{"id":2623,"date":"2025-07-08T12:26:54","date_gmt":"2025-07-08T12:26:54","guid":{"rendered":"https:\/\/estreetsecurity.com\/services\/?post_type=jobpost&#038;p=2623"},"modified":"2025-07-08T12:28:29","modified_gmt":"2025-07-08T12:28:29","slug":"senior-iam-engineer-permanent-onsite-new-york-ny","status":"publish","type":"jobpost","link":"https:\/\/estreetsecurity.com\/services\/jobs\/senior-iam-engineer-permanent-onsite-new-york-ny\/","title":{"rendered":"Senior IAM Engineer (Permanent &#8211; Onsite &#8211; New York, NY)"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Senior IAM Engineer (Permanent &#8211; Onsite &#8211; New York, NY)<\/h2>\n\n\n\n<p>A <strong>top-tier hedge fund<\/strong> is seeking a highly skilled <strong>Senior IAM Engineer<\/strong> to strategically shape the future of its identity and access management infrastructure. This <strong>permanent position<\/strong>, based <strong>onsite in New York, NY<\/strong>, offers a high-impact engineering role at the crucial intersection of security, scale, and performance. It&#8217;s ideal for a professional who thrives in technically rigorous and demanding environments.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">The Opportunity: Building the Identity Backbone of a World-Class Firm<\/h3>\n\n\n\n<p>You&#8217;ll become an integral part of a small, exceptionally skilled team responsible for <strong>building and securing the identity backbone of the firm<\/strong>. Your work will directly underpin the firm&#8217;s critical trading, research, and engineering operations, spanning everything from foundational directory services to cutting-edge cloud-native authentication platforms. This role offers a unique chance to influence the architecture of a world-class technology organization, working on systems that demand unparalleled reliability, speed, and security at scale, alongside engineers who value precision and measurable impact.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What You&#8217;ll Do: Driving Next-Generation Identity Platforms<\/h3>\n\n\n\n<p>As a Senior IAM Engineer, your responsibilities will blend strategic design, hands-on implementation, and leadership in highly secure, high-performance environments. You&#8217;ll be instrumental in evolving the firm&#8217;s identity and access capabilities across both on-premises and cloud infrastructures.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Design and Implement Next-Generation Identity Platforms:<\/strong> You will take a leading role in the <strong>design and implementation of next-generation identity platforms<\/strong>. This involves architecting scalable, secure, and resilient solutions that leverage cutting-edge technologies to modernize the firm&#8217;s identity infrastructure, ensuring it meets future demands for security, performance, and user experience.<\/li>\n\n\n\n<li><strong>Build and Maintain Resilient Authentication and Authorization Services:<\/strong> You will be responsible for meticulously <strong>building and maintaining resilient authentication and authorization services<\/strong> across both on-premises and cloud environments. This includes designing fault-tolerant systems, implementing robust security controls, and ensuring continuous availability for critical access pathways, directly supporting the firm&#8217;s trading, research, and engineering operations.<\/li>\n\n\n\n<li><strong>Lead Firm-Wide Initiatives to Improve Security Posture:<\/strong> You will spearhead and <strong>lead firm-wide initiatives aimed at continuously improving the overall security posture<\/strong> of the organization. This involves identifying systemic vulnerabilities, proposing strategic enhancements, and driving the implementation of solutions that bolster the firm&#8217;s defenses against sophisticated cyber threats. Your leadership will directly influence the security roadmap.<\/li>\n\n\n\n<li><strong>Develop Automation Pipelines Using Advanced Tools:<\/strong> You will be instrumental in driving operational efficiency and consistency by <strong>developing robust automation pipelines<\/strong>. This includes leveraging cutting-edge Infrastructure as Code (IaC) tools such as <strong>Terraform<\/strong> for provisioning cloud resources, <strong>Pulumi<\/strong> for multi-language infrastructure management, and <strong>Crossplane<\/strong> for extending Kubernetes to manage external resources. Your automation efforts will streamline deployments, reduce manual effort, and ensure configuration consistency.<\/li>\n\n\n\n<li><strong>Extend and Integrate Key IAM Solutions:<\/strong> You will <strong>extend and integrate industry-leading IAM solutions<\/strong> into the firm&#8217;s existing ecosystem. This includes working with platforms like <strong>Azure AD (Active Directory)<\/strong> for cloud-based identity, <strong>Okta<\/strong> for identity and access management, and <strong>PingFederate<\/strong> (PingFed) for enterprise federation. Your expertise will ensure seamless authentication and authorization across diverse applications and services.<\/li>\n\n\n\n<li><strong>Contribute to Internal Libraries and Governance Platforms:<\/strong> You will actively <strong>contribute to internal libraries and governance platforms<\/strong> developed within the firm. This involves writing high-quality code in <strong>Java, Python, or Go<\/strong>, creating reusable components, and enhancing platforms that enforce security policies, manage identity lifecycles, and ensure compliance. Your contributions will directly strengthen the firm&#8217;s internal security engineering capabilities.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">What We&#8217;re Looking For: Your Expertise in Identity &amp; Security Engineering<\/h3>\n\n\n\n<p>To excel as a Senior IAM Engineer at this top-tier hedge fund, you&#8217;ll need extensive experience in software or security engineering, deep expertise in IAM concepts, strong programming skills, and a proven track record of solving complex challenges.