Identity and Access Management Technical Lead
Summary
CAF America is hiring a remote (US-based) IAM Technical Lead to own identity governance across M365, Azure Entra ID, and SaaS platforms — managing SSO, MFA, provisioning, RBAC, and access audits for SOC2/PCI/GDPR compliance. The role leads identity lifecycle processes, collaborates with security and vendor teams, and partners with CAF's UK counterpart.
- Identity Lifecycle Leadership
- Define identity governance policies, access control standards, and compliance requirements to ensure security, regulatory compliance, and risk reduction across all enterprise systems.
- Define and govern authentication strategy, including SSO, MFA, and identity federation configurations, ensuring security and compliance. Provide standards and oversight for identity provider configurations.
- Define policies and standards for provisioning and deprovisioning user and group accounts across M365, Azure Entra ID, CRM, and integrated SaaS platforms, and monitor adherence to these standards
- Maintain RBAC structures and enforce least privilege principles.
- Access Governance
- Define and implement access control policies and standards.
- Own and Conduct periodic access audits and ensure compliance with SOC2, PCI, GDPR. Partner and collaborate with Cybersecurity and other internal teams (Risk & Compliance, and Privacy) to conduct these audits.
- Authentication Infrastructure
- Manage SSO, MFA, and identity federation configurations.
- Optimize authentication flows for security and usability.
- Compliance & Risk Alignment
- Partner with Cyber Security and Risk teams to meet regulatory requirements.
- Prepare audit reports and support compliance reviews.
- Integration & Automation
- Integrate identity solutions with enterprise applications and SaaS platforms.
- Enable and consult on automation initiatives for onboarding/offboarding workflows.
- Incident Response
- Act as identity SME during security incidents.
- Implement corrective actions and strengthen identity posture.
Secondary Responsibilities
- Collaborate with Cyber Security and Enterprise Apps personnel on security posture and access strategies.
- Coordinate with MSPs and SaaS vendors for identity integrations and compliance validation.
- Own and lead audit preparation and reporting for identity and access controls across all enterprise systems.
- Maintain detailed IAM documentation and evidence logs for SOC2, PCI, GDPR compliance. Coordinate with Risk & Compliance, Privacy, and Cyber Security team members to ensure timely completion of annual and periodic access reviews. Deliver audit reports to leadership and regulatory bodies as required.
- Support end-user training on MFA, SSO, and secure access practices.
- Provide technical input during security incidents and remediation efforts.
- Research emerging IAM technologies and recommend improvements for automation and efficiency.
- Strong knowledge of IAM principles, RBAC, and identity governance frameworks.
- Experience defining IAM policies and governance standards.
- Bachelor’s degree (B.A./B.S.) in IT or related field; or equivalent combination of education and experience.
- 2–4 years of experience in IAM or IT security roles, with hands-on expertise in identity lifecycle management, authentication protocols, and compliance support.
- Must be eligible to work legally in the United States.
- Experience with Azure Entra ID, Okta, M365, and SaaS integrations.
- Experience with compliance frameworks (SOC2, PCI, GDPR) and audit related audits.
- Familiarity with authentication protocols (SAML, OAuth, OpenID Connect).
- Hands-on expertise in identity and access management, including federation, SSO (SAML/OIDC), MFA
- Strong familiarity with enterprise CRM and productivity platforms, including user provisioning and password management.
- Hands-on experience with identity and access management tools such as Microsoft Entra ID, including configuring SSO and MFA for third-party SaaS applications.
- Proficiency in administering collaboration and file-sharing platforms (e.g., Dropbox, Google Shared Drives) with a focus on secure access.
- Advanced knowledge of Microsoft 365 and Azure Entra ID environments.
- Experience using compliance and audit tools or processes for SOC2, PCI, GDPR evidence collection.
- Experience managing internal ticketing systems and support workflows, including triage and resolution of identity-related issues.
- Exposure to cloud and web hosting environments (e.g., AWS) and IAM systems, with the ability to assist in maintenance and monitoring tasks.
- Knowledge of security frameworks and IAM governance best practices. (NIST/ISO)
- Exposure to automation tools and scripting (PowerShell, MS Power Automate) preferred.
- Work with multiple entities (internal teams, vendors, users, etc.) simultaneously while resolving complex system issues
- Maintain resilience, positive attitude, and supportive disposition while resolving difficult technical problems with complex decentralized SaaS and Cloud solutions
- Return and report to supervisor and peers, and demonstrate accountability for tasks
- Excellent documentation and communication skills, with experience maintaining IT knowledge bases and delivering user training.
Your health and wellness are important to us. CAF America offers a comprehensive benefits package which includes 100% paid premium for Employee Medical, Dental and Vision insurance along with a Health Savings Account (HSA), Life Insurance, Accidental Death and Dismemberment Insurance, Short- and Long-Term Disability, 401k program with up to 15% match, Lifestyle Savings Account, Employee Assistance Program (EAP) and robust Time Off programs.