Ensono Logo

Ensono

IAM Senior Engineer

Posted Yesterday
Be an Early Applicant
Easy Apply
Remote or Hybrid
Hiring Remotely in United States
125K-162K Annually
Senior level
Easy Apply
Remote or Hybrid
Hiring Remotely in United States
125K-162K Annually
Senior level
Lead design and delivery of enterprise IAM solutions across authentication, authorization, PAM, secrets management, identity governance, and privileged access. Own IAM outcomes for migrations, define reference architectures and integration patterns, execute SSO/MFA/federation/PAM configurations, ensure security/compliance, perform testing and risk remediation, develop automation and accelerators, mentor junior engineers, and document architectures and operational procedures while collaborating with application, cloud, and security teams.
The summary above was generated by AI

At Ensono, our Purpose is to be a relentless ally, disrupting the status quo and unleashing our clients to Do Great Things! We enable our clients to achieve key business outcomes that reshape how our world runs. As an expert technology adviser and managed service provider with cross-platform certifications, Ensono empowers our clients to keep up with continuous change and embrace innovation.

We can Do Great Things because we have great Associates. The Ensono Core Values unify our diverse talents and are woven into how we do business. These five traits are the key to achieving our purpose:


Honesty, Reliability, Curiosity, Collaboration, and Passion.

About the role and what you'll be doing:

The Senior IAM Engineer serves as a technical authority and trusted advisor, leading the design and delivery of Identity and Access Management (IAM) solutions in support of complex application migrations and enterprise security initiatives.

Operating within client governance frameworks, this role partners closely with client stakeholders, architects, and security leadership to define IAM strategies, establish integration standards, and guide implementation outcomes. The Senior IAM Engineer is accountable for the technical quality, security posture, and scalability of IAM solutions and provides leadership across the IAM lifecycle—from design and implementation through migration, testing, and operational readiness.

While this role remains hands-on, it extends beyond execution to include technical decision-making, architectural leadership, and mentorship, ensuring IAM solutions align with business objectives, regulatory requirements, and enterprise security standards.

We want all new Associates to succeed in their roles at Ensono. That's why we've outlined the job requirements below. To be considered for this role, it's important that you meet all Required Qualifications. If you do not meet all of the Preferred Qualifications, we still encourage you to apply.

KEY RESPONSIBILITIES

IAM Architecture & Design Leadership

  • Lead the design and implementation of IAM solutions across authentication, authorization, secrets management, identity governance, and privileged access domains

  • Define and maintain IAM reference architectures, integration patterns, and best practices aligned to enterprise standards

  • Provide technical recommendations and trade-off analysis balancing security, usability, scalability, and operational efficiency

  • Participate in architecture reviews and influence client IAM roadmaps and modernization strategies

Delivery Ownership & Execution

  • Own IAM outcomes for assigned programs and migrations, ensuring solutions meet security, compliance, and performance expectations

  • Lead IAM readiness activities for migrations and cutovers, including risk identification, mitigation planning, and execution support

  • Guide and execute IAM configuration and integrations for SSO, MFA, federation, PAM, and secrets management

  • Develop and enhance accelerators, automation, and self-service capabilities to improve delivery efficiency and consistency

Security, Risk & Compliance

  • Ensure IAM implementations align with enterprise security policies, regulatory requirements, and audit standards

  • Lead or coordinate IAM-related security testing, including authentication/authorization validation and vulnerability assessments

  • Identify IAM risks and proactively recommend remediation or improvement opportunities

Technical Leadership & Collaboration

  • Serve as a point of escalation for complex IAM issues and defect resolution

  • Mentor junior engineers and review IAM designs, configurations, and documentation

  • Collaborate with application teams, cloud engineers, security operations, and governance partners to drive successful IAM adoption

  • Document IAM architectures, configurations, and operational procedures for long-term sustainability

REQUIRED SKILLS & QUALIFICATIONS

  • 7+ years of progressive experience in Identity and Access Management engineering, including leadership of complex IAM initiatives

  • Proven experience designing and implementing IAM solutions in large-scale, hybrid, or cloud environments

  • Demonstrated ability to act as a technical authority and advisor, influencing IAM decisions and standards

 

Hands-on expertise with enterprise IAM technologies, including:

Privileged Access Management (PAM):

  • CyberArk (Enterprise Password Vault, Privileged Session Manager, Central Credential Provider, Conjur)

  • HashiCorp Vault (secrets engines, policies, authentication methods, dynamic credentials)

 

Authentication / Identity Providers (IDP):

  • ForgeRock (Access Management, Identity Management, Directory Services, Identity Gateway)

