> Markdown version of [/jobs/ext/2996287-cybersecurity-engineer-idam](https://www.wearedevelopers.com/jobs/ext/2996287-cybersecurity-engineer-idam). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer (IDAM) - **Company:** Moody's Corporation - **Location:** Charlotte, NC, United States - **Experience:** Expert - **Salary:** $116,500.0 - $192,300.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Artificial Intelligence, Cyber Security, Multi-Factor Authentication, Identity and Access Management, OpenID, Azure Active Directory, Phishing, Security Assertion Markup Language (SAML), Single Sign-On, Enterprise Software Applications, IT General Controls (ITGC), Okta, Information Technology - **Published:** September 19, 2026 - **Apply:** https://find.jobs/jobs-near-me/apply/ats-redirect/?id=2977934897-2 ## About the Role * 3+ years of hands-on access management engineering experience, including workforce identity configuration, administration, and lifecycle management (Okta preferred) * Strong depth in core Identity and Access Management and Single Sign-On protocols and application integration patterns - SAML, OIDC, and SCIM * Experience engineering authentication and multi-factor authentication policy using phishing-resistant methods * Hands-on experience with identity lifecycle and provisioning automation * Experience operating in regulated, audited environments (SOX/ITGC, FedRAMP, or equivalent), including producing audit evidence and control documentation * Working knowledge of identity governance concepts - access requests, certifications, separation of duties; Okta Identity Governance experience is preferred * Familiarity with Microsoft Entra ID administration, including Conditional Access policy engineering and hybrid identity management, is preferred * Strong written communication skills for producing audit-ready documentation and evidence packages * Ability to independently lead end-to-end engineering work from requirements through operational support * Demonstrated proficiency in artificial intelligence concepts, with hands-on experience using AI tools to streamline workflows and enhance operational efficiency. Proven ability to implement AI-powered solutions to solve business challenges. Demonstrates a growing awareness of AI risk management and a commitment to responsible and ethical AI use., * Bachelor's degree or equivalent qualification in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field * Advanced technical certifications preferred, such as Okta Certified Administrator/Professional (Consultant a plus), Microsoft Certified: Identity and Access Administrator (SC-300), CISSP, or equivalent identity/security certifications * Prior FedRAMP or US federal identity/compliance experience preferred ## Description This role supports Identity and Access Management initiatives end to end - including access management design, engineering, configuration, operations, audit evidence, and Cloud Identity and Access Management engineering and operations. * Own end-to-end engineering, configuration, and administration of workforce identities in Moody's Okta tenants, including the FedRAMP workforce, non-production, and Customer Identity and Access Management tenants, applying established standards and requirements * Design and maintain Single Sign-On and application integrations using SAML, OIDC, and SCIM across enterprise applications * Engineer authentication and multi-factor authentication policy to enforce a phishing-resistant assurance level * Own identity lifecycle (joiner/mover/leaver) and provisioning workflows, including automation via Okta Workflows * Monitor and respond to identity risk signals and threats * Design and administer groups, custom admin roles, and least-privilege access models * Produce and maintain SOX and FedRAMP audit evidence, partnering with Cybersecurity Governance and Audit teams * Provide engineering coverage for Microsoft Entra ID, including Conditional Access policy design and hybrid identity management configurations * Support hybrid identity operations and coordinate with the Entra/Active Directory engineering owner on shared administrative responsibilities per the team's admin-ownership model About the Team The Identity Engineering team designs, builds, and operates the identity and access management platforms that secure access across Moody's enterprise and regulated environments. By joining our team, you will help extend enterprise-grade identity engineering practices into a federal compliance boundary, working on phishing-resistant authentication, identity governance, and audit-ready operations for a global financial services firm. As Moody's continues to advance its AI capabilities, our team plays a critical role in delivering the secure, trusted identity foundations that enable innovation, automation, and responsible AI adoption across the organization. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 171: AI in disguise, Doomed tech and system prompts](https://www.wearedevelopers.com/magazine/594-dev-digest-171-ai-in-disguise-doomed-tech-and-system-prompts) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)