IAM Security Architect

Apex Systems

Indianapolis (IN)

On-site

USD 110,000 - 160,000

Full time

20 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical Insurance
401K with company match
ESPP
HSA
EAP
Training & certification support

Job summary

Everforth Apex Systems is seeking an IAM Engineer to design and implement secure identity solutions across AWS, Azure, and GCP. You will enforce least-privilege access, integrate with Okta and Azure AD, and drive identity governance, Zero Trust, and PAM programs.

The role emphasizes automation, infrastructure-as-code, and CI/CD integration to protect regulatory and privacy requirements in a multi-cloud environment.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
  • 5+ years of experience in IAM engineering or cloud security.
  • Hands-on experience with at least two major cloud providers (AWS, Azure, GCP).
  • Strong understanding of SAML, OAuth2, OIDC, LDAP, SCIM, and MFA technologies.
  • Experience implementing RBAC, ABAC, and least-privilege access models.
  • Familiarity with Zero Trust security architecture.
  • Experience with PAM solutions (CyberArk, BeyondTrust, Azure PIM, etc.).
  • Proficiency in scripting or automation (Python, PowerShell, Bash).
  • Experience with Infrastructure as Code (Terraform preferred).

Responsibilities

  • Design and implement IAM strategies across AWS, Azure, and GCP environments.
  • Develop and enforce least-privilege access models using RBAC and ABAC principles.
  • Implement and manage cloud-native IAM services (AWS IAM, Azure AD/Entra ID, GCP IAM).
  • Integrate cloud IAM with enterprise identity providers (Okta, Azure AD).
  • Establish identity governance controls, including access reviews, certifications, and role lifecycle management.
  • Implement Zero Trust access principles across cloud platforms.
  • Configure and manage Privileged Access Management (PAM) solutions.
  • Support regulatory and compliance requirements (HIPAA, SOC 2, ISO 27001, etc.).
  • Conduct IAM risk assessments and remediation planning.
  • Automate IAM provisioning and deprovisioning processes.
  • Develop infrastructure-as-code for IAM controls (Terraform, CloudFormation, ARM).
  • Integrate IAM controls into CI/CD pipelines.
  • Build automated monitoring and alerting for identity-related security events.
  • Monitor identity and access activities across cloud platforms.
  • Investigate and remediate IAM-related security incidents.
  • Partner with Security Operations and Cloud Engineering teams to improve identity threat detection.
  • Provide IAM subject matter expertise to cloud architects and application teams.
  • Review cloud designs to ensure secure identity integration.
  • Support cloud migration initiatives with secure identity architecture guidance.
  • Develop and maintain IAM standards, policies, and best practices documentation.

Skills

IAM engineering
Cloud security
AWS
Azure
GCP
SAML & OAuth
RBAC/ABAC
Zero Trust
Scripting (Python)
Terraform

Education

Bachelor’s degree in CS/Info Security

Tools

Okta
Azure AD/Entra ID
PAM (CyberArk/BeyondTrust)
Terraform

Job description

Job#: 3052716

Job Description
Overview

Our Client is seeking a highly skilled Identity & Access Management (IAM) Engineer with deep expertise in cloud security to support and enhance our multi-cloud environment. This role will focus on designing, implementing, and maintaining secure identity solutions across AWS, Azure, GCP, and other cloud platforms.

