Information Security Identity & Access Management Engineer

Johnson Financial Group

Racine (WI)

On-site

USD 110,000 - 150,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Johnson Financial Group is seeking an Information Security IAM Engineer to design, implement, and support enterprise identity and access capabilities across cloud and on-prem environments. You will manage identity lifecycle, IGA, and PAM while ensuring least-privilege access and auditable compliance.

Collaborate with IT, architecture, HR, and business stakeholders to deliver scalable identity solutions and runbooks, driving automation and security for EIAM and CIAM initiatives.

Qualifications

  • Bachelor’s degree in information security, cybersecurity, computer science, information systems, or related field.
  • 5–8 years of experience.
  • Cybersecurity certifications preferred (e.g., Microsoft AZ-500, Security+, SSCP, JFG InfoSec Platforms).
  • Experience with Python and PowerShell scripting languages for automation preferred.

Responsibilities

  • Design, implement, and maintain enterprise IAM solutions, including identity lifecycle, authentication, authorization, and federation.
  • Engineer and operate IGA capabilities such as provisioning/deprovisioning, access certifications, and RBAC.
  • Implement and support PAM controls including vaulting, session management, and least privilege enforcement.
  • Support EIAM and CIAM solutions across cloud and hybrid environments.
  • Operate and enhance user access reviews and certification processes for audit compliance.
  • Maintain visibility and reporting on user access activity, entitlements, and privileged usage.
  • Collaborate with IT Architects to design scalable IAM architectures aligned to zero trust principles.
  • Integrate IAM with enterprise platforms (e.g., Microsoft Entra ID, SaaS apps, on-prem AD).
  • Build automation for identity provisioning workflows, access enforcement, and reporting.
  • Develop and maintain runbooks, workflows, and SOPs.
  • Drive continuous improvement through process optimization and measurable efficiency gains.
  • Partner with HR, IT, app owners, and business units to align access models to job functions.
  • Act as technical SME for IAM and translate security requirements into business-aligned solutions.
  • Deliver IAM operational metrics, dashboards, and KPIs.

Skills

IAM engineering
RBAC
Zero Trust
Stakeholder management
Communication

Education

Bachelor’s Degree in Information Security

Tools

Python
PowerShell
Microsoft Entra ID
Active Directory
Linux

Job description

Overview

The Information Security Identity & Access Management (IAM) Engineer is responsible for engineering, implementing, and supporting enterprise identity and access capabilities that protect JFG systems and data through strong authentication, authorization, and access governance. Working under the direction of the Information Security Engineer & Operations Manager, this position focuses on Identity Lifecycle Management, Identity Governance & Administration (IGA), and Privileged Access Management (PAM) to ensure timely, appropriate, and auditable access aligned to business roles and the principle of least privilege. The engineer partners cross-functionally with IT, architecture, HR, and business stakeholders to deliver scalable identity solutions that enable secure business operations. Consistent with industry trends, this role requires a broad, cross-functional skillset across IAM, security architecture & engineering, and data protection, rather than deep specialization in a single domain. The role contributes to the design and continuous improvement of zero trust-aligned access controls, ensuring integration with cloud, on-prem, and customer identity platforms. This is an individual contributor role that may provide technical leadership and mentorship. Occasional off-hour and on-call support may be required. Less than 5% travel expected.

