Lead Identity Access Management (IAM) Engineer/Architect

FINRA

Washington

Hybrid

USD 140,000 - 210,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid work environment
PTO and personal days (15/5) + 9 sick
Volunteer service days
Nine paid holidays

Job summary

FINRA is seeking a Lead IAM Engineer/Architect to guide enterprise IAM programs from planning to implementation. You will design, develop, and optimize SailPoint IdentityIQ solutions, building Java-based customizations and connectors, while advancing cloud access automation with Python/PowerShell in AWS/Azure environments.

The role requires strong governance, security, and collaboration skills, with leadership responsibilities and cross-functional project delivery in a hybrid work setting.

Qualifications

  • Bachelor's degree in Computer Science, Information Systems or related discipline with at least seven (7) years of related experience; Master's preferred.
  • Experience leading security architecture, secure software development, and governance programs.
  • Must have strong written and verbal communication and cross-functional collaboration skills.

Responsibilities

  • Lead enterprise IAM initiatives from planning through implementation.
  • Design and develop custom Java-based solutions within SailPoint IdentityIQ.
  • Architect scalable IAM solutions across hybrid environments.
  • Lead the development of connectors and workflow configurations in SailPoint.
  • Build cloud access automation using Python/PowerShell (AWS/Azure).
  • Mentor junior engineers and lead cross-functional IAM transformation projects.
  • Partner with security/compliance teams on governance frameworks.
  • Communicate complex IAM concepts to non-technical stakeholders.
  • Contribute to Agile/Scrum project delivery and sprint planning.

Skills

IAM architecture
SailPoint IdentityIQ
Java development
AWS/Azure cloud
Python/PowerShell
Hybrid environment
Security governance
Agile/Scrum
Active Directory/Azure AD
Leadership/mentorship

Education

Bachelor's degree in Computer Science or related field
Master's degree and financial services experience preferred

Tools

SailPoint IdentityIQ
Java
AWS
Azure
Active Directory

Job description

The Lead IAM Engineer/Architect leads enterprise IAM initiatives from planning through implementation, develops custom Java-based solutions within SailPoint IdentityIQ, and builds cloud access automation using Python/PowerShell. This role manages complex access provisioning and deprovisioning workflows and partners with security and compliance teams on governance frameworks. This position reports directly to a Director or Senior Director.

Essential Job Functions
Architectural Leadership & Design
  • Lead enterprise IAM initiatives from planning through implementation
  • Design and develop custom Java-based solutions within SailPoint IdentityIQ
  • Lead the architecture of robust, scalable IAM solutions across hybrid environments
  • Collaborate on system architecture decisions and integration patterns
  • Design role modeling and certification campaigns
Engineering Excellence & Quality
  • Write and modify Java code within SailPoint for custom business logic (not just scripting - actual application development)
  • Develop custom connectors and perform connector customization
  • Configure and optimize workflow configuration
  • Lead implementation of comprehensive testing strategies for IAM solutions
  • Troubleshoot complex identity issues across hybrid environments
  • Strong SailPoint IdentityIQ administration/development and hands-on Java programming experience
DevOps & Infrastructure
  • Build and maintain AWS/Azure cloud access automation using Python/PowerShell
  • Implement AWS IAM with hands-on policy creation and automation
  • Manage complex access provisioning/deprovisioning workflows
  • Integrate Active Directory/Azure AD administration and integration
  • Create and maintain technical documentation for audit purposes
Mentorship & Cultural Leadership
  • Mentor junior engineers on SailPoint development, IAM architecture, and security best practices
  • Coach and train colleagues in best practices for IAM development
  • Lead cross-functional teams on IAM transformation projects
  • Champion collaborative resolution of complex identity issues
  • Provide feedback on processes and recommend improvements
Product & Stakeholder Collaboration
  • Partner with security and compliance teams on governance frameworks
  • Communicate complex IAM concepts to non-technical stakeholders
  • Openly share progress and priorities with key stakeholders
  • Lead projects using Agile/Scrum methodologies
  • Work under pressure and coordinate across multiple teams simultaneously
Security & Compliance
  • Ensure all work products meet enterprise security standards
  • Lead secure coding practices for IAM components
  • Create and maintain technical documentation for audit purposes
  • Design solutions supporting governance and compliance requirements
Education/Experience Requirements
  • Bachelor's degree in Computer Science, Information Systems or related discipline with at least seven (7) years of related experience, or equivalent training and/or work experience;
  • Master's degree and past Financial Services industry experience preferred.
  • Experience must include direct experience in leading key areas such as: securing networks and systems architecture, design and implementation, secure software assurance, intrusion detection, defense and incident response, security configuration management, access controls design and implementation and security policy and standards development.
  • In-depth knowledge of more than one communications protocol.
  • Experience managing several Cyber Security tools, including: Configuration Assessment, Log Aggregation, Integrity Verification, Web Application Security Testing, Network Access Control System, Network Intrusion prevention systems, and Endpoint Security Solutions.
  • Strong written and verbal technical communication skills.
  • Demonstrated ability to develop effective working relationships that improved the quality of work products.
  • Should be well organized, thorough, and able to handle competing priorities.
  • Ability to maintain focus and develop proficiency in new skills rapidly.
  • Ability to work in a fast paced environment.
  • Excellent planning skills.
  • Willingness to accept new challenges and grasp new or changing concepts, technologies and procedures.
  • In-depth knowledge across all areas of Information Security.
Work Conditions
  • Hybrid work environment, with defined in-person presence requirements.
  • Occasional travel and extended hours may be required.

