Engineer, IAM & Endpoint Platform

1P284 THE CARLYLE GROUP EMPLOYEE CO., LLC

Washington (District of Columbia)

On-site

USD 160,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The Carlyle Group is seeking an Experienced Engineer focused on Identity & Access Management (IAM) and Endpoint Platforms to join our Enterprise Productivity Solutions team within Global Technology & Solutions (GTS).

This role will own the implementation, maintenance, and continuous improvement of IAM platforms and endpoint management systems across Windows, macOS, iOS, Intune, and Jamf to enable secure access for Carlyle's workforce.

Qualifications

  • Bachelor’s Degree or equivalent in IT or engineering.
  • IAM-focused certifications preferred (e.g., SailPoint IdentityNow Engineer, Okta Administrator).
  • 6+ years of IT experience with IAM and endpoint management.

Responsibilities

  • Own design, implementation, and operations of IAM and endpoint platforms.
  • Automate workflows and RBAC using SailPoint IdentityNow, Okta, Entra ID.
  • Maintain Joiner-Mover-Leaver processes and access reviews.
  • Support executive stakeholders and resolve high-impact incidents.
  • Contribute to cross-EPS initiatives including Microsoft 365 administration.
  • Ensure compliance with SOX, NIST, ISO 27001 in IAM and endpoint programs.

Skills

Executive communication
On-call rotation
Cross-functional collaboration
Analytical troubleshooting

Education

Bachelor’s degree or equivalent years of relevant experience
IT or engineering discipline

Tools

SailPoint IdentityNow
Okta
CyberArk
Entra ID
Intune
Jamf
Active Directory
PowerShell
Python

Job description

Position Summary

The Carlyle Group is seeking an Experienced Engineer focused on Identity & Access Management (IAM) & Endpoint Platforms to join our Enterprise Productivity Solutions (EPS) team within Global Technology & Solutions (GTS). EPS is responsible for the platforms Carlyle's workforce relies on every day which includes Identity & Access Management, endpoint management (physical and virtual), Windows and macOS, Microsoft 365 and Purview, enterprise AI solutions, and other end-user technology services. This role’s primary focus is IAM and endpoint management, with the expectation that the engineer also contributes across other EPS workstreams as priorities evolve. The Engineer will own the implementation, maintenance, and continuous improvement of IAM platforms (SailPoint, Okta, CyberArk, Entra ID) and endpoint management systems (Intune, Jamf) across Windows, macOS, and iOS, and contribute over time to broader EPS initiatives. You will lead several digital workplace transformation initiatives, drive process and automation improvements, resolve complex technical issues, and collaborate across tech and business teams to shape strategy and solution direction in a global, fast-paced environment.