Key Responsibilities
Cloud IAM Architecture & Engineering
  • Design and implement IAM strategies across AWS, Azure, and GCP environments
  • Develop and enforce least-privilege access models using RBAC and ABAC principles
  • Implement and manage cloud-native IAM services (e.g., AWS IAM, Azure AD/Entra ID, GCP IAM)
  • Integrate cloud IAM with enterprise identity providers (e.g., Okta, Azure AD)
Security & Governance
  • Establish identity governance controls, including access reviews, certifications, and role lifecycle management
  • Implement Zero Trust access principles across cloud platforms
  • Configure and manage Privileged Access Management (PAM) solutions
  • Support regulatory and compliance requirements (HIPAA, SOC 2, ISO 27001, etc.)
  • Conduct IAM risk assessments and remediation planning
Automation & DevSecOps Integration
  • Automate IAM provisioning and deprovisioning processes
  • Develop infrastructure-as-code (Terraform, CloudFormation, ARM, etc.) for IAM controls
  • Integrate IAM controls into CI/CD pipelines
  • Build automated monitoring and alerting for identity-related security events
Monitoring & Incident Response
  • Monitor identity and access activities across cloud platforms
  • Investigate and remediate IAM-related security incidents
  • Partner with Security Operations and Cloud Engineering teams to improve identity threat detection
Collaboration & Advisory
  • Provide IAM subject matter expertise to cloud architects and application teams
  • Review cloud designs to ensure secure identity integration
  • Support cloud migration initiatives with secure identity architecture guidance
  • Develop and maintain IAM standards, policies, and best practices documentation
Required Qualifications
  • Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience)
  • 5+ years of experience in IAM engineering or cloud security
  • Hands-on experience with at least two major cloud providers (AWS, Azure, GCP)
  • Strong understanding of SAML, OAuth2, OIDC, LDAP, SCIM, and MFA technologies
  • Experience implementing RBAC, ABAC, and least-privilege access models
  • Familiarity with Zero Trust security architecture
  • Experience with PAM solutions (CyberArk, BeyondTrust, Azure PIM, etc.)
  • Proficiency in scripting or automation (Python, PowerShell, Bash)
  • Experience with Infrastructure as Code (Terraform preferred)
Preferred Qualifications
  • Cloud certifications (AWS Security Specialty, Azure Security Engineer, GCP Security Engineer)
  • IAM certifications (CISSP, CISM, CIAM, etc.)
  • Experience in regulated industries (healthcare, finance, etc.)
  • Experience with identity governance platforms (SailPoint, Saviynt, etc.)
  • Familiarity with container and Kubernetes identity security
  • Knowledge of API security and machine-to-machine authentication

Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our ‘Welcome Packet’ as well, which an Everforth Apex team member can provide.

Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.

Everforth Apex Systems is part of the Commercial Segment of Everforth, Inc.

NYSE: EFOR

4400 Cox Road

Suite 200

Glen Allen, Virginia 23060

© 2026 Everforth, Inc. All rights reserved.

Everforth Apex is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Benefits Department at [email protected] or 804-523-8228. (Do not submit resumes or solicit consultants to this email address). UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Systems Engineer MID - App Services NEN Tools Mgmt
Systems Engineer MID - App Services NEN Tools Mgmt

Apex Systems • San Diego (CA)

On-site
USD 110,000 - 150,000
Health insurance
401K with company match
ESPP (employee stock purchase)
IT Systems/Desktop Engineer
IT Systems/Desktop Engineer

Apex Systems • Denver (CO)

On-site
USD 85,000 - 125,000
Medical Benefits
401K program and ESPP
Okta Engineering Lead
Okta Engineering Lead

Apex Systems • Indianapolis (IN)

On-site
USD 120,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+5
Senior Cloud Platform Engineer
Senior Cloud Platform Engineer

Apex Systems • Austin (TX)

Hybrid
USD 140,000 - 180,000
401K with company match
HSA
ESPP
Network Security Analyst 1
Network Security Analyst 1

Apex Systems • Austin (TX)

On-site
USD 70,000 - 90,000
Medical, dental, vision insurance
401(k) with company match
Employee stock purchase program (ESPP)
+3
Full Stack Engineer
Full Stack Engineer

Apex Systems • Dearborn (MI)

Hybrid
USD 95,000 - 130,000
Medical, dental, vision insurance
401K with company match
HSA
+3
Cloud Engineer
Cloud Engineer

Apex Systems • Plano (TX)

Hybrid
USD 120,000 - 150,000
IT Strategy Manager
IT Strategy Manager

Apex Systems • Glen Allen (VA)

On-site
USD 140,000 - 190,000
Medical Insurance
401K + ESPP
HSA
Product Manager - Tech
Product Manager - Tech

Apex Systems • Phoenix (AZ)

Hybrid
USD 120,000 - 160,000
ESPP
401(k) program
Health Savings Account (HSA)
+3
Technical Program Manager
Technical Program Manager

Apex Systems • Charlotte (NC)

On-site
USD 96,000 - 138,000
Health insurance
401K with company match
ESPP (employee stock purchase program)
+2