Senior IAM (Identity & Access Management)

Hays Specialist Recruitment LLC
New York, NY, United States
4 days ago
Apply on www.hays.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Active Directory Audit Trail User Authentication Cloud Computing Cloud Computing Security Cyber Security Monitoring of Systems Identity and Access Management Python (Programming Language) Kerberos (Protocol) Lightweight Directory Access Protocols (LDAP) Microsoft Security Essentials
+16 more
OAuth OpenID Windows PowerShell Role-Based Access Control Openid Connect Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) User Provisioning Software Google Cloud Cyberark Infrastructure Automation Frameworks Information Technology Hashicorp Cloud Migration Terraform

Job description

  • Design, implement, and support IAM solutions across PCW & H100 GCP landing zones and hybrid identity environments.
  • Administer and maintain Microsoft Entra ID and Active Directory services, including federation, synchronization, and authentication services.
  • Implement IAM standards, access controls, and security policies aligned with enterprise architecture and compliance requirements.
  • Support the IAM tiering model (ADR-016), including role-based access controls, group-based permissions, and privileged access controls.
  • Assist in Active Directory security hardening, identity governance, and compliance-related activities.
  • Configure and manage Privileged Access Management (PAM) capabilities for administrative and elevated access scenarios.
  • Participate in secure identity integrations across cloud and on-premises platforms.

Collaboration & Expertise

  • Serve as a senior technical resource for IAM-related projects, incidents, and operational support activities.
  • Collaborate with Security, Infrastructure, Compliance, Audit, and Application teams to implement identity and access controls.
  • Support access governance processes, entitlement reviews, and compliance initiatives.
  • Provide subject matter expertise on IAM technologies, authentication methods, access management, and identity lifecycle processes.
  • Partner with project teams to ensure IAM requirements are incorporated into new solutions and system deployments.
  • Support audit activities and provide evidence for regulatory and compliance reviews, including HIPAA and SOX requirements.

Analysis & Configuration

  • Configure and maintain Active Directory organizational units, Group Policy Objects (GPOs), security groups, and delegated administration models.
  • Analyze and troubleshoot authentication, authorization, provisioning, and federation issues across multiple platforms.
  • Perform access reviews and assist in remediation of excessive, unused, or inappropriate access.
  • Monitor identity-related security events, audit logs, and privileged access activities.
  • Support IAM configurations for GCP IAM, cloud identity federation, and secure access models.
  • Assist with emergency access accounts and privileged access procedures.
  • Ensure IAM configurations follow least-privilege and Zero Trust security principles.

Strategic Planning

  • Support execution of IAM roadmaps and modernization initiatives.
  • Assist with identity platform enhancements, cloud migration projects, and access governance improvements.
  • Contribute to IAM maturity initiatives focused on automation, compliance, operational efficiency, and security.
  • Participate in long-term planning and capacity discussions for identity services and infrastructure.
  • Help ensure IAM solutions align with business, security, and regulatory requirements.

Requirements

The final salary or hourly wage, as applicable, paid to each candidate/applicant for this position is ultimately dependent on a variety of factors, including, but not limited to, the candidate’s/applicant’s qualifications, skills, and level of experience as well as the geographical location of the position.

Applicants must be legally authorized to work in the United States. Sponsorship not available., * This role requires leadership, development experience in addition to provisioning and policy support as the initial team members will be both operations and engineering - Must have feedback in this area.

  • 5 years of experience in Identity and Access Management (IAM), Information Security, Directory Services, or a related technical discipline.
  • Hands-on experience supporting and administering Microsoft Active Directory and Microsoft Entra ID.
  • Experience implementing and supporting hybrid identity environments, federation services, and modern authentication technologies.
  • Experience with Google Cloud Platform (GCP) IAM or comparable cloud identity platforms.
  • Experience supporting Privileged Access Management (PAM) processes and privileged account controls.
  • Knowledge of identity lifecycle management, access provisioning, deprovisioning, role-based access control (RBAC), and access governance processes.
  • Understanding of authentication and authorization protocols including SAML, OAuth, OpenID Connect (OIDC), LDAP, and Kerberos.
  • Experience supporting compliance and audit activities within regulated environments such as HIPAA and SOX.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent communication and collaboration skills with the ability to work effectively across technical and business teams.
  • Bachelor’s degree in Computer Science, Information Technology, Information Security, Engineering, or a related field, or an equivalent combination of education and relevant work experience.
  • Experience with GCP Config Connector (KCC) IAM resources.
  • Familiarity with Wiz IAM, Security Command Center, and cloud security monitoring tools.
  • Experience with CyberArk, HashiCorp Vault, Delinea, BeyondTrust, or similar PAM solutions.
  • Experience with Identity Governance and Administration (IGA) platforms.
  • Experience with automation and scripting using PowerShell, Python, Terraform, or Infrastructure-as-Code tools.
  • Industry certifications such as SC-300, Security+, AZ-500, CISSP, CISM, Microsoft Security, or GCP Security Engineer certifications.
  • Experience working in healthcare, life sciences, financial services, or other regulated industries.
  • Professional certifications related to IAM, cybersecurity, cloud technologies, or systems administration are preferred., You will be working with a professional recruiter who has intimate knowledge of the industry and market trends. Your Hays recruiter will lead you through a thorough screening process in order to understand your skills, experience, needs, and drivers. You will also get support on resume writing, interview tips, and career planning, so when there’s a position you really want, you’re fully prepared to get it.

About the company

Visit the Hays Career Advice section to learn top tips to help you stand out from the crowd when job hunting.

Hays is committed to building a thriving culture of diversity that embraces people with different backgrounds, perspectives, and experiences. We believe that the more inclusive we are, the better we serve our candidates, clients, and employees. We are an equal employment opportunity employer, and we comply with all applicable laws prohibiting discrimination based on race, color, creed, sex (including pregnancy, sexual orientation, or gender identity), age, national origin or ancestry, physical or mental disability, veteran status, marital status, genetic information, HIV-positive status, as well as any other characteristic protected by federal, state, or local law. One of Hays’ guiding principles is ‘do the right thing’. We also believe that actions speak louder than words. In that regard, we train our staff on ensuring inclusivity throughout the entire recruitment process and counsel our clients on these principles. If you have any questions about Hays or any of our processes, please contact us.

In accordance with applicable federal, state, and local law protecting qualified individuals with known disabilities, Hays will attempt to reasonably accommodate those individuals unless doing so would create an undue hardship on the company. Any qualified applicant or consultant with a disability who requires accommodation in order to perform the essential functions of the job should call or text 813.336.5570.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.hays.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:24 min

Evaluating remote software roles and compensation structures

Nacho Iacovino · World Congress 2021

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

3:41 min

Leveraging employer of record models for specialized workforce hiring

Bastian Eichler Bastian Eichler · World Congress 2026 Europe

Videos

See all

Related articles

See all