Cooley Logo

Cooley

Identity and Access Management (“IAM”) Engineer

Reposted 2 Days Ago
In-Office or Remote
12 Locations
130K-195K Annually
Senior level
In-Office or Remote
12 Locations
130K-195K Annually
Senior level
The IAM Engineer will design, implement, and operate secure identity services, ensuring compliance and supporting IAM across Azure AD, PAM, SSO, and governance processes.
The summary above was generated by AI
Identity and Access Management (“IAM”) Engineer

Cooley is seeking an IAM Engineer to join the Security team.

Position summary: Cooley Technology embraces a culture of customer service excellence, and all members of the department are expected to move this agenda forward. To that end, the Technology Identity and Access Management (“IAM”) Engineer works independently and serves as a key contributor in designing, implementing, and operating secure, compliant, and scalable identity services. This role supports the firm’s IAM program across Entra ID (Azure AD), Privileged Access Management, Active Directory, SSO/MFA/Conditional Access, Identity Governance processes, Cloud Identity (AWS), and Certificate Lifecycle Management. The position partners closely with Cybersecurity, Innovation and Technology teams, HR, as well as business stakeholders to deliver reliable identity capabilities that protect firm data and enable business operations. Specific duties include, but are not limited to, the following:

Position responsibilities: 

  • Deliver and operate IAM capabilities across provisioning, authentication, authorization, and identity lifecycle processes
  • Administer and improve Microsoft Entra ID (Azure AD) and on-prem Active Directory including account lifecycle management, group/role administration, delegations, and directory hygiene
  • Implement and support Single Sign-on (SSO), Multi Factor Authentication (MFA), and Conditional Access controls, ensuring authentication standards are applied consistently and exceptions are documented and governed
  • Engineer and maintain identity integrations for SaaS and on-prem applications, including federation and enterprise application configurations
  • Support the Privileged Access Management (PAM) program by onboarding privileged identities, implementing credential protection and rotation workflows, supporting access approvals and break-glass procedures
  • Execute identity governance workflows such as joiner/mover/leaver workflows, access requests, access reviews, exception handling, and remediation activities in coordination with IAM leadership and HR/Technology stakeholders
  • Implement cloud identity solutions using secure access patterns for human and workload identities, aligned to firm standards and least privilege
  • Contribute to certificate lifecycle management efforts, including inventory support, ownership mapping, issuance/renewal processes, and automation initiatives
  • Implement, manage and maintain internal and external certificate platforms
  • Automate and standardize IAM operations through scripting or other automation workflows to improve efficiency, consistency, and reliability
  • Monitor IAM systems and access posture for issues or anomalies and partner with Cyber Security and other Technology teams to resolve findings
  • Develop and maintain clear documentation, procedures, and runbooks for IAM systems and integrations
  • Participate in on-call rotation and after-hours support, as required
  • All other duties as assigned or required

Skills & experience: 

Required:

  • After orientation at Cooley LLP, exhibit proficiency in the Microsoft Office suite, iManage and other firm applications
  • Ability to work extended and/or weekend hours, as required
  • Ability to travel, as required
  • 4+ years of progressive IAM/directory/authentication or relevant experience in an enterprise environment. Senior level candidates must have 5+ years' directly applicable experience.
  • Hands-on experience with Entra ID (Azure AD) and Active Directory administration, including identity lifecycle management and enterprise account administration
  • Hands-on experience implementing and supporting SSO/MFA/Conditional Access controls
  • Experience with identity and access protocols such as SAML, OAuth, OpenID Connect, LDAP, and SCIM
  • Experience supporting or engineering Privileged Access Management (PAM) workflows
  • Experience working with cloud identity services, including roles, policies, and federation for human and workload identities
  • Ability to troubleshoot and resolve complex IAM issues and communicate solutions clearly to technical and non-technical stakeholders

Preferred:

