> Markdown version of [/jobs/ext/630387-security-engineer-identity-access-management](https://www.wearedevelopers.com/jobs/ext/630387-security-engineer-identity-access-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer Identity & Access Management - **Company:** Cambium Learning Group - **Location:** Dallas, TX, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Computing Platforms, User Authentication, Authentication Protocols, Cloud Computing, Identity and Access Management, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Ping (Networking Utility), Windows PowerShell, Role-Based Access Control, Azure Active Directory, Phishing, Zero Trust Network Access, Salesforce.Com, Security Assertion Markup Language (SAML), Scripting, Okta, Cyberark, Customer Identity Access Management, Information Technology, Api Gateway, Workday - **Published:** June 24, 2026 - **Apply:** https://www.dice.com/job-detail/2f22da1f-b951-4e2e-b890-2d3400e8dadf ## About the Role * Experience: 7+ years in IT/Security, with at least 4+ years focusing on Identity and Access Management (IAM) architecture. * Platform Expertise: Deep hands-on experience with modern IDP & PAM solutions (e.g., Okta, Ping Identity, Microsoft Entra ID/Azure AD, CyberArk, BeyondTrust, etc.). * Technical Skills: Proficiency in directory services (LDAP, AD) and scripting languages (PowerShell, Python) for automation. * Protocol Knowledge: Exceptional understanding of TLS, SSO, Federation, SAML, OAuth2, and OIDC protocols. * Education: Bachelor's degree in Computer Science, Information Technology, or equivalent experience. Preferred Qualifications: * Compliance: Familiarity with student data privacy regulations (FERPA, COPPA). * Zero Trust: Experience implementing Zero Trust architecture principals. * Certifications: CAIM, CAMS, CISSP, CISM, or vendor-specific certifications (e.g., Okta Certified Architect)., If you will be working remotely, either occasionally or on a permanent basis, you must have a reliable internet connection through a cable or fiber-optic broadband service with minimum speeds of 10 Mbps download and 5 Mbps upload. ## Description * Identity Strategy & Architecture: Architect and maintain the target-state architecture for internal workforce identity and help redesign customer-facing (CIAM) as appropriate. * Secure Access & Authentication: Architect secure, modern authentication protocols (SAML, OAuth2, OIDC, FIDO2) and fortify phishing-resistant MFA. * Identity Lifecycle Automation: Collaborate with IAM team to design automated provisioning, maintenance, and deprovisioning processes (SCIM) to handle high-volume user onboarding/offboarding. * Integration: Drive the integration of our privileged identity platform with brand Active Directories, Cloud and on-prem based platforms, and third-party applications such as SalesForce and Workday, as well as the architecture of an API gateway. * Governance & Compliance: Define RBAC (Role-Based Access Control) and ABAC (Attribute-Based Access Control) models to ensure compliance with student data privacy laws (e.g., FERPA, GDPR). * Mentorship: Act as a subject matter expert and mentor engineers on identity-first security best practices. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)