> Markdown version of [/jobs/ext/1442949-it-security-identity-access-technical-leader](https://www.wearedevelopers.com/jobs/ext/1442949-it-security-identity-access-technical-leader). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Identity & Access Technical Leader - **Company:** Pitney Bowes Inc - **Location:** Shelton, CT, United States - **Experience:** Expert - **Salary:** $130,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Application Programming Interfaces (APIs), Artificial Intelligence, JIRA, User Authentication, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Identity and Access Management, Intrusion Detection and Prevention, System Center Configuration Manager, OAuth, OpenID, Public Key Infrastructure, Windows PowerShell, Azure Active Directory, Zero Trust Network Access, Salesforce.Com, Security Assertion Markup Language (SAML), SAP (Applications), User Provisioning Software, Enterprise Software Applications, Okta, Cyberark, Software Security, Microsoft InTune, Information Technology, Workday, Vulnerability Analysis - **Published:** July 25, 2026 - **Apply:** https://dejobs.org/x/x/5B9E067C3F8149ED83029E5E5ED77CDE/job/ ## About the Role * 7-12 plus years professional experience in IT and/or Cybersecurity with an Enterprise Identity Management Team * Deep expertise in IAM frameworks, Zero Trust, and modern identity protocols (SAML, OAuth, OIDC, SCIM). * Experience with enterprise scale IAM platforms, On Premise, and Cloud Platforms. * Strong understanding of cloud identity (Azure AD/Entra, AWS IAM, GCP IAM, SaaS and API). * Knowledge of security architecture, threat modeling, and identity attack vectors. * Significant demonstrated knowledge of Active Directory and Entra processes and tools to include patching, hardening, configuration, and risk management * Demonstrated communication skills to communicate, persuade, influence without authority, and handle challenging conversations * Significant demonstrated knowledge of Identity management processes and tools to include Active Directory, Entra ID, Intune, Dell OneIdentity, Semperis, CyberArk, SAP, Salesforce and Workday. * Demonstrated knowledge in recent advances in IAM technology. Preferred * Bachelor's Degree in Information Security, Computer Science or equivalent * Information Security Certifications such as CISSP, CRISC, CIMP and/or CISM Knowledgeable and experienced in: * Active Directory (Including Azure A/D Synchronization) * Entra ID (Including App Registration, Passwordless Authentication, Enterprise Application SSO and Conditional Access Policies)Intune * OKTA * Semperis * CyberArk * Zscaler AppTotal * Automation Tools including Task Scheduler and PowerShell * InfoBlox BloxOne * Microsoft PKI, NPS, SCCM Patching * Illumio * Microsoft Defender * Dell OneIdentity (Configuration, Monitoring, Migration and Implementation) * Microsoft NPS * JIRA Service Desk * Use of AI, Must be legally authorized to work in the US. Employer will not sponsor position for employment visa status now or in the future (ex. H-1B). ## Description A Security Identity & Access Technical Leader responsible for designing, implementing, and governing the enterprise-wide Identity and Access Management (IAM) program. You partner across security, infrastructure, HR, engineering, and business teams to build a modern, scalable identity ecosystem, winning together to deliver secure, seamless access experiences across the organization. You Will: * Develop and maintain the organization's Identity & Access Management (IAM) strategy, roadmap, and governance model, driving alignment and shared accountability across teams. * Architect and oversee solutions for security, authentication, authorization, privileged access, SSO, MFA, SaaS security posture, API access controls, conditional access policies, and lifecycle management, delivering excellence in secure design and execution. * Technically lead modernization efforts such as Zero Trust, passwordless authentication, identity automation, Attribute-Based Access Controls, AI-driven threat detection and response, identity models for AI agents, and continuous AI behavioral authentication, helping the organization move fast while staying secure. * Define standards for API security, including API identity and access controls, secure API key and token management, least-privilege access for machine identities, and monitoring and anomaly detection for API usage. * Establish secure patterns for API authentication and authorization, including OAuth, OIDC, and token lifecycle management. * Lead the design and operation of Privileged Access Management (PAM) solutions (CyberArk). * Ensure projects are delivered within scope, budget, and schedule, balancing speed with precision. * Lead a technical team supporting user access provisioning, deprovisioning, terminations, and password resets across multiple SaaS and on-premise applications (Dell OneIdentity, Salesforce, SAP, Workday), fostering collaboration and continuous improvement. * Perform regular audits to ensure security protocols are followed and risks are proactively addressed. * Ensure technical solutions comply with privacy laws and regulatory requirements. * Investigate and respond to irregularities in system access with urgency and rigor. * Establish metrics to ensure IAM solutions meet both security and business objectives. * Plan, test, and implement configuration changes efficiently and effectively. * Document IAM processes and procedures to enable consistency and scalability. * Escalate and resolve issues in a timely manner, maintaining a high standard of reliability and responsiveness., * Deliver challenging and unique opportunities to contribute to the success of a transforming organization * Offer comprehensive benefits globally (PB Live Well (https://careers.pitneybowes.com/global/en/pb-live-well) ) ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)