Primary Responsibilities
  • IAM & Endpoint Management
    • Serve as a subject matter expert across IGA, PAM, SSO, MFA, and endpoint security; design, automate, and maintain IAM solutions across SailPoint IdentityNow, Okta, Active Directory, Entra ID, and Workday that govern access for internal and external users.
    • Administer Okta (SSO, MFA, adaptive authentication, lifecycle management, workflows) and enforce Zero Trust controls across IAM and endpoints, including device‑compliance‑based Conditional Access in Entra ID.
    • Design and maintain Joiner‑Mover‑Leaver (JML) workflows and role‑based access control (RBAC) frameworks in SailPoint IdentityNow, including role mining, entitlement mapping, provisioning, access certifications, and automated deprovisioning, to enforce least‑privilege access and meet regulatory requirements.
    • Run day‑to‑day IAM operations: SSO onboarding, MFA administration, access reviews, entitlement cleanup, HR‑driven lifecycle events, and platform upgrades.
    • Contribute to modernization of identity, endpoint, and access management platforms, driving initiatives that deliver measurable security, efficiency, and compliance value.
    • Support identity and access workstreams related to mergers, acquisitions, and divestitures.
  • AI & Automation
    • Apply AI to streamline IAM and endpoint operations within financial‑services compliance guardrails, and govern identities for agentic AI and non‑human identities (NHIs), including OAuth grant reviews, least‑privilege scoping, and extending JML to machine identities.
  • Operations & Support
    • Serve as an escalation point for executive‑level technical issues; interface effectively with senior stakeholders and their administrative teams to diagnose and resolve complex problems.
    • Own technical solutions end‑to‑end, from design and implementation through steady‑state operations, and build automation (PowerShell, Python) to streamline configuration management and reduce manual effort.
    • Resolve complex technical incidents, perform root‑cause analysis on high‑impact disruptions, meet SLOs, and serve as escalation point for the Service Desk on IAM and endpoint issues; maintain runbooks and technical documentation to support operational continuity.
  • Compliance & Governance
    • Support IAM and endpoint compliance programs (access recertifications, privileged‑account audits, endpoint posture assessments) and partner with Information Security, Legal, and Compliance on SOX, NIST, and ISO 27001 obligations.
  • Cross‑EPS Contribution
    • Contribute to other Enterprise Productivity Solutions workstreams as needed, including Microsoft 365 administration, broader Microsoft platform initiatives, virtual desktop solutions, and other end‑user technology platforms, staying versatile across the EPS portfolio while keeping IAM and endpoints as primary focus.
Requirements
  • Education & Certificates
    • Bachelor’s Degree or equivalent years of relevant experience (required).
    • Degree in Information Technology or similar engineering discipline (strongly preferred).
    • IAM‑focused certifications preferred (e.g., SailPoint IdentityNow Engineer, Okta Certified Professional/Administrator, SC‑300: Microsoft Identity and Access Administrator).
    • Microsoft endpoint certifications preferred (e.g., MD‑102: Microsoft 365 Endpoint Administrator, MS‑102: Microsoft 365 Administrator Expert).
    • Jamf certifications preferred (e.g., Jamf Certified Associate, Jamf Certified Tech, Jamf Certified Admin).
  • Professional Experience
    • 6+ years of overall relevant technical experience (required).
    • Experience in IT systems engineering with a focus on IAM, endpoint management, or related disciplines (required).
    • Expert‑level IAM skills spanning IGA, PAM, SSO, MFA, and RBAC, including role lifecycle, entitlement reviews, segregation of duties (SoD), and access certifications in SailPoint IdentityNow (preferred).
    • Experience supporting access governance audits and regulatory reviews; able to produce audit‑ready evidence for internal and external reviewers (preferred).
    • Experience developing automation scripts for IAM provisioning, endpoint configuration, and operational tasks (preferred).
    • Strong analytical and troubleshooting skills across complex, cross‑platform issues, including network connectivity fundamentals (preferred).
    • Clear communicator with technical and executive audiences; committed to white‑glove support for executive end users (preferred).
    • Proficient with project and service management tools (Jira, Confluence); able to manage and prioritize multiple concurrent initiatives (preferred).
    • Availability for on‑call rotation and willingness to support planned and unplanned maintenance during evenings and weekends as needed (required).
  • Competencies & Attributes
    • Microsoft Platform Stack (Active Directory, GPO, DNS, DHCP, Azure, Microsoft 365—Exchange, SharePoint, Teams, OneDrive, Power Automate); PowerShell modules including AAD, Exchange, MSOL (required).
    • AI Coding & Automation (e.g., Cursor, Claude Code, Codex) (preferred).
    • Microsoft Intune & Endpoint Management (Windows/iOS enrollment, Autopilot, Co‑management, device compliance policies, configuration profiles, app deployment, conditional access, device health attestation, LAPS, endpoint security policies, Defender for Endpoint integration) (required).
    • Identity & Privileged Access Management (Okta, SailPoint IdentityNow, CyberArk Vault/CPM/PSM, SAML, OIDC, RBAC, JIT access) (required).
    • Zero Trust Architecture (Conditional Access, device compliance enforcement, Zscaler, identity‑driven network segmentation, continuous verification) (required).
    • Compliance & Governance (SOX ITGCs, NIST 800‑53, ISO 27001, CIS Benchmarks, access recertification, audit evidence collection, endpoint posture assessment) (required).
    • Jamf (macOS/iPadOS Management, App Packaging/Deployments) (preferred).
    • Virtual Desktop Platforms (Azure Virtual Desktop, Windows 365) (preferred).
    • Scripting (PowerShell, Python, Bash, Visual Basic, Batch) (required).
    • AI & Agentic Security (Microsoft Copilot, AI‑assisted identity governance, agentic AI identity lifecycle management, machine identity governance, OAuth grant discovery, non‑human identity (NHI) controls, prompt engineering for IT operations, etc.) (preferred).
Benefits & Compensation

The compensation range for this role is specific to Washington, DC and takes into account a wide range of factors including but not limited to the skill sets required/preferred; prior experience and training; licenses and/or certifications. The anticipated base salary range for this role is $160,000 to $180,000. In addition to the base salary, the hired professional will enjoy a comprehensive benefits package spanning retirement benefits, health insurance, life insurance and disability, paid time off, paid holidays, family planning benefits and various wellness programs. Additionally, the hired professional may also be eligible to participate in an annual discretionary incentive program, the award of which will be dependent on various factors, including, without limitation, individual and organizational performance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineer, IAM & Endpoint Platform
Engineer, IAM & Endpoint Platform

The Carlyle Group • Washington

On-site
USD 160,000 - 180,000
Engineer, IAM & Endpoint Platform
Engineer, IAM & Endpoint Platform

1P284 THE CARLYLE GROUP EMPLOYEE CO., LLC • United States

On-site
USD 160,000 - 180,000
Lead IAM Engineer
Lead IAM Engineer

Blue Cross and Blue Shield of Massachusetts, Inc. • Boston (MA)

On-site
USD 163,000 - 200,000
Paid time off
Medical insurance
Dental insurance
+2
Identity Access Management Security Engineer
Identity Access Management Security Engineer

Highmark Health • United States

Hybrid
USD 86,400 - 138,600
Health insurance
Retirement plan
Professional development opportunities
Senior Systems Engineer - IAM
Senior Systems Engineer - IAM

Berkley Technology Services • Chicago (IL)

On-site
USD 121,000 - 137,000
Health insurance
Dental insurance
Vision insurance
+2
Senior Systems Engineer - IAM
Senior Systems Engineer - IAM

Berkley Technology Services • United States

On-site
USD 110,000 - 190,000
Base salary range: $107,000–$198,000
Comprehensive benefits package
Senior Systems Engineer - IAM
Senior Systems Engineer - IAM

Berkley Technology Services • Coppell (TX)

Hybrid
USD 107,000 - 198,000
IAM & Endpoint Platform Engineer: AI-Driven Automation
IAM & Endpoint Platform Engineer: AI-Driven Automation

The Carlyle Group • Washington

On-site
USD 160,000 - 180,000
Identity and Access Management (IAM) Subject Matter Expert (SME)
Identity and Access Management (IAM) Subject Matter Expert (SME)

Peraton • United States

On-site
USD 104,000 - 166,000
Senior IAM Engineer
Senior IAM Engineer

Socket.dev • Austin (TX)

On-site
USD 100,000 - 258,000
Equity
Medical Insurance
Vision Insurance
+2