
Distinguished Engineer, Identity and Access Management (IAM)
- Scottsdale, AZ
- Permanent
- Full-time
- IAM Strategy: Partner with IAM Engineering to define and drive the long-term IAM strategy, ensuring alignment with organizational goals and security standards.
- Architecture & Design: Architect and design scalable, secure, and user-friendly IAM solutions that address access challenges, enable business operations, and reduce risk.
- Authentication & Authorization: Oversee and guide the development and implementation of strong authentication and authorization protocols, such as SSO (Single Sign-On), MFA (Multi-Factor Authentication), OAuth, SAML, and OpenID Connect.
- Privilege Access Management (PAM): Design and implement PAM strategies and solutions to manage, monitor, and audit privileged accounts.
- Session & Password Management: Develop and maintain session management policies and password management strategies to mitigate risks and improve user experience.
- IAM Best Practices: Establish and promote industry best practices for IAM, ensuring that the organization is compliant with relevant regulations and standards such as NIST, PCI, SOX, and others.
- Active Directory (AD) Design: Oversee Active Directory architecture, guide strategy to consolidate domains, fortify the AD environment, and provide technical guidance for engineering and operational teams.
- Identity Stores & Provider Platforms: Design and integrate identity stores, directory services, and identity provider platforms (e.g., PING, Azure AD, etc.).
- Entitlement Management: AD Security group structure, cloud entitlement structure and management for AWS, GCP, and Azure.
- Cross-functional Collaboration: Work closely with security teams, infrastructure, application teams, and business units to ensure IAM solutions meet business needs while maintaining security and compliance.
- Risk Management & Incident Response: Identify and mitigate security risks related to access management, ensuring rapid response and resolution of IAM-related incidents.
- Continuous Improvement: Stay updated on industry trends, emerging IAM technologies, and security threats to continuously improve and evolve IAM strategy and solutions.
- Design Review: Conduct comprehensive risk assessments to identify vulnerabilities and threats to access management designs and solutions, identify gaps in design approaches and provide effective remediation solutions.
- Minimum of 15+ years of experience in Identity and Access Management, with at least 5 years in a leadership or distinguished technical role.
- Proven experience in designing, architecting, and implementing IAM solutions for complex, large-scale environments.
- Experience designing and operating corporate and customer facing identity and access management platforms.
- Extensive experience with IAM protocols such as SAML, OAuth, OpenID Connect, LDAP, and SCIM.
- Deep understanding of authentication and authorization mechanisms, including MFA, SSO, PAM, and session management.
- Hands-on experience with IAM platforms and technologies such as Active Directory, Azure AD, Okta, ForgeRock, Ping Identity, etc.
- Strong background in security frameworks and compliance requirements (e.g., NIST, ISO 27001, SOC 2, GDPR, HIPAA).
- Demonstrated experience in leading cross-functional teams, managing IAM projects, and driving strategic initiatives.
- Experience working in cloud-native environments (e.g., AWS, Azure, Google Cloud) and integrating IAM solutions with cloud services.
- Experience with identity governance and administration (IGA) platforms and solutions.
- Experience with designing and implementing federated identity solutions.
- Certified Information Systems Security Professional (CISSP) – preferred.
- Certified Identity and Access Manager (CIAM) – preferred.
- Certified Information Security Manager (CISM) – preferred.
- Certified Cloud Security Professional (CCSP) – preferred.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field; Master’s degree preferred.
- Ongoing education in cybersecurity, identity management, or related domains is a plus.
- In-depth technical expertise in IAM concepts and technologies.
- Strong communication skills, with the ability to articulate complex IAM concepts to both technical and non-technical stakeholders.
- Proven ability to collaborate and influence across the organization to deliver targeted business and security outcomes.
- Excellent problem-solving skills, with a focus on innovative and secure solutions to meet business needs.
- Leadership capabilities, with experience in mentoring teams and leading initiatives.
- Strong understanding of the user experience and balancing security with usability in IAM solutions.