IAM Engineer

Bayview Asset Management
Coral Gables, FL, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Active Directory Amazon Web Services Authentication Protocols Microsoft Azure Microsoft Exchange Server Identity and Access Management Python (Programming Language) Kerberos (Protocol) Lightweight Directory Access Protocols (LDAP) Microsoft Office Microsoft Software OAuth
+15 more
Windows PowerShell Role-Based Access Control Openid Connect Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) User Provisioning Software Scripting Google Cloud Okta Cyberark Information Technology Hashicorp Api Design SailPoint

Job description

We are seeking an experienced Identity Access & Management (IAM) Engineer to support our enterprise identity and access management initiatives. This role will focus on authentication, authorization, provisioning, privileged access management (PAM), and overall enterprise IGA administration. The IGA Engineer will play a key role in ensuring secure and efficient access to systems and applications while maintaining compliance with internal policies and regulatory requirements., * Design, implement, and maintain IGA solutions to automate user provisioning, deprovisioning, and access reviews.

  • Configure and manage role-based access control (RBAC), attribute-based access control (ABAC), and policy-based access controls.
  • Develop workflows for user lifecycle management (Joiner-Mover-Leaver).
  • Ensure compliance with internal security policies and external regulations.
  • Enforce security policies related to authentication and access control.

Privileged Access Management (PAM):

  • Implement and maintain PAM solutions to secure access to privileged accounts and credentials.

Enterprise IAM Administration & Support:

  • Maintain and optimize IGA platform configurations.
  • Monitor and troubleshoot identity-related incidents and service requests.
  • Work with cross-functional teams to implement IAM best practices.
  • Provide technical guidance on IAM strategies and solutions.

Requirements

Do you have experience in Microsoft Exchange?, Do you have a Bachelor’s degree?, * Hands-on experience with IGA platforms (e.g., SailPoint IdentityNow/IdentityIQ, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, One Identity, etc.).

  • Strong knowledge of authentication protocols and technologies (LDAP, SAML, OAuth, OpenID Connect, Kerberos).
  • Experience with PAM solutions (e.g., CyberArk, BeyondTrust, HashiCorp Vault, Thycotic/Delinea).
  • Familiarity with Active Directory (AD), Azure AD (Entra ID), SCIM, and API-based integrations.
  • Scripting skills in PowerShell, Python, or similar languages for automation.
  • Understanding of regulatory requirements related to IAM (e.g., SOX, HIPAA, NIST, ISO 27001).

Preferred Qualifications:

  • Experience with Cloud IAM (AWS, Azure, GCP).
  • Knowledge of Zero Trust Architecture (ZTA) principles.
  • Relevant certifications: CISSP, CISM, GIAC, Microsoft SC-300, SailPoint Certified Engineer, Okta Certified Professional/Administrator, CyberArk Defender/Guardian, etc., * Bachelor’s degree in Computer Science, Information Technology, or a related field (or equivalent experience).
  • Minimum of 5 years of experience managing Microsoft Exchange Server and Active Directory in a large enterprise environment.
  • Experience administering Office 365 / Exchange Online environments.

About the company

Founded in 1993, Bayview Asset Management is an investment management firm focused on mortgage and consumer credit investments, including whole loans, asset-backed securities, mortgage servicing rights, and other credit-related assets.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

1:06 min

Developer experience and project variety at scale

Alexandra Petri · WWC 2023

Videos

See all

Related articles

See all