Engineer Identity and Access Management

CFA Institute

Virginia (IL)

Hybrid

USD 80,000 - 115,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual incentive bonus
401(k) / Pension plan
Comprehensive medical benefits
Flexible work options
Generous leave
Wellness programs
Retirement plans

Job summary

CFA Institute is hiring an IAM Engineer to design, implement, and optimize identity services across a global tech ecosystem. You will work on SSO, MFA, identity governance, and access lifecycle, translating strategy into engineered solutions with strong automation focus.

The role emphasizes hands-on engineering, cross-team collaboration, and ongoing security improvements. It supports flexible work arrangements and requires 5–8 years in IAM, with expertise in Entra ID and modern authentication

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field.
  • 5–8 years of IAM, cybersecurity, or related engineering experience.
  • Hands-on experience implementing IAM technologies (SSO, MFA, identity governance, access lifecycle).
  • Strong proficiency in Microsoft Entra ID and Azure B2C and identity lifecycle management.
  • Experience with authentication protocols (SAML, OAuth, OIDC) and directory services.
  • Scripting/programming (PowerShell, Python) for automation and support.
  • System integration, API connectivity, and cloud identity architectures.
  • Understanding of IAM data structures, role modeling, and access control frameworks.
  • Ability to manage multi-system IAM environments and resolve issues.
  • Automation, metrics, and continuous improvement mindset.

Responsibilities

  • Design, build, configure, and enhance IAM solutions (SSO, MFA, access governance).
  • Develop integrations between IAM platforms and apps, infrastructure, and cloud services.
  • Implement authentication protocols and access control mechanisms.
  • Diagnose and resolve IAM system issues; lead root-cause analysis.
  • Develop scripts, automation, and tooling to improve provisioning and monitoring.
  • Support testing, validation, and deployment of IAM solutions.

Skills

IAM engineering
SAML/OIDC
PowerShell
Python
Azure Entra ID
Identity governance

Education

Bachelor's degree in Computer Science or related field

Job description

Are you excited to build and secure the identity services that power a modern enterprise? Do you enjoy solving complex authentication, access, and identity governance challenges at scale? Join CFA Institute as an IAM Engineer and design, implement, and optimize critical capabilities including SSO, MFA, identity governance, and access lifecycle management across a global technology ecosystem.

The Identity and Access Management (IAM) Engineer is responsible for designing, implementing, and continuously improving IAM systems, services, and controls. This role emphasizes deep technical contribution, solution engineering, and optimization of IAM platforms. The IAM Engineer translates IAM strategy into engineered solutions, develops and enhances identity services (SSO, MFA, identity governance, and access lifecycle), and ensures secure, scalable, and well-integrated IAM capabilities. The IAM Engineer works independently to solve complex technical problems, contributes to architecture and design decisions, and provides technical guidance across IAM initiatives. The position may be based in approved jurisdictions in the Unites States and reports to the Director Identity and Access Management. It is eligible for flexible work arrangements.

What You’ll Do
  • IAM Engineering & Solution Development
    • Design, build, configure, and enhance IAM solutions, including SSO, MFA, conditional access, identity lifecycle management, and access governance for both workforce and customer IAM.
    • Contribute to engineering design, prototyping, and feasibility testing of IAM solutions, ensuring scalability, reliability, and security.
    • Develop and maintain integrations between IAM platforms and enterprise applications, infrastructure, and cloud services.
    • Implement authentication protocols and access control mechanisms (e.g., SAML, OAuth, OIDC).
  • Programming, Troubleshooting & Technical Delivery
    • Diagnose and resolve complex IAM system issues, leading root-cause analysis and implementing sustainable fixes.
    • Participate in and lead technical troubleshooting efforts across identity systems and integrations.
    • Develop scripts, automation, and tooling to improve provisioning, monitoring, and access governance processes.
    • Support testing, validation, and deployment of IAM solutions, ensuring alignment with technical requirements.
  • Data, Process & Architecture Analysis
    • Analyze current-state IAM processes (joiner/mover/leaver, access reviews) and define optimized future-state workflows.
    • Collect and analyze IAM operational data to identify trends, inefficiencies, and improvement opportunities.
    • Contribute to IAM data architecture, including identity data models, role design, and entitlement structures.
  • Security & Risk Management
    • Implement and monitor IAM security controls, identifying vulnerabilities and recommending remediation actions.
    • Support cybersecurity risk management activities within IAM domains, ensuring alignment with enterprise standards.
    • Contribute to audit readiness through evidence collection, control validation, and documentation.
  • Continuous Improvement & Innovation
    • Identify and recommend technical enhancements to improve IAM platform performance, usability, and security posture.
    • Evaluate emerging IAM technologies and contribute to innovation initiatives and roadmap inputs.
    • Optimize workflows through automation, standardization, and engineering best practices.
What We’re Looking For
  • Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience)
  • 5–8 years of experience in IAM, cybersecurity, or related engineering roles.
  • Demonstrated hands-on experience implementing IAM technologies (SSO, MFA, identity governance, access lifecycle).
  • Strong proficiency in Microsoft Entra ID and Azure B2C and identity lifecycle management.
  • Experience with authentication protocols (SAML, OAuth, OIDC) and directory services.
  • Working knowledge of scripting/programming (e.g., PowerShell, Python) for automation and application support.
  • Experience with system integration, API-based connectivity, and cloud identity architectures.
  • Understanding of IAM data structures, role modeling, and access control frameworks.
  • Ability to manage complexity by analyzing multi-system IAM environments and resolving issues.
  • Optimizes work processes through automation, metrics, and continuous improvement.
  • Ensures accountability for technical deliverables and system performance.
  • Demonstrates strong technical problem-solving and analytical thinking.

