Security Engineer, IAM

Converge
United States
27 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Identity and Access Management Issue Tracking Systems Role-Based Access Control Software Vulnerability Management Scripting Information Technology

Job description

The Security Engineer, Identity & Access Management (IAM), serves within the Office of the CISO as the operational bridge between Security and Internal IT for identity and access governance, remediation tracking, and exception management. This role is responsible for maintaining independent security oversight while driving timely, auditable execution of access governance activities across the organization. The ideal candidate combines hands-on IAM expertise with strong governance discipline, documentation rigor, and the ability to coordinate recurring operational processes such as access reviews, remediation tracking, and risk-based exception handling., * Serve as the primary liaison between Security and Internal IT for access control, remediation tracking, and security control implementation.

  • Administer identity and access governance activities, including account lifecycle management, entitlement reviews, privileged access reviews, and account cleanup.
  • Coordinate recurring access review cycles, including monthly, quarterly, and annual certifications, privileged account reviews, role-change validations, inactive account reviews, and exception management processes.
  • Manage the operational aspects of security exception requests, including intake, documentation, risk assessment support, approval routing, renewals, and status reporting.
  • Partner with People Operations and Internal IT to reconcile identity data, review orphaned accounts, and drive appropriate deprovisioning activities.
  • Support vulnerability remediation governance processes, including issue tracking, escalation, and maintenance of formal exception documentation.
  • Prepare audit and compliance evidence related to access governance, privileged access management, remediation activities, and exception management programs.
  • Develop and maintain dashboards, metrics, and reporting to communicate review completion rates, remediation status, exception aging, and ownership accountability.
  • Collaborate with Security, Internal IT, GRC, application owners, and business stakeholders to advance remediation efforts and governance objectives.

Requirements

  • Strong knowledge of identity lifecycle administration, access governance, privileged access management, entitlement governance, and deprovisioning workflows.
  • Knowledge of enterprise identity platforms, directory services, role-based access control (RBAC), and privileged access principles.
  • Experience coordinating access reviews, resolving account exceptions, and collaborating effectively with technical and non-technical stakeholders.
  • Strong written and verbal communication skills with the ability to facilitate structured review and approval processes.
  • Ability to maintain audit-ready documentation and evidence records while working within defined operational processes, SLAs, and governance frameworks.
  • Knowledge of formal exception management processes, including approvals, renewals, compensating controls, and risk acceptance procedures.
  • Familiarity with vulnerability governance, remediation tracking, security metrics, and reporting.
  • Experience creating dashboards, structured reporting, and metrics to support governance and operational decision-making.
  • Scripting or automation experience to support access reviews, remediation tracking, reporting, or evidence collection.
  • Demonstrated competencies in Identity and Access Management, Access Governance, Privileged Access Management, Exception and Risk Management, Audit Readiness, Stakeholder Coordination, Reporting and Metrics, and Process Improvement., * Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field; or an equivalent combination of education and professional experience.
  • Minimum of 4-6 years of experience in Identity and Access Management, Security Operations, Access Governance, or a closely related security engineering discipline.
  • Preferred experience supporting formal exception management programs and audit/compliance activities related to access controls and privileged access governance.
  • Preferred experience with automation, remediation governance, and security operations reporting.
  • Relevant professional certifications such as Security+, SC-300, CISSP, or comparable security and IAM certifications are preferred.

Physical Requirements:

  • Prolonged periods of sitting at a desk and working on a computer.
  • Must be able to lift up to 15 pounds at times.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:56 min

Implementing state-driven deployment architecture using automated pipeline integration tools

Lian Li · World Congress 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:34 min

Automating the recruitment process to handle massive applicant volumes

Barbara Pirrera Barbara Pirrera +1 · World Congress 2024

Videos

See all

Related articles

See all