freehire launches on Product Hunt on 26 August.

Follow →

Identity & Access Management (IAM) Engineer III

Open 66d

Summary
We are seeking a Senior Identity & Access Management (IAM) Engineer to design, implement, and manage enterprise identity solutions across on premises and cloud environments. This role will serve as a technical authority for IAM architecture, leading initiatives across Identity Governance & Administration (IGA), Privileged Access Management (PAM), Single Sign On (SSO), and Multi Factor Authentication (MFA), while ensuring secure, scalable, and compliant identity services. The ideal candidate combines deep, hands on engineering experience with strong architectural skills and can partner closely with security, infrastructure, cloud, and application teams.

Visa Sponsorship Available
No

Minimum Requirements
Combination of Education and Experience will be considered. Must be authorized to work in the US as defined by the Immigration Act of 1986. Must pass a Criminal Background Check.
Education: Bachelor’s Degree in cybersecurity or Computer Science.
Certification: IAM or Cyber related certifications.
Years of Experience: Minimum seven (7) years of experience in related field.

Preferred Requirements
• Strong hands on experience implementing and supporting IGA, PAM, SSO, MFA, and identity federation solutions.
• Experience implementing Conditional Access, adaptive authentication, and Zero Trust identity controls.
• Experience securing machine identities, service accounts, and workload identities.
• Familiarity with Identity Threat Detection & Response (ITDR) concepts and tooling.
• Strong understanding of Active Directory, LDAP, Kerberos, and enterprise directory services.
• Experience designing and implementing enterprise IAM architectures.
• Solid understanding of authentication and authorization protocols (SAML, OAuth 2.0, OpenID Connect, LDAP).
• Experience managing cloud identity services (Azure AD / Entra ID, AWS IAM, GCP IAM).
• Strong scripting or automation skills (PowerShell, Python, Bash, or similar).
• Experience integrating IAM with SaaS, cloud, and custom applications.
• Strong understanding of Zero Trust and identity centric security principles.
• Ability to translate business requirements into secure technical solutions.
• Experience with common IAM platforms (e.g., SailPoint, Saviynt, Okta, Ping, CyberArk, BeyondTrust, Delinea).
• Experience supporting regulatory or compliance frameworks (SOX, PCI, HIPAA, SOC 2).
• Cloud security or IAM related certifications (e.g., CISSP, CCSP, Microsoft Identity certifications, AWS Security).
• Experience with access reviews, certification campaigns, segregation of duties (SoD), and audit remediation activities.
• Experience with CI/CD pipelines and Infrastructure as Code (Terraform, ARM, CloudFormation).

Job Duties
• Architect, engineer, and support enterprise IAM solutions across IGA, PAM, SSO, and MFA platforms.
• Own and manage the organization’s identity architecture, including cloud and hybrid identity models.
• Design and implement identity lifecycle management (joiner, mover, leaver) and access governance processes.
• Lead onboarding and integration of applications into SSO, MFA, and IGA platforms.
• Design and enforce role-based access control (RBAC) and least-privilege access models.
• Implement and manage PAM solutions for privileged accounts, service accounts, and secrets management.
• Manage cloud identity platforms (e.g., Azure AD / Entra ID, AWS IAM, GCP IAM) and their integrations.
• Develop and maintain IAM standards, architecture diagrams, and technical documentation.
• Serve as a subject matter expert for identity-related security incidents, audits, and compliance efforts.
• Collaborate with application, cloud, infrastructure, and security teams to deliver secure identity solutions.
• Mentor junior IAM engineers and contribute to IAM strategy and roadmap planning.
• Evaluate IAM tools and technologies and recommend improvements or new capabilities.
• Other duties as assigned. Architect, engineer, and support enterprise IAM solutions across IGA, PAM, SSO, and MFA platforms.
• Ability to lead cross functional initiatives and influence identity security standards across the enterprise.
• Experience integrating IAM platforms with SIEM, SOAR, and security monitoring solutions.
• Experience using REST APIs and automation frameworks to integrate IAM systems.
• Familiarity with Git based workflows and Agile delivery methodologies.
• Own and manage the organization’s identity architecture, including cloud and hybrid identity models.
• Experience managing hybrid identity environments, including Active Directory, Microsoft Entra ID, AWS IAM, and GCP IAM.
• Design and implement identity lifecycle management (joiner, mover, leaver) and access governance processes.
• Lead onboarding and integration of applications into SSO, MFA, and IGA platforms.
• Design and enforce role based access control (RBAC) and least privilege access models.
• Implement and manage PAM solutions for privileged accounts, service accounts, and secrets management.
• Manage cloud identity platforms (e.g., Azure AD / Entra ID, AWS IAM, GCP IAM) and their integrations.
• Develop and maintain IAM standards, architecture diagrams, and technical documentation.
• Serve as a subject matter expert for identity related security incidents, audits, and compliance efforts.
• Collaborate with application, cloud, infrastructure, and security teams to deliver secure identity solutions.
• Mentor junior IAM engineers and contribute to IAM strategy and roadmap planning.
• Evaluate IAM tools and technologies and recommend improvements or new capabilities.
• Ensure any direct reports understand and apply our Customer Commitment and customer service standards to their daily responsibilities as appropriate.
• Model Allegiant's customer service standards in personal actions and when providing leadership direction.
• Other duties as assigned.

