Senior IAM Engineer - Cloud, PAM & AI Security

New York Life Insurance Co

United States

Remote

USD 124,000 - 177,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

New York Life Insurance Co. seeks an experienced IAM Engineer to design, implement, and operate IAM solutions across IGA, PAM, Directory, and WAM, spanning on‑premises and cloud environments.

You will automate lifecycles, integrate with MFA and passwordless methods, and collaborate with security and infra teams to meet compliance and audit needs. The role requires deep experience with SailPoint, CyberArk, Ping Identity, Entra, and AD, plus scripting in PowerShell, Python, or Java.

Qualifications

  • Bachelor’s degree in CS or IS or equivalent experience.
  • 10+ years hands-on engineering across IAM domains.
  • Strong knowledge of SailPoint, CyberArk, PingOne, PingFederate, Ping Directory, Entra and Active Directory.
  • Proven experience integrating IAM solutions in hybrid (cloud + on-prem) environments.
  • Familiarity with identity protocols such as SAML, OAuth 2.0, OIDC, SCIM, LDAP, SPIFFE, DCR, and PKCE.
  • Strong scripting skills (PowerShell, Python, Java) for automation and integration.
  • Understanding of IAM‑related compliance and regulatory requirements (e.g., NYS DFS, NIST).
  • Ability to work effectively in a team‑oriented, collaborative environment, with strong problem‑solving skills

Responsibilities

  • Engineer, configure, and maintain IAM solutions across IGA, PAM, Directory, and WAM domains.
  • Collaborate with architecture teams to design IAM solutions that integrate securely with on‑premises and cloud applications (AWS, SaaS, hybrid models).
  • Develop and maintain workflows, connectors, policies, and scripts to automate identity lifecycle and access management processes.
  • Integrate IAM solutions with enterprise authentication and authorization frameworks, including MFA, passwordless authentication, and emerging NHI standards (e.g., SPIFFE, DCR, PKCE).
  • Partner with Information Security, Application, and Infrastructure teams to ensure IAM solutions meet security, compliance, and audit requirements.
  • Troubleshoot and resolve complex IAM‑related incidents, performance issues, and integration challenges.
  • Support roadmap delivery for IAM initiatives, including cloud adoption, Zero Trust enablement, and modernization of legacy IAM services.
  • Contribute to solution design reviews, platform upgrades, and security hardening initiatives.
  • Explore and implement AI/ML‑based anomaly detection for identity risk scoring and adaptive authentication.
  • Build automation scripts (Python, PowerShell, Java) to enhance IAM workflows.
  • Collaborate on introducing AI‑driven decision‑making for access governance, identity‑based threat detection, and identity intelligence.
  • Stay engaged with emerging identity, cloud, and AI‑related technologies; bring forward ideas to evolve IAM for the future.

Skills

IAM engineering
SailPoint
CyberArk
Ping Identity
Active Directory
OAuth 2.0
OIDC
PowerShell
Python
Java
Cloud + on-prem

Education

Bachelor's degree in CS/IS or equivalent

Tools

SailPoint IdentityNow
CyberArk
PingFederate
PingOne
Azure AD
AWS IAM
Entra
Ping Directory
Active Directory

Job description

New York Life Insurance Co. seeks an experienced IAM Engineer to design, implement, and operate IAM solutions across IGA, PAM, Directory, and WAM, spanning on‑premises and cloud environments.

You will automate lifecycles, integrate with MFA and passwordless methods, and collaborate with security and infra teams to meet compliance and audit needs. The role requires deep experience with SailPoint, CyberArk, Ping Identity, Entra, and AD, plus scripting in PowerShell, Python, or Java.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior IAM Engineer — Hybrid, Cloud & Zero-Trust
Senior IAM Engineer — Hybrid, Cloud & Zero-Trust

New York Life • New York (NY)

Hybrid
USD 124,000 - 177,000
Discretionary bonus eligibility
Annual incentive program
Senior IAM & AI-Driven Security Engineer
Senior IAM & AI-Driven Security Engineer

HealthEquity • United States

On-site
USD 115,000 - 150,000
Medical, dental, and vision
HSA contribution and match
Dependent care FSA match
+6
Chief Authentication Architect & IAM Leader
Chief Authentication Architect & IAM Leader

New York Life Insurance Co • United States

Remote
USD 148,000 - 211,000
Full benefits package
Leave programs
Lead IAM Engineer & Architect — SailPoint Automation
Lead IAM Engineer & Architect — SailPoint Automation

Financial Industry Regulatory Authority, Inc. • Rockville (MD)

Hybrid
USD 131,000 - 238,000
Discretionary bonus
Health insurance
401(k) with company match
+1
IAM/Privileged Access Management Architect
IAM/Privileged Access Management Architect

InterSources Inc • New York (NY)

On-site
USD 120,000 - 160,000
Senior IAM Engineer - Identity & Access Management
Senior IAM Engineer - Identity & Access Management

Expand Energy • Spring (TX)

On-site
USD 140,000 - 170,000
Hybrid Senior IAM Engineer: Identity & Access Solutions
Hybrid Senior IAM Engineer: Identity & Access Solutions

The Guardian Life Insurance Company of America • Town of Bethlehem (NY)

Hybrid
USD 99,000 - 163,000
Privileged Access Management Engineer – PAM & Automation
Privileged Access Management Engineer – PAM & Automation

Pacific Life • United States

On-site
USD 138,000 - 168,000
Health insurance
Wellbeing Reimbursement Account
Paid Time Off
+2
Senior IAM Engineer: Identity Security & Access
Senior IAM Engineer: Identity Security & Access

GreatAmerica Financial Services Corporation • Iowa (LA), Northern (KY)

Hybrid
USD 120,000 - 170,000
Hybrid work arrangements
Health insurance
401(k) and company match
+1
Senior PAM Engineer - IAM & Privileged Access
Senior PAM Engineer - IAM & Privileged Access

Pacific Life • Newport Beach (CA)

On-site
USD 168,000 - 205,000
Health benefits
Paid time off
Parental leave
+1