About this opportunity
Storm2 lists this Senior IAM Engineer opportunity in new york, New York. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Join a highly regulated, cloud-first digital assets business where identity is one of the most critical security controls in the organization. This is a senior individual contributor role with ownership across Identity & Access Management (IAM), Privileged Access Management (PAM), Identity Governance, secrets management, and cryptographic key governance.
We are looking for an engineer who enjoys building and automating security controls rather than simply administering access. You will own production identity platforms, lead the evolution of privileged access controls, drive automation, and partner closely with Security, Infrastructure, and Engineering teams.
What You'll Do
Own the design, implementation, and lifecycle management of enterprise IAM and PAM platforms
Build and automate identity processes including joiner, mover, leaver workflows, access certifications, credential rotation monitoring, and entitlement reviews
Design least-privilege access models across AWS and Azure environments
Implement and govern privileged access controls including just-in-time access, session management, and privileged account onboarding
Develop integrations between identity platforms and broader security tooling using APIs, scripting, and Infrastructure as Code
Lead access recertification programs and produce audit-ready evidence for regulatory and compliance reviews
Drive secrets and certificate lifecycle initiatives, including rotation, inventory management, and governance
Partner with Engineering and Platform teams to review identity, secrets, and access control designs
Own technical vendor relationships, platform roadmaps, and proof-of-concept evaluations
Support incident response and business continuity planning where identity or cryptographic controls are involved
What We’re Looking For
Significant hands-on experience in IAM, Identity Security, or Privileged Access Engineering
Deep experience administering, implementing, or redesigning enterprise PAM solutions such as CyberArk, BeyondTrust, Delinea, Teleport, StrongDM, or similar
Strong Identity Governance experience using SailPoint, Saviynt, Zilla, or comparable platforms
Experience with:
Access certifications
Entitlement modeling
RBAC and least-privilege design
Application onboarding and federation
Strong AWS and Azure identity experience including:
IAM roles and policies
Identity federation
Conditional Access
Experience writing automation using Python, PowerShell, Terraform, APIs, or Infrastructure as Code
Ability to work directly with auditors, risk teams, and engineering stakeholders
Nice to Have
CyberArk Privilege Cloud, PSM, Secure Web Sessions, Conjur
AWS IAM Identity Center
Teleport, StrongDM, or Boundary
AWS Secrets Manager, HashiCorp Vault, 1Password
PKI, certificate lifecycle management, DigiCert, Entrust
Financial services, fintech, digital assets, trading, or cryptocurrency experience
Why Join?
Direct ownership of security-critical platforms
Exposure to cloud-native infrastructure and modern security architecture
Close partnership with senior security leadership
Opportunity to shape and modernize identity controls through automation
High-impact environment where security is a core business function, not an afterthought
This role is ideal for a CyberArk Engineer, PAM Engineer, Identity Security Engineer, SailPoint Engineer, or Senior IAM Engineer looking to take ownership of a modern identity security estate in a fast-growing regulated environment.
#J-18808-Ljbffr
Worksite address
new york, NY, 10261, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.