Security Engineer, IAM
Posted 2hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Security Engineer governing identity access, privileged reviews, remediation, and exceptions. Supporting audit-ready IAM operations for a U.S.-based organization.
Responsibilities:
- Serve as the primary liaison between Security and Internal IT for access control, remediation tracking, and security control implementation
- Administer identity and access governance activities, including account lifecycle management, entitlement reviews, privileged access reviews, and account cleanup
- Coordinate recurring access review cycles, including monthly, quarterly, and annual certifications, privileged account reviews, role-change validations, inactive account reviews, and exception management processes
- Manage security exception requests, including intake, documentation, risk assessment support, approval routing, renewals, and status reporting
- Partner with People Operations and Internal IT to reconcile identity data, review orphaned accounts, and drive deprovisioning activities
- Support vulnerability remediation governance, including issue tracking, escalation, and formal exception documentation
- Prepare audit and compliance evidence related to access governance, privileged access management, remediation activities, and exception management
- Develop and maintain dashboards, metrics, and reporting on review completion rates, remediation status, exception aging, and ownership accountability
- Collaborate with Security, Internal IT, GRC, application owners, and business stakeholders on remediation and governance objectives
Requirements:
- Strong knowledge of identity lifecycle administration, access governance, privileged access management, entitlement governance, and deprovisioning workflows
- Knowledge of enterprise identity platforms, directory services, role-based access control (RBAC), and privileged access principles
- Experience coordinating access reviews, resolving account exceptions, and collaborating with technical and non-technical stakeholders
- Strong written and verbal communication skills to facilitate structured review and approval processes
- Ability to maintain audit-ready documentation and evidence within operational processes, SLAs, and governance frameworks
- Knowledge of formal exception management, including approvals, renewals, compensating controls, and risk acceptance procedures
- Familiarity with vulnerability governance, remediation tracking, security metrics, and reporting
- Experience creating dashboards, structured reporting, and metrics for governance and operational decision-making
- Scripting or automation experience supporting access reviews, remediation tracking, reporting, or evidence collection
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field, or equivalent combination of education and professional experience
- Minimum 4–6 years of experience in Identity and Access Management, Security Operations, Access Governance, or closely related security engineering
- Preferred experience with formal exception management programs and audit/compliance activities
- Preferred experience with automation, remediation governance, and security operations reporting
- Relevant certifications such as Security+, SC-300, CISSP, or comparable security and IAM certifications are preferred
- Ability to sit for prolonged periods and work at a computer
- Ability to lift up to 15 pounds at times



















