> Markdown version of [/jobs/ext/3584399-advanced-security-engineer-iam-relativity](https://www.wearedevelopers.com/jobs/ext/3584399-advanced-security-engineer-iam-relativity). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Advanced Security Engineer (IAM) Relativity - **Company:** AI Enabled Solutions LLC - **Location:** Phoenix, AZ, United States (Remote available) - **Experience:** Expert - **Salary:** $104,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, User Authentication, Microsoft Azure, Bash Shell, Software as a Service, Cyber Security, Identity and Access Management, Python (Programming Language), Kerberos (Protocol), Key Management, Network Security, Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Ping (Networking Utility), Windows PowerShell, Role-Based Access Control, Azure Active Directory, Anti-Phishing, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, Software Engineering, Software Vulnerability Management, Policy as Code, Cloud Platform System, Okta, Cyberark, Multi-Cloud, Cyber Threat Analysis, HR Software, Information Technology, CIS Benchmarks, Drift Detection, Api Design, SailPoint, Security Orchestration, Automation & Response - **Published:** October 4, 2026 - **Apply:** https://www.juju.com/job/21_01a0ef03-b2e3-7e51-88d2-e056b0be4f8c ## About the Role * Must be able to obtain and maintain the required Public Trust clearance for this role * Bachelor's in Computer Science, Information Security, or equivalent experience. * 5+ years of hands-on experience in enterprise IAM or security engineering, with a focus on identity, authentication, and access domains, or a Master's degree in Cybersecurity or a relevant field. * Hands-on experience with common identity tools such as IdP/SSO (Okta, Entra ID/Azure AD, Ping), IGA (SailPoint, Saviynt), PAM (CyberArk, BeyondTrust), and directory services, plus intermediate knowledge of authentication and federation protocols (SAML, OIDC, OAuth 2.0, SCIM, LDAP, Kerberos). * Basic knowledge of industry-standard security benchmarks and frameworks (MITRE, NIST 800-63, Zero Trust). * Proficiency in at least one scripting/automation language (Python, Bash, or PowerShell) applied to modern containerized services, CLI-based commands, and/or identity-specific use cases (API-driven provisioning, policy-as-code). * Ability to communicate technical findings clearly to both engineering peers and non-technical stakeholders. Preferred qualifications: * Familiarity with AI-enabled identity operations (UEBA, ML-based access-risk scoring, or AI-assisted access-review and threat-hunting workflows). * Basic knowledge of common cloud environments (AWS, Azure, or GCP) and their native identity services (IAM, RBAC, workload identity). * Working knowledge of the software development lifecycle, software engineering practices, or infrastructure-as-code environments: contributing identity and access controls (secrets management, workload identity, policy-as-code) to CI/CD pipelines. * Experience with non-human, workload, and AI-agent identity, secrets management, and machine-to-machine authentication. * Experience supporting compliance and audit requirements (SOC 2, ISO 27001, FedRAMP, HIPAA) from an identity and access control perspective. * Relevant certifications such as SC-300 (Microsoft Identity and Access Administrator), AZ-500 (Azure Security Engineer), Okta Certified Professional/Administrator, SailPoint IdentityIQ, SEC+, CISSP, CISA, or equivalent., Endpoint Security, Network Security, Penetration Testing, Security Architecture Design, Security Automation, Security Information, Security Information and Event Management (SIEM), Security Operations, Threat Modeling, Vulnerability Management ## Description * Implement and operate identity controls spanning workforce, machine, and workload identity as part of a layered defense-in-depth model. * Operate continuous adaptive trust mechanisms, including continuous access evaluation (CAE), risk-based step-up authentication, and session revocation, that re-verify identity against real-time posture and behavioral signals rather than at the access gate alone. * Configure ZTNA, least-privilege access, phishing-resistant MFA/FIDO2, and JIT access across access paths. * Implement SSO, federation, and authentication standards (SAML, OAuth 2.0, OIDC, SCIM, Kerberos, LDAP) across SaaS and multi-cloud environments. * Apply hardening standards to identity infrastructure using CIS Benchmarks/DISA STIGs with automated compliance validation. Identity Lifecycle, Governance & PAM * Build and maintain identity lifecycle automation (joiner/mover/leaver) integrating HR systems, directories, and downstream applications. * Operate identity governance and administration (IGA) workflows: access reviews, certification campaigns, and segregation-of-duties checks. * Administer privileged access management (PAM) including credential vaulting, JIT elevation, and session monitoring. * Maintain governance of non-human identities (service accounts, workloads, secrets) using drift detection and policy-as-code. Detection, Response & Collaboration * Feed identity telemetry into the detection stack (SIEM/SOAR, UEBA) to support detection of credential abuse, privilege escalation, and lateral movement. * Execute identity-focused IR playbook steps for account takeover, credential compromise, and session hijacking. * Implement identity checks in CI/CD pipelines (secret scanning, IaC identity analysis), acting on AI-generated fix recommendations in PR workflows. * Track identity hygiene metrics and support audits, certifications, and e-discovery requirements alongside GRC.