Senior Information Security Engineer (IAM)
Model N
- Design, implement, and support IAM solutions including identity lifecycle management, authentication, authorization, and access governance.
- Provide senior-level support for user provisioning, deprovisioning, and access review processes.
- Configure and optimize SSO, MFA, conditional access, and federation services.
- Analyze access-related security events and support investigations in partnership with the SOC and other security teams.
- Design and maintain role models, entitlement structures, and privileged access workflows.
- Review and guide application and infrastructure integrations with IAM platforms using established standards.
- Lead automation efforts to reduce manual work and improve reliability across IAM and security processes.
- Contribute to and review security documentation, policies, standards, and audit materials.
- Partner with engineering and business teams to ensure secure access design for new and evolving technologies.
- Implement and support IAM capabilities across AWS, Okta, Entra ID, Active Directory, and SaaS platforms.
- Design and manage service accounts, application identities, and workload authentication models.
- Implement and support secrets management using KMS, Vault, and cloud-native solutions.
- Integrate IAM logging with SIEM platforms and help refine identity-focused detection and monitoring.
- Support audits, access certifications, and remediation of security findings.
Job Qualification
- 4 to 6 years of experience in information security, security engineering, or related technical roles.
- Strong hands-on experience with IAM platforms such as Active Directory, Entra ID, Okta, SailPoint, CyberArk, or similar technologies.
- Deep understanding of authentication and authorization concepts and protocols including SAML, OAuth, OIDC, LDAP, and Kerberos.
- Experience with scripting or automation using PowerShell, Python, or similar languages.
- Practical experience with identity governance, privileged access management, and access review processes.
- Solid understanding of security fundamentals, cloud security concepts, and zero trust principles.
- Experience supporting security or IAM in large, distributed, or hybrid environments.
- Background integrating cloud platforms such as AWS, Azure, or GCP with enterprise IAM systems.
- Exposure to DevOps or DevSecOps practices, API integrations, or workflow automation.
- Relevant certifications such as Microsoft Identity, Okta Professional, CISSP, or GIAC.