> Markdown version of [/jobs/ext/2868853-iam-security-engineer](https://www.wearedevelopers.com/jobs/ext/2868853-iam-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Security Engineer - **Company:** BorgWarner - **Location:** Auburn Hills, MI, United States - **Experience:** Experienced - **Salary:** $92,800.0 - $127,600.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Automation of Tests, Business Software, Cloud Computing, Cyber Security, Computer Engineering, Desktop Computing, Domain Name System (DNS), Identity and Access Management, Issue Tracking Systems, Information Technology Operations, Windows Domain, OAuth, OpenID, Windows PowerShell, Role-Based Access Control, Security Assertion Markup Language (SAML), Systems Integration, Tisax, Information Technology - **Published:** September 12, 2026 - **Apply:** https://jobs.mitalent.org/job-seeker/job-details/JobCode/407804863 ## About the Role Required: A bachelor's degree in cybersecurity, computer science, computer engineering, or related field. Equivalent professional experience may be considered in lieu of formal degree, * 3-5 years experience in cybersecurity, IT, or similar discipline, with at least 2 years of hands-on identity security experience. * 3+ years of hands-on experience administering Active Directory, including a strong understanding of its core components and services. * Hands-on experience with one or more IAM/IAG platforms. * Working knowledge of access governance, RBAC, provisioning, and directory services. * Experience onboarding applications into IAM platforms. * Understanding of SSO/MFA technologies, SAML/OIDC/OAuth protocols. * Familiarity with compliance frameworks: NIST, TISAX, SOX, ISO 27001. * Experience setting up a new domain from start to finish. * Experience working with DNS and common DNS record types. * Strong understanding of certificates and certificate creation. PREFERRED KNOWLEDGE, SKILLS & ABILITIES * Certifications such as: CISSP, SC-300, CCSP, Security+, etc., highly preferred. - Microsoft certifications * Prior ownership of an IAM tool or identity governance program. * Hands-on knowledge of PAM, secrets management, or identity threat detection. * Portfolio examples (RBAC matrix, IAM workflows, automation scripts, etc.). * Familiarity with PowerShell scripting. * Excellent analytical and problem-solving skills. * Ability to work independently and collaboratively in a team environment. * Excellent communication and interpersonal skills. * Experience working in a ticket tracking system. * Self- motivated, reliable and able to prioritize and work independently. * Aptitude for understanding and troubleshooting technical problems. ## Description An Identity and Access Management (IAM) Security Engineer designs, implements, and maintains systems to ensure that only authorized users have access to enterprise resources at the right time through strong processes, well-managed IAM tools, and consistent oversight. This role will serve as an agent of identity security, leading access review processes, improving RBAC models, optimizing IAM platforms, and partnering with teams across the business to drive secure identity practices. This highly technical role requires bridging security architecture with daily IT operations and development., IAM Governance & Oversight * Lead scheduled and ad-hoc access reviews for human and non-human identities, applications, groups, cloud resources, and privileged accounts. * Create, maintain and enforce IAM governance standards, policies, and procedures. * Monitor identity controls for audit support and compliance with internal and external frameworks. * Drive remediation efforts for access control gaps. * Assist projects as an advisor regarding AD and Entra. Role-Based Access Control (RBAC) & Lifecycle Management * Design and refine RBAC models, access tiers, and least-privilege principles with internal stakeholders. * Work with application owners to map permissions and standardize access roles. * Support user M365 team in maintaining lifecycle processes (Joiner/Mover/Leaver) and automated provisioning workflows where available. * Lead efforts to identify, design, and deploy areas of automation within the RBAC and access lifecycle process. * Manage AD users, computers/assets and groups. * Manage Entra users, computers/assets and groups. * Support user and computer migrations during acquisitions and divestitures. IAM Tool Ownership & Administration * Serve as primary owner/admin for one or more IAM platforms. * Manage configuration, integrations, workflows, AD and Entra platforms. * Coordinate enhancements, upgrades, and platform improvements. * Partner with application teams to onboard securely new systems into the IAM ecosystem. * Document and define provisioning rules and ensure consistent access patterns. * Provide technical support and guidance to business end-users and business application support team members. Engineering & Cloud Infrastructure Support * Lead MFA/Passkey implementation and support SSO integrations and ensure alignment with security requirements. * Create and manage SSO applications in Entra using knowledge of SAML and Oauth. * Deploy and manage Active Directory Domain Controllers. * Deploy and manage DNS servers. * Create and manage internal/external certificates * Lead Automation of the digital certification process Security Operations Support * Review and approve access requests for elevated or sensitive roles. * Help investigate access-related security incidents and identity threats. * Provide security guidance to internal teams for identity best practices. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)