  • Bachelor’s degree in computer science, Information Systems, or related field
  • Experience with PAM tooling and privileged identity workflows and/or identity governance
  • Familiarity with AWS IAM and broader cloud IAM patterns
  • PowerShell scripting (or equivalent) to support automation and operational consistency
  • Experience with CrowdStrike Identity Protection
  • Experience with Tenable Identity Exposure
  • Experience with SIEM solutions
  • Prior law firm or professional services experience
  • Relevant certifications such as CISSP, Azure, AWS or other IAM-focused certifications

Competencies:

  • Entrepreneurial by nature
  • Strong analytical and problem-solving skills, with the ability to design, implement and troubleshoot identity and access solutions
  • Demonstrates sound technical judgement when implementing authentication, access controls, and security integrations
  • Works independently while effectively prioritizing tasks and managing multiple workstreams
  • Communicates clearly and professionally with both technical and non-technical stakeholders
  • Maintains a high level of accuracy, documentation, and attention to detail in operational work
  • Adapts quickly to changing requirements, technologies, and priorities
  • Ability to organize, prioritize and coordinate multiple activities often under tight timelines
  • Ability to drive projects to completion and achieve goals
  • Strong judgment
  • Team-player with collaborative spirit

Cooley offers a competitive compensation and excellent benefits package and is committed to fair and equitable employment practices.

EOE.

The expected annual pay range for this position with a full-time schedule is $130,000 - $195,000. Senior level candidates may be considered for this position and would be eligible for a higher salary range based on experience. Please note that final offer amount will be dependent on geographic location, applicable experience and skillset of the candidate.

We offer a full range of elective benefits including medical, health savings account (with applicable medical plan), dental, vision, health and/or dependent care flexible spending accounts, pre-tax commuter benefits, life insurance, AD&D, long-term care coverage, backup care for children and/or adults and other parental support benefits. In addition to elective benefit options, benefited employees receive firm-paid life insurance, AD&D, LTD, short term medical benefits as well as 21 days of Paid Time Off (“PTO”) and 10 paid holidays each year. We provide generous parental leave and fertility benefits. New employees will attend a detailed benefit orientation to learn more about our many benefits and resources.

Top Skills

Active Directory
AWS
Azure Ad
Conditional Access
Crowdstrike Identity Protection
Ldap
Mfa
Oauth
Openid Connect
Powershell
Privileged Access Management
SAML
Scim
SIEM
Sso
Tenable Identity Exposure

Similar Jobs

15 Minutes Ago
Remote or Hybrid
United States
160K-210K Annually
Senior level
160K-210K Annually
Senior level
HR Tech • Information Technology • Professional Services • Sales • Software
Own and operate production-grade Kubernetes infrastructure on AWS, build GitOps CI/CD with GitHub Actions and ArgoCD, develop AI agents and internal DevOps tooling, maintain Datadog-based observability, and manage on-call incident response while collaborating with engineering teams to improve reliability and delivery speed.
Top Skills: Kubernetes,Aws,Python,Go,Datadog,Github Actions,Argocd,Gitops,Ci/Cd,Ai/Llm
18 Minutes Ago
Remote
2 Locations
81K-122K Annually
Mid level
81K-122K Annually
Mid level
Artificial Intelligence • Productivity • Software • Automation
Support procure-to-pay operations by managing vendor master data and onboarding, performing OFAC/TIN matching and 1099/1042 determinations, coding and reviewing AP invoices, handling virtual card transactions, organizing Zendesk tickets, aiding purchase requests, maintaining process documentation, and performing month-end reconciliations and automations.
Top Skills: Zip,Erp,Zendesk,Slack
28 Minutes Ago
Remote or Hybrid
United States
107K-143K Annually
Senior level
107K-143K Annually
Senior level
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Lead end-to-end business process reengineering and transformation initiatives: assess current state, design near- and long-term solutions spanning customer experience, operations, digitization, automation and risk, develop implementation and sequencing plans, build business cases, and create executive materials to drive adoption and sustainable measurement.
Top Skills: AutomationDesign ThinkingDigitizationLeanLean Six-Sigma

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account