We are not able to provide sponsorship at this time. No agencies, please.

Expected salary range: $80,400 - $115,000 per year. All salary ranges are subject to adjustment based on experience, education, and other factors relevant to the position including location.

Additional benefits include eligibility for an annual incentive bonus, a 12% employer contribution to a 401(k) or pension plan, and a comprehensive medical benefits package.

We care about our employees’ well-being, offering industry-leading benefits like:

  • Comprehensive health coverage for you and your family
  • Generous leave and time off
  • Competitive retirement plans
  • Flexible work options
  • Wellness, education, and support programs

We are an Equal Opportunity Employer. CFA Institute prohibits both discrimination and harassment with regard to all identifying characteristics: any individual employee, group of employees, or prospective employee on the basis of race, color, national origin, citizenship or immigration status, religion, creed or belief, age, marital or partnership status, marital or family status, care giver status, pregnancy and maternity, sexual and other reproductive health decisions, physical abilities/qualities, disability, sexual orientation, gender, gender identity or expression, predisposing genetic characteristic, military or veteran status, status as a victim or witness of domestic violence or sex offense or stalking, unemployment status, infectious disease carrier status, migrant worker status, educational background, socio-economic status, geographic location and culture or any other basis protected by applicable law. This policy impacts all aspects of employment, including but not limited to, recruitment, hiring, compensation, training, development, promotion, demotion, layoff, recall, furlough, transfer, leave of absence, and dismissal. This is a global policy that applies to all CFA Institute employees, regardless of location.

If, due to a disability or current medical condition, you need an accommodation or assistance to complete a job application, you can request one at any stage of the recruitment process. Please send an email to humanresources@cfainstitute.org noting the accommodations or assistance you are requesting. Please do not include any medical or health information in this email. We will review your request and contact you to discuss the possible options and arrangements. We will try our best to provide you with an accommodation or assistance that meets your needs and respects your preferences.

Our application is not compatible with Internet Explorer (IE). We recommend using Chrome.

Join a talented and diverse team supporting our mission to lead the global investment profession. When you work at CFA Institute, you become part of something bigger. We are a globally recognized organization committed to promoting the highest standards of ethics and professional excellence in the investment industry. The skills and experience you develop throughout your career directly support that mission. By investing in our people, we enable both our employees and our organization to succeed.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Engineer, IAM
Sr Engineer, IAM

Altice USA • Bethpage (NY)

On-site
USD 100,000 - 165,000
Sr Engineer, IAM
Sr Engineer, IAM

Altice USA • Plano (TX)

On-site
USD 100,000 - 165,000
Security Engineer (IAM)
Security Engineer (IAM)

Triwill Group • United States

On-site
USD 13,000 - 20,000
IAM Engineer
IAM Engineer

The Clearing House • North Carolina

Hybrid
USD 90,000 - 130,000
Engineer, IAM
Engineer, IAM

Altice USA • Bethpage (NY)

On-site
USD 90,000 - 130,000
Engineer, IAM
Engineer, IAM

Altice USA • Plano (TX)

On-site
USD 90,000 - 120,000
Identify Architect
Identify Architect

Finance of America • United States

On-site
USD 140,000 - 160,000
Health insurance
Dental & Vision
Life insurance
+2
Identity Access Management Security Engineer
Identity Access Management Security Engineer

Highmark Health • United States

Hybrid
USD 86,400 - 138,600
Health insurance
Retirement plan
Professional development opportunities
Lead IAM Engineer
Lead IAM Engineer

Blue Cross and Blue Shield of Massachusetts, Inc. • Boston (MA)

On-site
USD 163,000 - 200,000
Paid time off
Medical insurance
Dental insurance
+2
IAM Engineer-
IAM Engineer-

Associates Systems LLC • Irving (TX)

On-site
USD 120,000 - 160,000