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Extensive Software or Security Engineering Experience:<\/strong> You must possess <strong>8+ years of verifiable experience in software or security engineering<\/strong>. This extensive background demonstrates a seasoned professional capable of tackling complex technical challenges and delivering robust, secure solutions in high-stakes environments.<\/li>\n\n\n\n<li><strong>Deep Expertise in IAM Concepts:<\/strong> You are required to have <strong>deep expertise in core IAM concepts<\/strong>, including:\n<ul class=\"wp-block-list\">\n<li><strong>Authentication:<\/strong> Understanding various methods of verifying user identity (e.g., MFA, SSO, passwordless).<\/li>\n\n\n\n<li><strong>Federation:<\/strong> Knowledge of how identities are shared and managed across different security domains (e.g., SAML, OAuth, OpenID Connect).<\/li>\n\n\n\n<li><strong>Zero Trust:<\/strong> A strong grasp of Zero Trust principles, where no user or device is inherently trusted, and all access is verified.<\/li>\n\n\n\n<li><strong>PKI (Public Key Infrastructure):<\/strong> Understanding of digital certificates, certificate authorities, and their role in secure communication and identity.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Experience with Foundational Identity Services:<\/strong> You must have hands-on <strong>experience with foundational identity services<\/strong> that underpin enterprise access management. This includes deep familiarity with <strong>Active Directory<\/strong> (for centralized user management), <strong>LDAP (Lightweight Directory Access Protocol)<\/strong> for directory services, and <strong>PKI (Public Key Infrastructure)<\/strong> components for secure digital identities and communication.<\/li>\n\n\n\n<li><strong>Strong Programming Skills in Multiple Languages\/Tools:<\/strong> You possess <strong>strong programming skills<\/strong> in a combination of relevant languages and tools. This includes <strong>Java, Go, Python<\/strong> (for application and automation development), <strong>Terraform HCL (HashiCorp Configuration Language)<\/strong> for Infrastructure as Code, and <strong>Rego<\/strong> (for policy-as-code languages like OPA). This polyglot capability ensures versatility in developing and securing diverse systems.<\/li>\n\n\n\n<li><strong>Track Record of Solving Complex Challenges:<\/strong> You must have a proven <strong>track record of solving complex technical and organizational challenges<\/strong>. This indicates your ability to dissect intricate problems, devise innovative solutions, navigate cross-functional dynamics, and deliver impactful results in demanding environments.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Why This Role? Influence and Impact at Scale<\/h3>\n\n\n\n<p>This is more than a security role\u2014it&#8217;s an exceptional <strong>chance to influence the architecture of a world-class technology organization<\/strong>. You&#8217;ll be working on systems that demand unparalleled reliability, blazing speed, and ironclad security at immense scale. You&#8217;ll collaborate alongside engineers who prioritize precision and measurable impact, fostering an environment where your contributions are highly valued and directly shape the firm&#8217;s technological future.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Senior IAM Engineer (Permanent &#8211; Onsite &#8211; New York, NY) A top-tier hedge fund is seeking a highly skilled Senior IAM Engineer to strategically shape the future of its identity and access management infrastructure. This permanent position, based onsite in New York, NY, offers a high-impact engineering role at the crucial intersection of security, scale, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"menu_order":0,"template":"","jobpost_category":[426,231],"jobpost_job_type":[273],"jobpost_location":[357],"jobpost_tag":[442,604,561,2805,2808,576,603,2810,288,2811,2797,2800,1969,2804,506,566,1814,1025,2806,2799,2803,1484,2807,669,2809,245,2813,2802,2801,2798,246,2812,843],"class_list":["post-2623","jobpost","type-jobpost","status-publish","hentry","jobpost_category-it","jobpost_category-security","jobpost_job_type-onsite","jobpost_location-new-york-city-ny","jobpost_tag-active-directory","jobpost_tag-api-security","jobpost_tag-authentication-services","jobpost_tag-authorization-services","jobpost_tag-automation-pipelines","jobpost_tag-azure-ad","jobpost_tag-cloud-iam","jobpost_tag-crossplane","jobpost_tag-cybersecurity","jobpost_tag-go","jobpost_tag-hedge-fund","jobpost_tag-iam-infrastructure","jobpost_tag-identity-access-management","jobpost_tag-identity-platforms","jobpost_tag-java","jobpost_tag-ldap","jobpost_tag-nyc-tech-jobs","jobpost_tag-okta","jobpost_tag-on-prem-iam","jobpost_tag-onsite-new-york","jobpost_tag-performance","jobpost_tag-permanent-job","jobpost_tag-pingfederate","jobpost_tag-pki","jobpost_tag-pulumi","jobpost_tag-python","jobpost_tag-rego","jobpost_tag-scale","jobpost_tag-security-engineering","jobpost_tag-senior-iam-engineer","jobpost_tag-terraform","jobpost_tag-terraform-hcl","jobpost_tag-zero-trust"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/jobpost\/2623","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/jobpost"}],"about":[{"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/types\/jobpost"}],"author":[{"embeddable":true,"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/users\/1"}],"wp:attachment":[{"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/media?parent=2623"}],"wp:term":[{"taxonomy":"jobpost_category","embeddable":true,"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/jobpost_category?post=2623"},{"taxonomy":"jobpost_job_type","embeddable":true,"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/jobpost_job_type?post=2623"},{"taxonomy":"jobpost_location","embeddable":true,"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/jobpost_location?post=2623"},{"taxonomy":"jobpost_tag","embeddable":true,"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/jobpost_tag?post=2623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}