> Markdown version of [/jobs/ext/2536422-iam-engineer](https://www.wearedevelopers.com/jobs/ext/2536422-iam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Engineer - **Company:** New York Life Insurance Company - **Location:** United States - **Experience:** Expert - **Salary:** $124,000.0 - $177,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Active Directory, Artificial Intelligence, Amazon Web Services, User Authentication, Build Automation, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Information Systems, Data Security, Identity and Access Management, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Ping (Networking Utility), Windows PowerShell, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Software Engineering, Systems Integration, Scripting, Cloud Platform System, Cyberark, Software Security, HybridCloud, Pingfederate, Information Technology, Data Management, SailPoint - **Published:** August 21, 2026 - **Apply:** https://www.careerbuilder.com/job-details/senior-associate-iam-engineer-new-york-ny--420a41aa-e29f-40a5-af3d-c64646662088 ## About the Role * Bachelor's degree in Computer Science, Information Systems, or equivalent experience. * 10+ years of hands-on engineering experience across multiple IAM domains. * Strong knowledge of and experience with SailPoint, CyberArk, PingOne, PingFederate, Ping Directory, Entra and Active Directory. * Proven experience integrating IAM solutions in hybrid (cloud + on-premises) environments. * Familiarity with identity protocols such as SAML, OAuth 2.0, OIDC, SCIM, LDAP, SPIFFE, DCR, and PKCE. * Strong scripting skills (e.g., PowerShell, Python, Java) for automation and integration. * Understanding of IAM-related compliance and regulatory requirements (e.g., NYS DFS, NIST). * Ability to work effectively in a team-oriented, collaborative environment, with strong problem-solving skills. * Preferred Qualifications * Experience with cloud identity platforms (e.g., Azure AD, AWS IAM). * Exposure to Zero Trust architectures, modern authentication strategies, and AI-enabled security capabilities. * Prior experience in a large enterprise or financial services environment. * IAM vendor certifications (e.g., SailPoint IdentityNow Engineer, CyberArk Trustee/Defender, Ping Identity Certified Professional)., Amazon Web Services (AWS), Applications Security, Artificial Intelligence (AI), Authentication, Automation, Cloud Applications, Cloud Computing, Computer Science, Customer Experience, Financial Services, Hybrid Cloud, IAM - Information Assurance Management, Identify Issues, Identity Data Management, Information Technology & Information Systems, Information/Data Security (InfoSec), Java, LDAP (Lightweight Directory Access Protocol), Leading Edge Technology, LinkedIn, Microsoft Active Directory, Microsoft Windows Azure, Newsroom, OAuth, Problem Solving Skills, Process Development, Productivity Management, Python Programming/Scripting Language, Regulatory Compliance, Regulatory Requirements, Risk, Scripting (Scripting Languages), Security Assertion Markup Language (SAML), Software Engineering, Software as a Service (SaaS), Systems Administration/Management, Team Player, Technical/Engineering Design, U.S. National Institute of Standards and Technology (NIST), Volunteer Experience, Windows PowerShell ## Description The IAM Engineer will play a key role in designing, engineering, and maintaining NYL's Identity & Access Management solutions across all IAM domains: Identity Governance & Administration (IGA), Privileged Access Management (PAM), Directory Services, and Web Access Management (WAM). This role blends hands-on engineering with solution architecture, ensuring that IAM capabilities are robust, scalable, secure, and aligned with enterprise standards. The IAM Engineer will support both on-premises and cloud environments, working with a mix of commercial, SaaS, and custom platforms. Experience in SailPoint, CyberArk, Ping, Entra and Active Directory is strongly preferred. The ideal candidate will bring technical depth, a strong learning mindset, and genuine enthusiasm for advancing their craft. We are building the identity foundation for a more connected, AI-enabled, and technology-driven future so curiosity, adaptability, and readiness to embrace new capabilities will be essential. What You'll Do: * Engineer, configure, and maintain IAM solutions across IGA, PAM, Directory, and WAM domains. * Collaborate with architecture teams to design IAM solutions that integrate securely with on-premises and cloud applications (AWS, SaaS, hybrid models). * Develop and maintain workflows, connectors, policies, and scripts to automate identity lifecycle and access management processes. * Integrate IAM solutions with enterprise authentication and authorization frameworks, including MFA, passwordless authentication, and emerging NHI standards (e.g., SPIFFE, DCR, PKCE). * Partner with Information Security, Application, and Infrastructure teams to ensure IAM solutions meet security, compliance, and audit requirements. * Troubleshoot and resolve complex IAM-related incidents, performance issues, and integration challenges. * Support roadmap delivery for IAM initiatives, including cloud adoption, Zero Trust enablement, and modernization of legacy IAM services. * Contribute to solution design reviews, platform upgrades, and security hardening initiatives. * Explore and implement AI/ML-based anomaly detection for identity risk scoring and adaptive authentication. * Build automation scripts (Python, PowerShell, Java) to enhance IAM workflows. * Collaborate on introducing AI-driven decision-making for access governance, identity-based threat detection, and identity intelligence. * Stay engaged with emerging identity, cloud, and AI-related technologies; bring forward ideas to evolve IAM for the future. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)