
Senior Identity & Access Management Systems Engineer (IAM)
- Seattle, WA
- Permanent
- Full-time
- Lead the design, implementation, and daily operations of our enterprise-wide Privileged Access Management (PAM) solutions.
- Develop and enforce PAM policies for credential vaulting, session isolation, privileged command monitoring, and just-in-time (JIT) access.
- Integrate critical applications and infrastructure into both our PAM and SSO platforms, ensuring secure and seamless access for privileged users.
- Utilize DevOps practices and Infrastructure-as-Code (IaC) tools like Terraform and Ansible to automate the deployment and management of PAM and other IAM systems.
- Provide Tier 3 operational support for PAM, SSO, and MFA platforms, serving as the subject matter expert for troubleshooting complex privileged access issues.
- Investigate and respond to security incidents related to compromised credentials and privileged access abuse.
- Collaborate with IT, infrastructure, and security teams to drive the evolution of our Zero Trust architecture by strengthening privileged access controls and implementing principles of least privilege.
- Document PAM architecture, engineering standards, and operational procedures (SOPs) for both technical teams and end-users.
- Participate in a 24x7 on-call rotation as an L3 engineer for critical IAM and PAM systems.
- Bachelor's degree in IT, Information Security, Computer Science, or equivalent experience
- 2+ years of hands-on experience in Identity & Access Management, with a focus on Privileged Access Management (PAM)
- Hands on experience in designing, deploying, and managing enterprise PAM solutions such as Netwrix, CyberArk, Beyond Trust, or similar platforms.
- Deep understanding of PAM concepts including privileged session management, credential vaulting and rotation, endpoint privilege management, and just-in-time (JIT) access.
- Comprehensive knowledge of modern authentication standards and technologies, including SAML, OIDC, OAuth, MFA, and JSON Web Token (JWT).
- Strong understanding of core enterprise technologies including Windows and Unix/Linux OS, databases, directory services (Active Directory, LDAP), and cloud platforms (AWS, Azure, GCP).
- Proficiency with DevOps automation/orchestration tools (Ansible, Terraform, CircleCI) and scripting/programming experience (Python, Java, JavaScript).
- Familiarity with security standards and frameworks such as NIST, ISO 27001, and their application to both privileged and standard access management.
- Experience with Identity Governance and Administration (IGA) products (SailPoint, Saviynt).
- Experience with Cloud Infrastructure Entitlement Management (CIEM) tools.
- Okta Certified Professional, Administrator, or Consultant certification.
- Hold a CISSP certificate.
- Medical/Dental/Vision/Life, AD&D insurance
- Flexible Spending Accounts (FSA) & Health Savings Account (HSA)
- Long-term/Short-term Disability
- Employee Assistance Program (EAP) program
- 401K Plan with Company Match
- 18-21 days of the Paid Time Off (PTO) a year based on the tenure
- 12 Paid Holidays
- XX weeks of Paid Parental leave
- Pre-tax commuter benefits
- MTV - [Free] Electric Car Charging Station