> Markdown version of [/jobs/ext/2566868-security-engineer-iam](https://www.wearedevelopers.com/jobs/ext/2566868-security-engineer-iam). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, IAM - **Company:** Converge - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Identity and Access Management, Issue Tracking Systems, Role-Based Access Control, Software Vulnerability Management, Scripting, Information Technology - **Published:** August 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8b967e65eb18ea0f ## About the Role * Strong knowledge of identity lifecycle administration, access governance, privileged access management, entitlement governance, and deprovisioning workflows. * Knowledge of enterprise identity platforms, directory services, role-based access control (RBAC), and privileged access principles. * Experience coordinating access reviews, resolving account exceptions, and collaborating effectively with technical and non-technical stakeholders. * Strong written and verbal communication skills with the ability to facilitate structured review and approval processes. * Ability to maintain audit-ready documentation and evidence records while working within defined operational processes, SLAs, and governance frameworks. * Knowledge of formal exception management processes, including approvals, renewals, compensating controls, and risk acceptance procedures. * Familiarity with vulnerability governance, remediation tracking, security metrics, and reporting. * Experience creating dashboards, structured reporting, and metrics to support governance and operational decision-making. * Scripting or automation experience to support access reviews, remediation tracking, reporting, or evidence collection. * Demonstrated competencies in Identity and Access Management, Access Governance, Privileged Access Management, Exception and Risk Management, Audit Readiness, Stakeholder Coordination, Reporting and Metrics, and Process Improvement., * Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field; or an equivalent combination of education and professional experience. * Minimum of 4-6 years of experience in Identity and Access Management, Security Operations, Access Governance, or a closely related security engineering discipline. * Preferred experience supporting formal exception management programs and audit/compliance activities related to access controls and privileged access governance. * Preferred experience with automation, remediation governance, and security operations reporting. * Relevant professional certifications such as Security+, SC-300, CISSP, or comparable security and IAM certifications are preferred. Physical Requirements: * Prolonged periods of sitting at a desk and working on a computer. * Must be able to lift up to 15 pounds at times. ## Description The Security Engineer, Identity & Access Management (IAM), serves within the Office of the CISO as the operational bridge between Security and Internal IT for identity and access governance, remediation tracking, and exception management. This role is responsible for maintaining independent security oversight while driving timely, auditable execution of access governance activities across the organization. The ideal candidate combines hands-on IAM expertise with strong governance discipline, documentation rigor, and the ability to coordinate recurring operational processes such as access reviews, remediation tracking, and risk-based exception handling., * Serve as the primary liaison between Security and Internal IT for access control, remediation tracking, and security control implementation. * Administer identity and access governance activities, including account lifecycle management, entitlement reviews, privileged access reviews, and account cleanup. * Coordinate recurring access review cycles, including monthly, quarterly, and annual certifications, privileged account reviews, role-change validations, inactive account reviews, and exception management processes. * Manage the operational aspects of security exception requests, including intake, documentation, risk assessment support, approval routing, renewals, and status reporting. * Partner with People Operations and Internal IT to reconcile identity data, review orphaned accounts, and drive appropriate deprovisioning activities. * Support vulnerability remediation governance processes, including issue tracking, escalation, and maintenance of formal exception documentation. * Prepare audit and compliance evidence related to access governance, privileged access management, remediation activities, and exception management programs. * Develop and maintain dashboards, metrics, and reporting to communicate review completion rates, remediation status, exception aging, and ownership accountability. * Collaborate with Security, Internal IT, GRC, application owners, and business stakeholders to advance remediation efforts and governance objectives. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Recruiting in 2025: Will AI Help or Take Over?](https://www.wearedevelopers.com/videos/1301-recruiting-in-2025-will-ai-help-or-take-over) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)