Join a highly regulated, cloud-first digital assets business where identity is one of the most critical security controls in the organization. This is a senior individual contributor role with ownership across Identity & Access Management (IAM), Privileged Access Management (PAM), Identity Governance, secrets management, and cryptographic key governance.
We are looking for an engineer who enjoys building and automating security controls rather than simply administering access. You will own production identity platforms, lead the evolution of privileged access controls, drive automation, and partner closely with Security, Infrastructure, and Engineering teams.
What You'll Do
- Own the design, implementation, and lifecycle management of enterprise IAM and PAM platforms
- Build and automate identity processes including joiner, mover, leaver workflows, access certifications, credential rotation monitoring, and entitlement reviews
- Design least-privilege access models across AWS and Azure environments
- Implement and govern privileged access controls including just-in-time access, session management, and privileged account onboarding
- Develop integrations between identity platforms and broader security tooling using APIs, scripting, and Infrastructure as Code
- Lead access recertification programs and produce audit-ready evidence for regulatory and compliance reviews
- Drive secrets and certificate lifecycle initiatives, including rotation, inventory management, and governance
- Partner with Engineering and Platform teams to review identity, secrets, and access control designs
- Own technical vendor relationships, platform roadmaps, and proof-of-concept evaluations
- Support incident response and business continuity planning where identity or cryptographic controls are involved
What We’re Looking For
- Significant hands-on experience in IAM, Identity Security, or Privileged Access Engineering
- Deep experience administering, implementing, or redesigning enterprise PAM solutions such as CyberArk, BeyondTrust, Delinea, Teleport, StrongDM, or similar
- Strong Identity Governance experience using SailPoint, Saviynt, Zilla, or comparable platforms
- Experience with:
- Access certifications
- Entitlement modeling
- RBAC and least-privilege design
- Application onboarding and federation
- Strong AWS and Azure identity experience including:
- IAM roles and policies
- Identity federation
- Conditional Access
- Experience writing automation using Python, PowerShell, Terraform, APIs, or Infrastructure as Code
- Ability to work directly with auditors, risk teams, and engineering stakeholders
Nice to Have
- CyberArk Privilege Cloud, PSM, Secure Web Sessions, Conjur
- AWS IAM Identity Center
- Teleport, StrongDM, or Boundary
- AWS Secrets Manager, HashiCorp Vault, 1Password
- PKI, certificate lifecycle management, DigiCert, Entrust
- Financial services, fintech, digital assets, trading, or cryptocurrency experience
Why Join?
- Direct ownership of security-critical platforms
- Exposure to cloud-native infrastructure and modern security architecture
- Close partnership with senior security leadership
- Opportunity to shape and modernize identity controls through automation
- High-impact environment where security is a core business function, not an afterthought
This role is ideal for a CyberArk Engineer, PAM Engineer, Identity Security Engineer, SailPoint Engineer, or Senior IAM Engineer looking to take ownership of a modern identity security estate in a fast-growing regulated environment.