Security Engineer Identity & Access Management
Cambium Learning Group
Dallas, TX, United States
about 2 months ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source
Tech stack
Computing Platforms
User Authentication
Authentication Protocols
Cloud Computing
Identity and Access Management
Python (Programming Language)
Lightweight Directory Access Protocols (LDAP)
OAuth
OpenID
Ping (Networking Utility)
Windows PowerShell
Role-Based Access Control
+12 more
Azure Active Directory
Phishing
Zero Trust Network Access
Salesforce.Com
Security Assertion Markup Language (SAML)
Scripting
Okta
Cyberark
Customer Identity Access Management
Information Technology
Api Gateway
Workday
Job description
- Identity Strategy & Architecture: Architect and maintain the target-state architecture for internal workforce identity and help redesign customer-facing (CIAM) as appropriate.
- Secure Access & Authentication: Architect secure, modern authentication protocols (SAML, OAuth2, OIDC, FIDO2) and fortify phishing-resistant MFA.
- Identity Lifecycle Automation: Collaborate with IAM team to design automated provisioning, maintenance, and deprovisioning processes (SCIM) to handle high-volume user onboarding/offboarding.
- Integration: Drive the integration of our privileged identity platform with brand Active Directories, Cloud and on-prem based platforms, and third-party applications such as SalesForce and Workday, as well as the architecture of an API gateway.
- Governance & Compliance: Define RBAC (Role-Based Access Control) and ABAC (Attribute-Based Access Control) models to ensure compliance with student data privacy laws (e.g., FERPA, GDPR).
- Mentorship: Act as a subject matter expert and mentor engineers on identity-first security best practices.
Requirements
- Experience: 7+ years in IT/Security, with at least 4+ years focusing on Identity and Access Management (IAM) architecture.
- Platform Expertise: Deep hands-on experience with modern IDP & PAM solutions (e.g., Okta, Ping Identity, Microsoft Entra ID/Azure AD, CyberArk, BeyondTrust, etc.).
- Technical Skills: Proficiency in directory services (LDAP, AD) and scripting languages (PowerShell, Python) for automation.
- Protocol Knowledge: Exceptional understanding of TLS, SSO, Federation, SAML, OAuth2, and OIDC protocols.
- Education: Bachelor’s degree in Computer Science, Information Technology, or equivalent experience.
Preferred Qualifications:
- Compliance: Familiarity with student data privacy regulations (FERPA, COPPA).
- Zero Trust: Experience implementing Zero Trust architecture principals.
- Certifications: CAIM, CAMS, CISSP, CISM, or vendor-specific certifications (e.g., Okta Certified Architect)., If you will be working remotely, either occasionally or on a permanent basis, you must have a reliable internet connection through a cable or fiber-optic broadband service with minimum speeds of 10 Mbps download and 5 Mbps upload.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
about 2 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago
LM
Luis Minvielle
Why Upskilling And Reskilling is Important For Developers
over 2 years ago
AJ
Austin Joy
What Are The Top Skills Required For Azure Developers?
over 4 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago