> Markdown version of [/jobs/ext/2683388-senior-iam-identity-access-management](https://www.wearedevelopers.com/jobs/ext/2683388-senior-iam-identity-access-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior IAM (Identity & Access Management) - **Company:** Hays Specialist Recruitment LLC - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Audit Trail, User Authentication, Cloud Computing, Cloud Computing Security, Cyber Security, Monitoring of Systems, Identity and Access Management, Python (Programming Language), Kerberos (Protocol), Lightweight Directory Access Protocols (LDAP), Microsoft Security Essentials, OAuth, OpenID, Windows PowerShell, Role-Based Access Control, Openid Connect, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), User Provisioning Software, Google Cloud, Cyberark, Infrastructure Automation Frameworks, Information Technology, Hashicorp, Cloud Migration, Terraform - **Published:** September 2, 2026 - **Apply:** https://www.hays.com/job-detail/senior-iam-%28identity-access-management%29--new-york_1186291 ## About the Role The final salary or hourly wage, as applicable, paid to each candidate/applicant for this position is ultimately dependent on a variety of factors, including, but not limited to, the candidate's/applicant's qualifications, skills, and level of experience as well as the geographical location of the position. Applicants must be legally authorized to work in the United States. Sponsorship not available., * This role requires leadership, development experience in addition to provisioning and policy support as the initial team members will be both operations and engineering - Must have feedback in this area. * 5 years of experience in Identity and Access Management (IAM), Information Security, Directory Services, or a related technical discipline. * Hands-on experience supporting and administering Microsoft Active Directory and Microsoft Entra ID. * Experience implementing and supporting hybrid identity environments, federation services, and modern authentication technologies. * Experience with Google Cloud Platform (GCP) IAM or comparable cloud identity platforms. * Experience supporting Privileged Access Management (PAM) processes and privileged account controls. * Knowledge of identity lifecycle management, access provisioning, deprovisioning, role-based access control (RBAC), and access governance processes. * Understanding of authentication and authorization protocols including SAML, OAuth, OpenID Connect (OIDC), LDAP, and Kerberos. * Experience supporting compliance and audit activities within regulated environments such as HIPAA and SOX. * Strong analytical, troubleshooting, and problem-solving skills. * Excellent communication and collaboration skills with the ability to work effectively across technical and business teams. * Bachelor's degree in Computer Science, Information Technology, Information Security, Engineering, or a related field, or an equivalent combination of education and relevant work experience. * Experience with GCP Config Connector (KCC) IAM resources. * Familiarity with Wiz IAM, Security Command Center, and cloud security monitoring tools. * Experience with CyberArk, HashiCorp Vault, Delinea, BeyondTrust, or similar PAM solutions. * Experience with Identity Governance and Administration (IGA) platforms. * Experience with automation and scripting using PowerShell, Python, Terraform, or Infrastructure-as-Code tools. * Industry certifications such as SC-300, Security+, AZ-500, CISSP, CISM, Microsoft Security, or GCP Security Engineer certifications. * Experience working in healthcare, life sciences, financial services, or other regulated industries. * Professional certifications related to IAM, cybersecurity, cloud technologies, or systems administration are preferred., You will be working with a professional recruiter who has intimate knowledge of the industry and market trends. Your Hays recruiter will lead you through a thorough screening process in order to understand your skills, experience, needs, and drivers. You will also get support on resume writing, interview tips, and career planning, so when there's a position you really want, you're fully prepared to get it. ## Description * Design, implement, and support IAM solutions across PCW & H100 GCP landing zones and hybrid identity environments. * Administer and maintain Microsoft Entra ID and Active Directory services, including federation, synchronization, and authentication services. * Implement IAM standards, access controls, and security policies aligned with enterprise architecture and compliance requirements. * Support the IAM tiering model (ADR-016), including role-based access controls, group-based permissions, and privileged access controls. * Assist in Active Directory security hardening, identity governance, and compliance-related activities. * Configure and manage Privileged Access Management (PAM) capabilities for administrative and elevated access scenarios. * Participate in secure identity integrations across cloud and on-premises platforms. Collaboration & Expertise * Serve as a senior technical resource for IAM-related projects, incidents, and operational support activities. * Collaborate with Security, Infrastructure, Compliance, Audit, and Application teams to implement identity and access controls. * Support access governance processes, entitlement reviews, and compliance initiatives. * Provide subject matter expertise on IAM technologies, authentication methods, access management, and identity lifecycle processes. * Partner with project teams to ensure IAM requirements are incorporated into new solutions and system deployments. * Support audit activities and provide evidence for regulatory and compliance reviews, including HIPAA and SOX requirements. Analysis & Configuration * Configure and maintain Active Directory organizational units, Group Policy Objects (GPOs), security groups, and delegated administration models. * Analyze and troubleshoot authentication, authorization, provisioning, and federation issues across multiple platforms. * Perform access reviews and assist in remediation of excessive, unused, or inappropriate access. * Monitor identity-related security events, audit logs, and privileged access activities. * Support IAM configurations for GCP IAM, cloud identity federation, and secure access models. * Assist with emergency access accounts and privileged access procedures. * Ensure IAM configurations follow least-privilege and Zero Trust security principles. Strategic Planning * Support execution of IAM roadmaps and modernization initiatives. * Assist with identity platform enhancements, cloud migration projects, and access governance improvements. * Contribute to IAM maturity initiatives focused on automation, compliance, operational efficiency, and security. * Participate in long-term planning and capacity discussions for identity services and infrastructure. * Help ensure IAM solutions align with business, security, and regulatory requirements. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [What if your HR software adapted to you, not the other way around?](https://www.wearedevelopers.com/videos/100259-what-if-your-hr-software-adapted-to-you-not-the-other-way-around) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Best Job Search Websites of 2025](https://www.wearedevelopers.com/magazine/368-the-best-job-search-websites-of-2025) - [Top HR Tech Conferences in 2024](https://www.wearedevelopers.com/magazine/303-top-hr-tech-conferences-in-2024) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [Finding Jobs in Germany](https://www.wearedevelopers.com/magazine/375-finding-jobs-in-germany)