For work that is performed in CO, FL, TX, IL, PA, MA, MD, VA, Washington, DC, NY and NJ, please refer to the chart below for the salary range for the corresponding location. FINRA complies with all state and local pay transparency laws and regulations requiring the disclosure of salary ranges for the position. In addition to location, actual compensation is based on various factors, including but not limited to, the candidate's skill set, level of experience, education, and market considerations.

CO/FL/TX: Minimum Salary $114,200, Maximum Salary $207,200

IL/PA: Minimum Salary $125,900, Maximum Salary $228,000

MA/MD/VA/Washington, DC: Minimum Salary $131,200, Maximum Salary $238,300

NY/NJ: Minimum Salary $131,200, Maximum Salary $248,700

#LI-Hybrid

The information provided above has been designed to indicate the general nature and level of work of the position. It is not a comprehensive inventory of all duties, responsibilities and qualifications required.

Time Off and Paid Leave*

FINRA encourages its employees to focus on their health and wellness in many ways, including through a generous time-off program of 15 days of paid time off, 5 personal days and 9 sick days, unless otherwise required by law (all pro-rated in the first year). Additionally, we are proud to support our communities by providing two volunteer service days (based on full-time schedule). Other paid leave includes military leave, jury duty leave, bereavement leave, voting and election official leave for federal, state or local primary and general elections, care of a family member leave (available after 90 days of employment); and childbirth and parental leave (available after 90 days of employment). Full-time employees receive nine paid holidays.

*Based on full-time schedule

Important Information

FINRA's Code of Conduct imposes restrictions on employees' investments and requires financial disclosures that are uniquely related to our role as a securities regulator. FINRA employees are required to disclose to FINRA all brokerage accounts that they maintain, and those in which they control trading or have a financial interest (including any trust account of which they are a trustee or beneficiary and all accounts of a spouse, domestic partner or minor child who lives with the employee) and to authorize their broker-dealers to provide FINRA with duplicate statements for all of those accounts.

All of those accounts are subject to the Code's investment and securities account restrictions, and new employees must comply with those investment restrictions- including disposing of any security issued by a company on FINRA's Prohibited Company List or obtaining a written waiver from their Executive Vice President- by the date they begin employment with FINRA. Employees may only maintain securities accounts that must be disclosed to FINRA at one or more securities firms that provide an electronic feed (e-feed) of data to FINRA, and must move securities accounts from other securities firms to a firm that provides an e-feed within three months of beginning employment.