Key Responsibilities
  • Design, implement, and maintain enterprise IAM solutions, including identity lifecycle, authentication, authorization, and federation
  • Engineer and operate Identity Governance & Administration (IGA) capabilities such as provisioning/deprovisioning, access certifications, and role-based access control (RBAC)
  • Implement and support Privileged Access Management (PAM) controls including vaulting, session management, and least privilege enforcement
  • Support both enterprise identity (EIAM) and customer identity (CIAM) solutions across cloud and hybrid environments
  • Operate and enhance user access reviews (UARs) and certification processes to ensure appropriate access and audit compliance
  • Maintain visibility and reporting on user access activity, entitlements, and privileged usage
  • Partner with Risk and Audit functions to support controls testing, evidence collection, and regulatory requirements
  • Collaborate with IT Architects to design scalable IAM architectures aligned to modern zero trust principles
  • Integrate IAM capabilities with enterprise platforms (e.g., Microsoft Entra ID, SaaS applications, on-prem AD)
  • Contribute to security architecture & engineering initiatives, ensuring identity is embedded into system designs
  • Build and maintain automation for identity provisioning workflows, access enforcement, and reporting
  • Develop and maintain runbooks, workflows, and standard operating procedures
  • Drive continuous improvement through process optimization and measurable efficiency gains
  • Partner with HR, IT, application owners, and business units to align access models to job functions (“need-to-know”)
  • Act as a technical SME for IAM, translating security requirements into business-aligned solutions
  • Demonstrate strong communication and stakeholder management skills, enabling adoption across non-technical teams
  • Support and deliver IAM operational metrics, dashboards, and KPIs
  • Contribute to program maturity improvements across Identity & Access Management services
  • Provide technical leadership and mentorship to junior engineers or project team members
  • Lead IAM-related initiatives or workstreams to ensure delivery of InfoSec services
Education, Knowledge, and Skills
  • Bachelor’s Degree in Information Security, Cybersecurity, Computer Science, Information Systems, or related field
  • 5-8 years' experience
  • Cybersecurity Certifications preferred: Microsoft AZ-500, Security+, SSCP, JFG InfoSec Platforms
  • Experience with Python and PowerShell scripting languages for automation preferred
  • Works without supervision
  • Expert report writing and communication skills
  • Strong collaboration skills to work with other IS and IT engineers and business partners to solve problems effectively
  • Has strong understanding of Information Security platforms at JFG
  • Has strong understanding of common Information Security controls and frameworks
  • Has a strong understanding of networking concepts and technologies
  • Has a strong understanding of Windows and Linux environments
  • Can operate beyond instruction and guidelines where needed
  • Has strong understanding of both cybersecurity industry and financial services industry allowing them to revise existing processes/standards or establish new processes/standards as needed
  • Takes complete ownership of all RunBook, support, and process documentation for their service portfolio
For Senior Level
  • 8+ years of experience for a Senior level role
  • Ability to guide work of other team members
  • Expert level understanding of security controls
  • Ability to identify operational capability gaps and establish roadmaps / strategies
Come as you are.

Come as You Are.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Identity & Access Management (IAM) Engineer
Sr. Identity & Access Management (IAM) Engineer

NKC Health • Kansas City (MO)

On-site
USD 100,000 - 130,000
Sr Identity and Access Management Analyst
Sr Identity and Access Management Analyst

Chicago Bridge & Iron Company • The Woodlands (TX)

On-site
USD 100,000 - 130,000
Senior Manager of Identity Access Management (IAM)
Senior Manager of Identity Access Management (IAM)

Optimize Search Group • Plano (TX)

On-site
USD 140,000 - 190,000
IAM Engineer
IAM Engineer

The Clearing House • North Carolina

Hybrid
USD 90,000 - 130,000
Sr. Identity and Access Management Analyst
Sr. Identity and Access Management Analyst

CB&I • The Woodlands (TX)

On-site
USD 120,000 - 170,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000
Cybersecurity Engineer
Cybersecurity Engineer

ssacareers • Washington

Remote
USD 130,000 - 160,000
IT Security and IAM Engineer/Administrator
IT Security and IAM Engineer/Administrator

Cypress HCM • Cincinnati (OH)

On-site
USD 70,000 - 90,000
Benefits
Community Involvement
PTO
+2
Information Security Identity and Access Engineer
Information Security Identity and Access Engineer

PSECU • Harrisburg

Hybrid
USD 120,000 - 170,000
Staff Identity Governance and Access Engineer
Staff Identity Governance and Access Engineer

United States Digital Space LLC • Washington

On-site
USD 180,000 - 230,000