Senior Identity and Access Engineer

Morgan, Lewis & Bockius LLP
Miami, FL, United States
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Active Directory Microsoft Azure Cloud Computing Identity and Access Management JSON Lightweight Directory Access Protocols (LDAP) OAuth Object-Oriented Software Development Windows PowerShell Role-Based Access Control Openid Connect Zero Trust Network Access
+9 more
Security Assertion Markup Language (SAML) Software Systems SQL Databases Systems Integration Enterprise Software Applications Cyberark Multi-Cloud HybridCloud SailPoint

Job description

  • Respond to strategies provided by the Architecture and Engineering team and its management for implementation and oversight and will be called upon to resolve the highest-level technical issues. In addition, this person will partner with applicable teams to ensure secure, scalable, and compliant identity services.
  • Develop innovative IAM strategies and take ownership of these through all phases.
  • Deliver enterprise-wide IAM, identity governance, and authentication solutions in a hybrid cloud capacity.
  • Design and implement lifecycle management automation for joiner, mover and leaver scenarios.
  • Implement role-based access control (RBAC) and apply the concept of least-privilege.
  • Provide programmatic solutions to include PowerShell, JSON, SQL, LDAP, and object-oriented languages for IAM systems.
  • Collaborate with other IAM team members on system design, architecture, and strategies to provide high levels of customer satisfaction.
  • Integrate enterprise applications for SSO and set up provisioning/offboarding.
  • Lead key meetings including technical, cross-functional, and stakeholder meetings.
  • Ensure Enterprise services and servers remain operational and monitor Active Directory, EntraID, and IAM services.
  • Provide after-hours support as needed to address incidents, system maintenance.
  • Create and maintain architecture and documentation for IAM systems.
  • Represents the team during the audit and ISO 27001 certification process.
  • Participate in on-call support rotation.

Requirements

  • A bachelor’s degree from a four-year college or university.
  • 5 years of hands-on experience in Identity and Access Management / Identity Governance engineering roles.
  • 5 years of experience with Cloud technologies (Azure, AWS, GCE) in a hybrid/multi-cloud identity environment.
  • Solid understanding of identity federation protocols (SAML, OAuth, OpenID Connect) and access governance concepts.
  • Problem-solving and analytical skills; ability to handle complex, time-sensitive incidents.
  • Excellent communication skills and ability to collaborate across technical and non-technical stakeholders., * Expertise in MS Active Directory (design, administration, Group Policy, replication, trusts, privileged access).
  • Proficiency with MS Entra ID (conditional access, PIM, hybrid identity, SSO/MFA, entitlement management, access reviews).
  • Advanced PowerShell scripting skills for automation, reporting, integrating, and administration of AD/Entra ID/SailPoint environments.
  • Experience implementing and supporting SailPoint (Identity Now, IdentityIQ, or Identity Security Cloud), including custom workflows, rules, transforms, connectors, certifications, and integrations.
  • SailPoint Certified IdentityIQ Engineer / IdentityNow Administrator is preferred.
  • Familiarity with security frameworks (NIST, Zero Trust, ISO 27001); compliance requirements (SOX, GDPR, HIPAA, etc.); PAM tools (e.g., CyberArk, Delinea) are a plus.
  • Core back-end technologies (Microsoft Windows 2019 Server and above, Varonis, LDAP, Cloud Identity solutions, and related IAM software solutions), ISO 27001 principles.

About the company

Morgan, Lewis & Bockius LLP, one of the world’s leading global law firms with offices in strategic hubs of commerce, law, and government across North America, Asia, Europe, and the Middle East, is seeking to hire a Sr. Identity and Access Engineer. Reporting to the Manager of Identity and Access Management, the Sr. Identity and Access Engineer provides mentoring to fellow engineers and contributes great things to the team with respect to knowledge transfer and advanced knowledge of Identity Access Management (IAM) engineering fundamentals.

This position will reside in either our Miami or Philadelphia office with a hybrid in-office/remote working schedule.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

2:08 min

Managing complex structures and corporate guidelines

Alexandra Petri · WWC 2023

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:03 min

Distinguishing type definition constructs from data validation routines

Clemens Vasters Clemens Vasters · WWC 2025

Videos

See all

Related articles

See all