You can read more about these restrictions here.

As standard practice, employees must also execute FINRA's Employee Confidentiality and Invention Assignment Agreement without qualification or modification and comply with the company's policy on nepotism.

Search Firm Representatives

Please be advised that FINRA is not seeking assistance or accepting unsolicited resumes from search firms for this employment opportunity. Regardless of past practice, a valid written agreement and task order must be in place before any resumes are submitted to FINRA. All resumes submitted by search firms to any employee at FINRA without a valid written agreement and task order in place will be deemed the sole property of FINRA and no fee will be paid in the event that person is hired by FINRA.

FINRA is an Equal Opportunity Employer

All qualified applicants receive consideration for employment without regard to any legally protected category, including race, color, age, national origin, ethnicity, religion, disability, genetic information, military or veteran status, sex, or any other status or classification protected by state or local law.

FINRA strives to make our career site accessible to all users. If you need a disability-related accommodation for completing the application process, please contact FINRA's Employee Relations team at 240-386-4865 or by email at EmployeeRelations@FINRA.org. Please note that this process is exclusively for inquiries regarding accommodations in the application process.

FINRA abides by the requirements of 41 CFR 60-741.5(a). This regulation prohibits discrimination against qualified individuals on the basis of disability and requires affirmative action by covered prime contractors and subcontractors to employ and advance in employment qualified individuals with disabilities.

FINRA abides by the requirements of 41 CFR 60-300.5(a). This regulation prohibits discrimination against qualified protected veterans and requires affirmative action by covered prime contractors and subcontractors to employ and advance in employment qualified protected veterans.

©2026 FINRA. All rights reserved. FINRA is a registered trademark of the Financial Industry Regulatory Authority, Inc.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Identity Access Management (IAM) Engineer/Architect
Lead Identity Access Management (IAM) Engineer/Architect

FINRA • Rockville (MD)

Hybrid
USD 131,000 - 238,000
Health insurance
401(k) plan with company match
Tuition reimbursement
+2
Lead Product Manager - Enterprise Data Inventory
Lead Product Manager - Enterprise Data Inventory

FINRA • Rockville (MD)

Hybrid
USD 131,000 - 238,000
Discretionary bonus
Health, dental & vision insurance
401(k) with company match
Lead Identity Access Management (IAM) Engineer/Architect
Lead Identity Access Management (IAM) Engineer/Architect

Financial Industry Regulatory Authority, Inc. • Washington

Hybrid
USD 131,000 - 238,000
Senior Advisor: Market Regulation & Regulatory Service Agreement (RSA)
Senior Advisor: Market Regulation & Regulatory Service Agreement (RSA)

FINRA • Washington

Hybrid
USD 181,000 - 356,000
Senior Analyst, MS Operations & Procedures
Senior Analyst, MS Operations & Procedures

FINRA • New York (NY)

On-site
USD 93,000 - 200,000
Associate Director / Lead Engineer, GenAI
Associate Director / Lead Engineer, GenAI

FINRA • Rockville (MD)

Hybrid
USD 131,000 - 238,000
Health insurance
401(k) match
Tuition reimbursement
+1
Principal Counsel, Regulatory
Principal Counsel, Regulatory

FINRA • Washington

Hybrid
USD 125,000 - 230,000
Health, dental and vision insurance
401(k) with company match
Tuition reimbursement
+3
Principal Analyst, MS Operations, Procedures and Standards - All FINRA Locations at FINRA New Y[...]
Principal Analyst, MS Operations, Procedures and Standards - All FINRA Locations at FINRA New Y[...]

FINRA • New York (NY)

On-site
USD 93,000 - 200,000
Lead Security Engineer
Lead Security Engineer

FINRA • Rockville (MD)

Hybrid
USD 131,000 - 238,000
Health, dental and vision insurance
401(k) plan with company match
Tuition reimbursement
+4
Director, Transparency Services Equities
Director, Transparency Services Equities

FINRA • New York (NY)

Hybrid
USD 154,000 - 313,000
Hybrid work environment
Some travel required