  • RSA (SecurID Authentication Manager, MFA, Identity Governance & Lifecycle)

 

User Access & Entitlement Management:

  • SailPoint (IdentityIQ, IdentityNow – access certifications, provisioning, role management)

  • ESF (Enterprise Security Framework – entitlement management and access controls)

  • Strong experience with authentication and federation protocols: SAML, OAuth 2.0, OpenID Connect, Kerberos

  • Advanced knowledge of Active Directory, LDAP, and identity integrations

  • Experience with cloud platforms (AWS, Azure) and cloud-native IAM services

  • Strong scripting and automation capabilities (PowerShell, Python, Terraform, or equivalent)

  • Excellent troubleshooting, analytical, and communication skills

  • Experience in financial services or highly regulated industries preferred

 

Preferred Certifications:

  • CyberArk Certified Defender or Delivery Engineer

  • HashiCorp Certified Vault Associate / Professional

  • ForgeRock Certified Engineer

  • SailPoint Certified IdentityIQ Engineer

  • RSA Certified Administrator

Why Ensono?

Ensono is a place to make better happen – for our clients and for your career. You can do great things through innovation or collaboration, by learning or volunteering, or to promote diversity and inclusion. You can do great things for your own health or for a healthier planet. Whatever it means to you to do great things we want Ensono to be the place you can do it. 

We are a client-facing business, but we do encourage clients to allow us to work remotely most of the time so if you are not required to be on a client site, you can choose to work from home or in our Ensono offices.

Some of our benefits include:

  • Unlimited Paid Days Off

  • Three health plan options

  • 401k with company match

  • Eligibility for dental, vision, short and long-term disability, life and AD&D coverage, and flexible spending accounts

  • Family Forming Benefit including fertility coverage and adoption/surrogacy reimbursement

  • Paid childbearing and paternal leave

  • Education Reimbursement, Student Loan Assistance or 529 College Funding

  • Sabbatical leave

  • Wellness program

  • Flexible work schedule

As of the date of this posting, a good faith estimate of the current pay scale for this role is $125,000 to $162,000 annually based on a full-time schedule. Please note that placement in the range may vary based on numerous factors including but not limited to skills, experience, internal equity, and business needs. In addition to base salary, other compensation programs, depending on eligibility, include an annual bonus plan based on company and individual performance and an equity grant under our Associate Equity Appreciation Program.

Ensono is an Equal Opportunity/Affirmative Action employer. We are committed to providing equal employment to our Associates and building a diverse and inclusive workforce. All qualified applicants will be considered without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, or other legally protected basis, in accordance with applicable law.

Pay transparency nondiscrimination statement/posting OFCCP’s pay transparency policy can be found on OFCCP’s website.

If you need accommodation at any point during the application or interview process, please let your recruiter know or email [email protected].

Similar Jobs

8 Days Ago
In-Office or Remote
180K-225K Annually
Senior level
180K-225K Annually
Senior level
Consumer Web • Healthtech • Professional Services • Social Impact • Software
Design, standardize, and automate the IAM lifecycle and workflows. Integrate and maintain IdP connections, drive RBAC/least-privilege adoption, automate provisioning/deprovisioning, resolve identity incidents, document processes, and partner with stakeholders to establish IAM governance.
Top Skills: 1PasswordAPIsChromeosConfluenceGmailGoogle WorkspaceIdpIntuneJAMFJIRAJira Service DeskJmlKolideLumosOidcOktaRbacSAMLScimSlackZendesk
Yesterday
Easy Apply
Remote or Hybrid
United States
Easy Apply
125K-162K Annually
Senior level
125K-162K Annually
Senior level
Cloud • Information Technology
Manage and maintain ForgeRock IAM suite (AM, IDM, DS, IG), ensure high availability, perform L3 support and root-cause analysis, develop custom authentication scripts/plugins, configure MFA and conditional access, integrate directories (AD/Azure AD), and automate deployments with CI/CD and container tooling.
Top Skills: Active DirectoryAzure Ad/Entra IdCi/CdDockerForgerock AmForgerock DsForgerock IdmForgerock IgGitGroovyJavaJavaScriptJenkinsJSONJvmKubernetesLdapLinuxOauth 2.0Openid Connect (Oidc)Saml 2.0
2 Days Ago
Remote
United States
Senior level
Senior level
Fintech • Cryptocurrency • Web3
As a Senior Backend & Platform Engineer, you'll design and operate critical systems in identity management, financial operations, and blockchain infrastructure while leading projects and mentoring engineers.
Top Skills: AWSBlockchainFinancial SystemsGoGCPIdentity & Access ManagementRust

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account