IAM Engineer

Applied IAM

Northern (KY)

Hybrid

USD 70,000 - 110,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

AppliedIAM is seeking an IAM Engineer to contribute to client delivery work that improves visibility and reduces risk across identity governance, access controls, and integrations. You will build detections, dashboards, and runbooks while collaborating with a client-facing team to enhance identity security posture.

You’ll onboard telemetry from IdP/IGAs, validate logs, and automate tasks with Python or PowerShell, supporting cloud and endpoint sources as you learn and grow in a security-focused

Qualifications

  • Bachelor's or Master's degree in Computer Science, Cybersecurity, Engineering, or a closely related field.
  • Strong fundamentals in networking and systems, and a working understanding of authentication.
  • Interest in identity security and access controls (SSO, MFA, least privilege, privileged access).
  • Basic understanding of REST APIs (HTTP methods, JSON, and token-based authentication) and comfort using tools like Postman/cURL.
  • Comfort reading and interpreting logs and documenting findings.
  • Basic cloud familiarity (AWS/Azure/GCP) and willingness to learn how identity and access work in cloud environments.
  • Ability to automate small tasks or data pulls using Python or PowerShell.
  • Clear written communication and comfort collaborating in a client-facing team.
  • Authorization to work in the United States.

Responsibilities

  • Work with the AppliedIAM team to identify critical identity signals (SSO/MFA, privileged access, service accounts) and define what “good logging” looks like
  • Onboard and validate telemetry from identity and access platforms (IdP/IGA/PAM), plus supporting cloud and endpoint sources, to improve investigation readiness
  • Build and tune detections focused on identity risk (anomalous sign-ins, MFA abuse, privilege escalation, excessive entitlements, and service-account misuse)
  • Create lightweight dashboards and recurring summaries that help clients understand identity security posture and trends
  • Enrich alerts using APIs and automation (Python/PowerShell) to add context like user attributes, group membership, roles, device details, and recent changes
  • Support investigations by collecting timelines, preserving evidence, and drafting clear incident notes and recommended next steps
  • Assist with security checks (vulnerability scans and configuration reviews) and track remediation items to closure with engineering teams
  • Help validate IAM controls (MFA/conditional access, least privilege, privileged workflows) and document improvement opportunities
  • Contribute to internal runbooks and knowledge base articles so common response tasks are consistent and repeatable

Skills

Networking fundamentals
Systems fundamentals
Identity security concepts
REST APIs
Python scripting
Written communication
US work authorization

Education

B.S. or M.S. in Computer Science or related field

Tools

Postman
cURL
Git/GitHub
Cloud familiarity (AWS/Azure/GCP)

Job description

At AppliedIAM, we treat identity as the control plane for modern security. As an IAM Engineer, you'll contribute to client delivery work that improves visibility and reduces risk—supporting identity governance, access controls, and integrations while building practical, job-ready engineering skills.

Core Responsibilities
  • Work with the AppliedIAM team to identify critical identity signals (SSO/MFA, privileged access, service accounts) and define what “good logging” looks like
  • Onboard and validate telemetry from identity and access platforms (IdP/IGA/PAM), plus supporting cloud and endpoint sources, to improve investigation readiness
  • Build and tune detections focused on identity risk (anomalous sign-ins, MFA abuse, privilege escalation, excessive entitlements, and service-account misuse)
  • Create lightweight dashboards and recurring summaries that help clients understand identity security posture and trends
  • Enrich alerts using APIs and automation (Python/PowerShell) to add context like user attributes, group membership, roles, device details, and recent changes
  • Support investigations by collecting timelines, preserving evidence, and drafting clear incident notes and recommended next steps
  • Assist with security checks (vulnerability scans and configuration reviews) and track remediation items to closure with engineering teams
  • Help validate IAM controls (MFA/conditional access, least privilege, privileged workflows) and document improvement opportunities
  • Contribute to internal runbooks and knowledge base articles so common response tasks are consistent and repeatable
Minimum Qualifications
  • Bachelor's or Master's degree (in progress or recently completed) in Computer Science, Cybersecurity, Engineering, or a closely related field
  • Strong fundamentals in networking and systems (TCP/IP, DNS, Windows/Linux basics) and a working understanding of authentication
  • Interest in identity security and access controls (SSO, MFA, least privilege, privileged access)
  • Basic understanding of REST APIs (HTTP methods, JSON, and token-based authentication) and comfort using tools like Postman/cURL
  • Comfort reading and interpreting logs (sign-in events, admin actions, audit trails) and documenting what you find
  • Basic cloud familiarity (AWS/Azure/GCP) and willingness to learn how identity and access work in cloud environments
  • Ability to automate small tasks or data pulls using Python or PowerShell
  • Clear written communication and comfort collaborating in a client-facing team
  • Authorization to work in the United States
Preferred Qualifications
  • Exposure to IAM platforms and workflows (SailPoint, CyberArk, Okta, Saviynt) through coursework, labs, or projects
  • Familiarity with identity standards and protocols (SAML, OIDC/OAuth2, SCIM) and how they show up in logs
  • Experience building small integrations or automations using APIs (data pulls, enrichment, simple connectors)
  • Understanding of common identity attack paths (credential stuffing, token theft, MFA fatigue, privilege escalation) and where to detect them
  • Evidence of practical work (home lab, GitHub projects, write-ups, dashboards, scripts, or detection experiments)
  • Comfort using Git/GitHub for collaboration and documentation
What You’ll Get
Compensation

Competitive compensation aligned to the role and location

Flexible setup

A schedule and work style that supports outcomes

Growth & feedback

Regular guidance and practical learning

Applicants have rights under federal employment laws:
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IAM Engineer-
IAM Engineer-

Associates Systems LLC • Irving (TX)

On-site
USD 120,000 - 160,000
IAM Engineer
IAM Engineer

Accenture Federal Services • Washington

On-site
USD 64,000 - 222,000
Sr. IAM Engineer
Sr. IAM Engineer

IDMWORKS • Oregon (WI)

Hybrid
USD 115,000 - 160,000
IAM Engineer
IAM Engineer

Ampcus Inc • Gaithersburg (MD)

On-site
USD 80,000 - 120,000
IAM Engineer
IAM Engineer

Mindlance • Charlotte (NC)

On-site
USD 120,000 - 170,000
IAM Engineer
IAM Engineer

Tata Consultancy Services • Sunnyvale (CA)

On-site
USD 80,000 - 104,000
IT Security and IAM Engineer/Administrator
IT Security and IAM Engineer/Administrator

Cypress HCM • Cincinnati (OH)

On-site
USD 70,000 - 90,000
Benefits
Community Involvement
PTO
+2
IAM Engineer
IAM Engineer

Swoon • United States

Hybrid
USD 90,000 - 120,000
Identity Security & Access Engineer
Identity Security & Access Engineer

Applied IAM • Northern (KY)

Hybrid
USD 70,000 - 110,000
IAM (Sailpoint) Architect (REMOTE)
IAM (Sailpoint) Architect (REMOTE)

Conexess Group • Livonia (MI)

On-site
USD 90,000 - 130,000