> Markdown version of [/jobs/ext/2430987-senior-iam-engineer](https://www.wearedevelopers.com/jobs/ext/2430987-senior-iam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior IAM Engineer - **Company:** College Of American - **Location:** Northfield, IL, United States - **Experience:** Expert - **Salary:** $118,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** User Authentication, Cyber Security, Multi-Factor Authentication, Identity and Access Management, OAuth, Openid Connect, Azure Active Directory, Security Assertion Markup Language (SAML), Single Sign-On, Okta, Information Technology, SailPoint - **Published:** August 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ffb82abef0ca07c8 ## About the Role * Detail-oriented with a focus on accuracy and consistency in access control implementation * Strong sense of ownership and accountability for assigned responsibilities * Curious and proactive in identifying opportunities to improve security and processes * Willingness to learn and adapt to evolving technologies and security threats * Collaborative mindset with a focus on enabling the business securely * Demonstrates accountability for outcomes and ability to operate with limited direction * Comfortable working through ambiguity and making sound decisions Professional: * Ability to work effectively with cross-functional teams including IS, application owners, and business stakeholders * Strong problem-solving and analytical skills, with the ability to diagnose and resolve complex issues * Ability to manage multiple priorities and deliver work in a structured and timely manner * Strong written and verbal communication skills including the ability to explain technical concepts to non-technical audiences * Ability to document processes, configurations, and standards clearly and concisely * Ability to make informed technical decisions and provide guidance on identity-related implementations * Ability to influence stakeholders and drive adoption of security controls and standards Technical: * Strong understanding of identity and access management concepts including authentication, authorization, and federation * Knowledge of identity protocols such as SAML, OAuth 2.0, and OpenID Connect * Familiarity with Multi-Factor Authentication (MFA), Single Sign-On (SSO), and Conditional Access concepts * Understanding of identity lifecycle management including provisioning and deprovisioning processes * Familiarity with privileged access management (PAM) concepts and service account governance * Ability to troubleshoot identity and access issues across integrated systems * Ability to design and implement access control strategies aligned to security requirements * Strong understanding of modern identity threats and mitigation techniques Education and Experience Education: * Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field (or equivalent experience) Experience: * 5+ years of experience in identity and access management or related security engineering roles * Hands-on experience with IAM platforms such as Microsoft Entra ID, Okta, SailPoint, or similar * Experience implementing SSO, MFA, and identity federation solutions * Strong understanding of authentication and authorization protocols (SAML, OAuth 2.0, OpenID Connect) * Experience designing and implementing Conditional Access or equivalent access control policies * Familiarity with identity lifecycle management and access provisioning processes * Familiarity with privileged access management (PAM) concepts and service account governance * Ability to troubleshoot complex identity and access issues across integrated systems Related certifications: * Relevant certifications such as Microsoft Identity certifications, CISSP, CISM, or similar are preferred but not required ## Description The Senior Identity & Access Management (IAM) Engineer is responsible for the implementation, operation, and continuous improvement of identity and access management capabilities across the enterprise. This role leads the design and enforcement of identity controls to ensure secure, efficient, and compliant access to systems and data. The position works closely with security leadership, IT teams, and application owners to implement scalable identity solutions, strengthen authentication and access controls, and support evolving business and security requirements. Specific Duties Identity & Access Management Engineering * Designs, implements, and maintains IAM solutions, including Single Sign-On (SSO), Multi-Factor Authentication (MFA), and identity federation * Configures and manages identity platforms (e.g., Microsoft Entra ID, Okta, or similar) * Implements and maintains Conditional Access policies aligned to organizational security requirements * Integrates applications with identity providers using standard protocols (e.g., SAML, OAuth, OpenID Connect) Access Control & Authentication * Establishes and enforces authentication and access control standards across the environment * Manages and continuously improves MFA strategy, including enforcement, exclusions, and user experience considerations * Supports secure onboarding of applications and services into centralized identity systems * Reviews and improves role-based and attribute-based access models where applicable Privileged Access & Non-Human Identity Management * Establishes and maintains controls for privileged access, including administrative roles and elevated permissions * Supports the implementation and ongoing improvement of Privileged Access Management (PAM) capabilities * Develops and enforces standards for service accounts and other non-human identities, including credential management and access restrictions * Identifies opportunities to reduce standing privilege and improve least privilege across systems and platforms * Partners with infrastructure and application teams to improve visibility and governance of non-human identities Identity Lifecycle & Governance * Supports identity lifecycle processes for both human and non-human identities, including provisioning, deprovisioning, and access changes * Identifies opportunities to improve automation and consistency in access management workflows * Partners with IT and business teams to ensure appropriate access controls are implemented and maintained * Contributes to the maturation of identity governance and privileged access capabilities over time Operational Support & Troubleshooting * Troubleshoots and resolves identity-related issues, including authentication failures and access inconsistencies * Supports incident response efforts involving identity or access-related events * Monitors IAM systems for reliability, performance, and security issues Collaboration & Continuous Improvement * Works with cross-functional teams to ensure identity services are integrated into new and existing systems * Evaluates and recommends improvements to IAM tools, configurations, and processes * Supports ongoing maturation of identity capabilities, including privileged access and identity governance * Stays current with evolving identity threats, technologies, and best practices Practice Ownership and Project Oversight * Owns and maintains security standards, control requirements, and guidance within the assigned security practice domain * Leads security scoping activities for enterprise initiatives involving controls within the assigned practice area * Defines security requirements, deliverables, and acceptance criteria for initiatives impacting the practice domain * Oversees alignment of implementation plans to established security standards * Collaborates with project managers and business stakeholders to ensure security milestones are defined, tracked, and documented * Escalates material deviations from established standards and supports formal risk documentation where appropriate Metrics & Reporting * Develops and maintains key performance indicators and metrics related to the assigned security practice domain * Provides periodic reporting on control maturity, risk posture, and initiative progress * Communicates practice-level performance insights to security leadership and relevant stakeholders, * Schedule flexibility to allow for availability required during the CAP's non-business hours for activities such as resolution of critical issues or outages, managing off-hours maintenance, meetings with offshore teams, or other critical business needs. * Travel is required when necessary; expected to be less than 10%. * Candidates must reside within 75 miles of Northfield, IL and meet in-office requirements. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026) - [The top 200 passwords of 2024 can be cracked in less than a second](https://www.wearedevelopers.com/magazine/502-the-top-200-passwords-of-2024-can-be-cracked-in-less-than-a-second)