Physical Requirements
The Physical Demands and Work Environment described here are a representative of those that must be met by a Team Member to successfully perform the essential functions of the role. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the role.


Office/IT - While performing the duties of this job, the Team Member is regularly required to stand, sit, talk, hear, see, reach, stoop, kneel, and use hands and fingers to operate a computer, key board, printer, and phone. May be required to lift, push, pull, or carry up to 50 lbs. May be required to work various shifts/days in a 24 hour situation. Regular attendance is a requirement of the role. Exposure to moderate noise (i.e. business office with computers, phones, printers, and foot traffic), temperature and light fluctuations. Ability to work in a confined area as well as the ability to sit at a computer terminal for an extended period of time. Some travel may be a requirement of the role.

Essential Services Provider
Allegiant as a national air carrier is deemed an essential service provider during declared national and state emergencies. Team Members will be required to report to their assigned trip or work location during national and state emergencies unless prohibited by local, state or federal order.

EEO Statement
We welcome all individuals from varied backgrounds and experiences to apply. Our company values the unique perspectives and talents that each person brings to our team.

Equal Opportunity Employer: Disability/Veteran
For more information, see

What this application asks

lever

Which location are you applying for?, Resume/CV, Full name, Pronouns, Email, Phone, Current location, Current company, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL, Other website

  • Are you at least 18 years of age? choose one
  • Are you legally authorized to work in the United States? choose one
  • Will you now or in the future require employment-based visa sponsorship to work in the US? If, when your current work authorization expires, you may require employment-based visa sponsorship to continue working with Allegiant, please select ‘Yes.’ Examples of statuses that may require current or future sponsorship include, but are not limited to: H-1B, H-1B1, E-2, E-3, L-1, TN, O-1, F-1 (CPT, OPT, and STEM OPT), and J-1. Allegiant is unable to provide employment sponsorship now or in the future. choose one
  • What is the highest level of education completed? Do not include degrees that are in progress or with a future graduation date. choose one · optional
  • Please include your completed degree program and school name for verification purposes. (Example: B.S. in Business Administration, UNLV). If you selected “High School Diploma or GED,” enter your high school name. written answer
  • In the last 10 years, have you ever been involuntarily terminated or asked to resign your employment? If Yes - please explain below | If No - please answer N/A. written answer
  • Do you have a non-compete agreement or other legal written restrictions that would restrict you from performing work required in this role? If Yes - please provide a copy of the non-compete agreement or other legal written restrictions to your recruiter. choose one
  • Do you have recall rights to any airline role? If Yes - which airline? | If No - please answer N/A. written answer
  • Are you related to anyone who is currently working for Allegiant? If Yes - please list the name of the person(s) and their relationship to you. | If No - please answer N/A. written answer
  • Have you ever been employed by an Allegiant company, Sun Country, or through a Third Party Contractor Agency onsite? choose one
  • You should know that Allegiant does not employ a Substance Abuse Professional (SAP) as part of its DOT/FAA substance abuse testing program and therefore cannot accommodate any SAP-imposed return to duty requirements. If you have any such requirements in place from current or prior employment, you will not be eligible for employment at Allegiant in a safety sensitive role. yes / no · optional
  • What is your Legal First Name?
  • What is your Legal Last Name?
  • Collaboration starts with honest, upfront conversations. The salary range for this role is $150,000 - $183,700, with offers based on experience, skills, and abilities. Does that fit within your expectations? choose one
  • This role is based at our Las Vegas, NV headquarters and includes regular in-person collaboration. Are you comfortable working on-site as needed? choose one
  • This position requires working at our Las Vegas, NV headquarters or Minneapolis and St. Paul, MN headquarters . Please select the option that best describes your current situation: choose one
  • This role requires a Bachelor's degree in cybersecurity or Computer Science. Do you meet this requirement? choose one
  • This role requires an IAM or related certification. Please describe your completed certifications written answer
  • This role requires a minimum seven (7) years of experience in a related field to this role. Do you meet this requirement? choose one
  • How many years of experience do you have working in Identity & Access Management (IAM) or related security engineering roles? choose one
  • Which of the following IAM areas have you had hands-on experience with? (Select all that apply) yes / no · optional
  • Have you designed and implemented enterprise IAM architectures or solutions? choose one
  • Which authentication and authorization protocols are you familiar with? (Select all that apply) yes / no · optional
  • What cloud identity platforms or services have you worked with? (Select all that apply) yes / no · optional
  • How familiar are you with Zero Trust and identity-centric security principles? choose one
  • Do you have experience with CI/CD pipelines or Infrastructure as Code tools (e.g., Terraform, ARM templates, CloudFormation)? choose one
  • Which of the following certifications do you currently hold? (Select all that apply) yes / no · optional

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available