Lead Security Engineer
Job Description – IAM Engineering Manager
Role: IAM Engineering Manager – Directory Services, Endpoint Privilege & Identity Governance
Function
Cybersecurity – Identity & Access Management (IAM)
Role Summary
The IAM Engineering Manager is responsible for leading the design, engineering, and delivery of enterprise Identity and Access Management (IAM) platforms, with primary ownership of Microsoft Entra ID (Azure AD), Active Directory, BeyondTrust Endpoint Privilege Management (EPM), and Identity Governance & Administration (IGA) solutions. This role provides strong technical and people leadership, drives IAM platform modernization, ensures secure and scalable architectures, and partners closely with Security Architecture, IAM Operations, GRC, IT, and business stakeholders to deliver resilient, compliant, and future‑ready identity services.
Key Responsibilities
IAM Platform Engineering Leadership
- Lead engineering ownership for Entra ID, Active Directory, BeyondTrust EPM, and IGA platforms across on‑prem, hybrid, and cloud environments.
- Define and execute IAM engineering roadmaps, reference architectures, and technical standards.
- Ensure IAM platforms are designed for security, scalability, resiliency, and high availability.
- Drive platform upgrades, new feature adoption, and reduction of technical debt.
Directory & Authentication Engineering
- Lead engineering for Active Directory and Entra ID, including hybrid identity, synchronization, and directory lifecycle management.
- Design and govern Conditional Access, MFA, passwordless authentication, and identity protection controls.
- Oversee SSO and federation integrations using SAML, OAuth 2.0, and OpenID Connect.
- Align directory and authentication engineering with Zero Trust and identity‑centric security models.
Endpoint Privilege & Privileged Identity Engineering
- Own engineering strategy and implementation for BeyondTrust Endpoint Privilege Management (EPM).
- Drive least‑privilege enforcement, elevation policies, and endpoint privilege standards.
- Ensure monitoring, visibility, and compliance for privileged activities on endpoints.
- Collaborate with PAM teams to ensure end‑to‑end privileged access governance.
Identity Governance & Administration (IGA)
- Provide engineering leadership for IGA platforms such as SailPoint or equivalent solutions.
- Oversee application onboarding, lifecycle workflows, access request models, and certifications.
- Ensure strong integration between IGA, directory services, and privileged access platforms.
- Support maturity growth in role management, access governance, and compliance capabilities.
People & Delivery Management
- Lead, mentor, and develop IAM engineering teams including engineers and technical leads.
- Own hiring, performance management, career development, and succession planning.
- Establish a culture of engineering excellence, accountability, and continuous learning.
- Ensure predictable delivery using Agile and DevOps practices.
Risk, Compliance & Stakeholder Engagement
- Ensure IAM engineering solutions meet security, compliance, and audit requirements.
- Support risk assessments, control design, and remediation initiatives.
- Act as a senior technical advisor to leadership and business stakeholders.
- Manage vendor relationships and lead PoCs for new IAM technologies.
Required Skills & Experience
- 10–15 years of experience in IAM, security engineering, or identity platforms.
- 5+ years of experience in technical leadership or engineering management roles.
- Deep hands‑on experience with Microsoft Active Directory and Entra ID.
- Strong expertise in authentication, MFA, Conditional Access, and SSO technologies.
- Experience with BeyondTrust EPM or similar endpoint privilege management solutions.
- Hands‑on experience with IGA platforms such as SailPoint or equivalent.
- Strong understanding of IAM protocols including SAML, OAuth 2.0, OpenID Connect, and SCIM.
Preferred Qualifications
- Experience working in healthcare or other highly regulated environments.
- Exposure to Zero Trust architectures and passwordless authentication.
- Strong automation skills using PowerShell, APIs, or workflow orchestration tools.
- Relevant certifications such as Azure, IAM, CISSP, or equivalent.
Leadership & Behavioral Competencies
- Strong technical judgment and architectural thinking.
- Ability to translate business requirements into secure engineering solutions.
- Excellent communication skills with technical and executive stakeholders.
- Ownership mindset with a bias for quality and execution.
- Collaborative leadership style that builds high‑performing teams.