effectively with cross-functional teams including IS, application owners, and business stakeholders. Strong problem-solving and analytical skills, with the ability to diagnose and resolve complex issues. Ability to manage multiple priorities and deliver work in a structured and timely manner. Strong written and verbal communication skills including the ability to explain technical concepts to non-technical audiences. Ability to document processes, configurations, and standards clearly and concisely.
Ability to make informed technical decisions and provide guidance on identity-related implementations. Ability to influence stakeholders and drive adoption of security controls and standards.
Technical:
Strong understanding of identity and access management concepts including authentication, authorization, and federation. Knowledge of identity protocols such as SAML, OAuth 2.0, and OpenID Connect. Familiarity with Multi-Factor Authentication (MFA), Single Sign-On (SSO), and Conditional Access concepts. Understanding of identity lifecycle management including provisioning and deprovisioning processes. Familiarity with privileged access management (PAM) concepts and service account governance. Ability to troubleshoot identity and access issues across integrated systems.
Ability to design and implement access control strategies aligned to security requirements. Strong understanding of modern identity threats and mitigation techniques.
Education and Experience
- Education:
Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field (or equivalent experience).
Experience:
5+ years of experience in identity and access management or related security engineering roles. Hands-on experience with IAM platforms such as Microsoft Entra , Okta, SailPoint, or similar. Experience implementing SSO, MFA, and identity federation solutions. Strong understanding of authentication and authorization protocols (SAML, OAuth 2.0, OpenID Connect). Experience designing and implementing Conditional Access or equivalent access control policies. Familiarity with identity lifecycle management and access provisioning processes.
Familiarity with privileged access management (PAM) concepts and service account governance. Ability to troubleshoot complex identity and access issues across integrated systems. Related certifications:
Relevant certifications such as Microsoft Identity certifications, CISSP, CISM, or similar are preferred but not required.
Additional Criteria
- Schedule flexibility to allow for availability required during the CAP's non-business hours for activities such as resolution of critical issues or outages, managing off-hours maintenance, meetings with offshore teams, or other critical business needs. Travel is required when necessary; expected to be less than 10%. Candidates must reside within 75 miles of Northfield, IL and meet in-office requirements. Salary: $118,000 - $150,000.
Equal Opportunity Employer The CAP is an equal opportunity/affirmative action employer, providing equal employment opportunities (EEO) to all employees and qualified applicants for employment without regard to race, creed, color, religion, sex, gender identity and/or expression, national origin, age, ancestry, disability or genetic information, military status, sexual orientation, marital status, citizenship status, order of protection status, homelessness, or any other characteristic protected by federal law and the applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities.
Applicants have rights under Federal Employment Laws:
Family and Medical Leave Act Equal Employment Opportunity Employee Polygraph Protection Act.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).