Description: Job Title: IAM Engineer
Work Location & Reporting Address: Plano, TX 75024 or Bethpage, NY (Hybrid)
Job Details:
Minimum years of experience required: 8-10 years
Certification needed: No
Must Have Skills:
"Java, Python, Go
"OIDCOAuth 2.0 flows, token validation
"IDP security policy, behavioral anomaly signals
"Need of Customer Identity engineers that have experience migrating from legacy customer facing applications, with legacy custom Identity databases to a centralized CIAM system as using Auth0 from Okta as that platform (Okta Auto0)
Nice to have skills:
"SIEM integration for identityspecific alert logic
"IAM security baseline requirements
Detailed Job Description:
Overview:
The Identity & Access Management Engineer will provide Identity and Access Management consulting and engineering services supporting customer identity platform configuration, integration, migration, and authentication modernization initiatives.
Responsibilities:
IDP Platform Administration & Configuration
"Administer and configure the enterprise IDP tenant day-to-day: application integrations (OIDC, SAML), sign-on policies, MFA enrollment policies, network zones, and trusted origins.
"Build and maintain Customer IDP schema custom attributes, group rules, attribute mappings, and user profile transformations that support accurate identity data across all integrated systems.
"Design and implement IDP Lifecycle Management configurations for automated provisioning and de-provisioning via SCIM 2.0 and Workflows, covering Joiner / Mover / Leaver events.
"Develop and maintain workflows (no-code/low-code) and Event Hooks for automated identity orchestration, exception routing, and audit logging.
"Manage IDP authorization servers: custom scopes, claims, access policies, and token lifetime configurations aligned to application security requirements.
"Monitor platform health via system logs and integrated SIEM tooling; triage alerts, identify anomalies, and escalate or remediate per runbook.
"Create and maintain platform operational documentation along with providing customer facing support teams tools, job aids and runbooks.
Authentication Modernization & Application Migration
"Execute the migration of applications from legacy authentication mechanisms to customer IDP SSO, working from migration playbooks defined by the IAM Manager and adapting them to each application's specific stack and constraints.
"Perform OIDC and SAML application registrations in IDP: configure redirect URIs, response types, grant types, initiated login URIs, and post-logout behavior.
"Test end-to-end authentication and authorization flows in development, staging, and production environments; document results and coordinate with application teams to resolve gaps before go-live.
"Support the enablement of passwordless and phishing-resistant authentication.
"Maintain the migration tracker and contribute status updates for leadership reporting on the application portfolio onboarding roadmap.
Application Team Enablement & Technical Support
"Serve as a first-line technical advisor for application development teams integrating with IDP answering questions on SDK selection, token design, scope modeling, and session management in office hours and async channels.
"Write and maintain integration guides, code samples, and reference implementations (JavaScript, Java, Python, or Go) to help application teams onboard with minimal friction.
"Diagnose and resolve complex authentication failures, token validation errors, and SCIM provisioning issues by reviewing system logs, HAR files, and application-side logs.
"Participate in architecture reviews for new application integrations, flagging identity anti-patterns and recommending standards-compliant alternatives.
"Contribute to the IAM community of practice: share knowledge through documentation, recorded demos, and team enablement sessions.
Security, Compliance & Identity Operations
"Implement and validate authentication policy controls: step-up MFA triggers, adaptive access rules, session expiration, and assurance-level requirements aligned to data sensitivity classifications.
"Support access certification campaigns by producing accurate user-application access reports from IDP data and coordinating with application owners on remediation.
"Contribute to audit evidence collection for SOX, SOC 2, PCI-DSS, and privacy-related IAM controls; maintain accurate configuration documentation as a control artifact.
"Participate in IAM incident response: diagnose authentication outages, credential compromise events, or misconfiguration issues; execute runbook remediation steps and contribute to post-incident reviews.
"Apply and track IDP configuration hygiene: unused apps, dormant users, overly permissive policies, and API token rotation following the team's security baseline standards.
Tooling, Automation & Continuous Improvement
"Build and maintain automation scripts and Infrastructure-as-Code (IaC) configurations for repeatable configuration management using Terraform or equivalent.
"Contribute to the IAM team's CI/CD pipeline for configuration deployments: write tests for policy changes, peer-review pull requests, and promote changes through dev/stage/prod environments.
"Identify operational toil and propose automation or tooling improvements to reduce manual work for the team and for application teams onboarding to IDP.
"Evaluate new IDP features and Identity Engine capabilities; prepare proof-of-concept implementations and recommendations for the Manager to consider for roadmap inclusion.
Qualifications:
Required:
"3+ years of experience in Identity and Access Management, IT security, or a closely related technical discipline with hands-on platform administration responsibilities.
"Demonstrated, hands-on experience administering customer IDP s in a production environment: application integrations, sign-on policies, MFA, Universal Directory, and Lifecycle Management.
"Working knowledge of identity protocols and standards: OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and SCIM 2.0 able to read and interpret protocol flows, tokens, and assertions.
"Experience troubleshooting authentication and provisioning issues end-to-end using system logs, browser developer tools, and HAR file analysis.
"Ability to read and write code in at least one modern language (JavaScript/Node.js, Python, Java, or Go) sufficient to build integrations, automation scripts, and code samples.
"Comfortable working directly with application development teams in a consulting or enablement capacity able to explain IAM concepts clearly to non-IAM engineers.
"Familiarity with private cloud and cloud platforms (AWS, Azure, or GCP) and how identity integrates with cloud-native services (e.g., API Gateway authorizers, managed identity, cloud IAM roles).
Preferred:
"Certifications in customer identity platforms. (or willingness to obtain within 6 months of hire).
"Experience with workflows for no-code/low-code identity orchestration.
"Hands-on experience with FIDO2/WebAuthn or phishing resistant enrollments and policy configuration.
"Experience managing IDP configuration as code using Terraform or similar IaC tools.
"Familiarity with CIAM-specific patterns: progressive profiling, social login (Google, Apple, Facebook), consent and preference management, and customer-facing MFA enrollment UX.
"Exposure to SIEM integration for identity telemetry, and experience writing alert logic or dashboards for IAM signals.
"Understanding of Zero Trust principles and practical experience implementing device trust or continuous access evaluation policies.
"Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field; equivalent experience considered