IAM Implementation Engineer
ARCHIVED
We can't find an active application page for this role right now. It may reopen or be listed elsewhere. Use Next Steps to search for an active apply link and similar live jobs.
Role: Sr. IAM Implementation Engineer (Microsoft Entra ID and CyberArk PAM)Location: New York, NY 10017 (100% Onsite – No flexibility)Full Time Role SummaryWe are seeking a Senior / Principal IAM & PAM Implementation Engineer with deep hands‑on experience in Microsoft Entra ID (Azure AD) and CyberArk Privileged Access Management, combined with AI / GenAI identity security exposure, to support financial services and highly regulated clients. This role is execution‑driven and operates in mission‑critical environments where identity failures directly impact business continuity, regulatory compliance, and customer trust. The engineer will design, implement, and operate IAM and PAM controls aligned to Zero Trust principles, audit requirements, and financial‑industry regulations. Key ResponsibilitiesIdentity & Access Management (Microsoft Entra ID / Azure AD)Design and hands‑on implement Microsoft Entra ID solutions in regulated, production‑critical environmentsDesign and enforce Conditional Access, MFA, passwordless authentication, and device‑based accessIntegrate internal and third‑party applications using SAML, OAuth 2.0, OIDCImplement identity lifecycle (JML), RBAC, access reviews, and entitlement managementMaintain role-based access control (RBAC) aligned with least‑privilege principles.Support IAM integrations with CyberArk PAM, DLP, and security platforms where applicable.Troubleshoot complex sign‑in, token, MFA, PRT, and policy enforcement issues with minimal user disruptionPrivileged Access Management (CyberArk PAM)Hands‑on deployment and administration of CyberArk components: Vault, PSM, CPM, Secrets ManagementOnboard privileged accounts across servers, databases, network, cloud, and service identitiesEnforce least‑privilege, credential rotation, session recording, and approval workflowsIntegrate CyberArk with Microsoft Entra ID for identity‑driven privileged access.Monitor privileged access activity and investigate suspicious or non‑compliant usage.Support PAM audits, regulatory reviews, and emergency access scenarios (break‑glass)AI / GenAI Identity SecurityImplement identity and access controls for AI and GenAI platforms (e.g., Microsoft Copilot, enterprise AI workloads)Secure: AI service identities and service principalsAPI access and automation credentialsAI training and inference access pipelinesAlign IAM, PAM controls with enterprise AI governance, model risk, and data protection standardsGovernance, Compliance & RiskImplement IAM and PAM controls aligned with Financial‑services regulatory expectations and Internal risk & audit frameworksSupport audits and compliance reviews (e.g., access evidence, privileged access reports)Design and maintain audit‑ready documentation, including: Architecture diagramsPolicy definitionsAccess workflows and operational proceduresParticipate in identity‑related incident response, RCA, and remediation activitiesDelivery & Client EngagementLead IAM/PAM implementations from design through production rolloutWork closely with Security leadership, Risk & compliance teams, Application owners, Auditors and regulators (as required)Provide clear, pragmatic recommendations balancing security, usability, and regulatory complianceAct as a trusted technical advisor to clients in high‑stakes environments Required Skills & ExperienceMandatory (Hands‑on)8–15 years of IAM / Security engineering experience in regulated environmentsStrong hands‑on experience with: Microsoft Entra ID (Azure AD)CyberArk PAM (Vault, PSM, CPM, Secrets)Conditional Access, MFA, Passwordless, RBACSAML, OAuth 2.0, OpenID ConnectProduction troubleshooting in large enterprise environmentsRegulated‑Industry ExperienceExperience supporting financial services, banking, insurance, or similarly regulated clientsExposure to audit, compliance, or risk workflows related to identity and privileged accessComfort operating under strict change management and approval processesNice to HaveIdentity Governance (PIM, Access Reviews)SIEM integrations (Azure Sentinel, Splunk)PowerShell / automation for IAM & PAMZero Trust architecture implementation experienceSoft SkillsStrong hands‑on engineering mindset (not architecture‑only).Process‑driven mindset with strong documentation discipline.Pragmatic problem‑solver with strong risk awarenessExcellent client communication and stakeholder management skills. Clear communication with technical and business stakeholders.Ability to build long‑term, trusted relationships.Calm and methodical approach in high‑impact production incidents. Ability to support incidents under pressurePreferred CertificationsMicrosoft SC‑300 / AZ‑104 / AZ‑900CyberArk PAM certificationsSecurity or identity‑related certifications (preferred)