{"id":2761,"date":"2025-07-22T03:19:56","date_gmt":"2025-07-22T03:19:56","guid":{"rendered":"https:\/\/estreetsecurity.com\/services\/?post_type=jobpost&#038;p=2761"},"modified":"2025-07-22T03:33:31","modified_gmt":"2025-07-22T03:33:31","slug":"lead-iam-engineer-permanent-hybrid-remote-newark-nj-new-york-ny","status":"publish","type":"jobpost","link":"https:\/\/estreetsecurity.com\/services\/jobs\/lead-iam-engineer-permanent-hybrid-remote-newark-nj-new-york-ny\/","title":{"rendered":"Lead IAM Engineer (Permanent &#8211; Hybrid\/Remote &#8211; Newark, NJ \/ New York, NY)"},"content":{"rendered":"\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>An opportunity has come through our network for a <strong>Lead IAM Engineer<\/strong> at a leading <strong>energy\/utilities organization<\/strong>. This <strong>full-time, permanent position<\/strong> offers hybrid\/remote flexibility, allowing you to be based out of <strong>Newark, New Jersey, or New York, New York<\/strong>, with a competitive salary ranging from <strong>$140,000 &#8211; $165,000 annually<\/strong>. This is a senior-level, hands-on technical leadership role that is absolutely critical for leading the design, implementation, and management of enterprise Identity and Access Management (IAM) solutions, ensuring secure access, enforcing security policies, and driving IAM strategy across the organization.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">What You&#8217;ll Be Doing: Spearheading Enterprise IAM Strategy and Security<\/h3>\n\n\n\n<p>As a Lead IAM Engineer, you&#8217;ll be at the forefront of securing critical systems and data, ensuring robust identity and access controls across complex on-premises and cloud environments. Your responsibilities will blend strategic architecture, hands-on implementation, and cross-functional leadership.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>IAM Architecture &amp; Implementation:<\/strong> You will lead the <strong>design and management of comprehensive IAM solutions<\/strong> across the enterprise. This includes implementing Single Sign-On (SSO) for simplified access, Multi-Factor Authentication (MFA) for enhanced security, Privileged Access Management (PAM) for securing elevated accounts, and Role-Based Access Control (RBAC) for granular permissions. Your work ensures a secure and efficient access landscape.<\/li>\n\n\n\n<li><strong>Identity Governance:<\/strong> You&#8217;ll oversee <strong>identity lifecycle management<\/strong>, from user provisioning (granting access) to deprovisioning (revoking access). This involves establishing processes for managing user identities throughout their journey within the organization, ensuring accurate and timely access changes, and maintaining compliance with internal and external policies.<\/li>\n\n\n\n<li><strong>Access Control:<\/strong> You&#8217;ll implement advanced access control principles such as <strong>least privilege<\/strong> (granting only necessary access), <strong>Just-In-Time (JIT) access<\/strong> (granting temporary access only when needed), and <strong>Zero Trust principles<\/strong> (never trust, always verify). These controls significantly reduce the attack surface and enhance the security posture of critical systems.<\/li>\n\n\n\n<li><strong>Directory &amp; Federation Services:<\/strong> You&#8217;ll manage core directory services like <strong>Active Directory<\/strong> and <strong>Azure AD (Active Directory)<\/strong>, as well as <strong>LDAP (Lightweight Directory Access Protocol)<\/strong>. Your expertise will extend to implementing <strong>federation protocols<\/strong> such as SAML (Security Assertion Markup Language), OAuth, and OpenID Connect, enabling seamless and secure identity sharing across different systems and organizations.<\/li>\n\n\n\n<li><strong>Cloud IAM:<\/strong> You will be responsible for <strong>securing access across various cloud platforms<\/strong> (e.g., AWS, Azure). This involves implementing proper identity federation, managing cloud-native identity services, and defining secure role management to ensure consistent and compliant access controls within the dynamic cloud environment.<\/li>\n\n\n\n<li><strong>Compliance &amp; Security:<\/strong> You&#8217;ll ensure strict <strong>alignment with regulatory frameworks<\/strong> like <strong>SOX (Sarbanes-Oxley Act)<\/strong> and <strong>NIST (National Institute of Standards and Technology)<\/strong> guidelines, as well as other relevant industry and security standards. This includes <strong>conducting audits and risk assessments<\/strong> to identify potential compliance gaps and vulnerabilities within the IAM domain, ensuring robust governance.<\/li>\n\n\n\n<li><strong>Incident Response:<\/strong> You will collaborate closely with security teams to <strong>detect and remediate IAM-related incidents<\/strong>. This involves investigating security breaches, identifying compromised accounts, implementing containment strategies, and restoring normal operations quickly and effectively, minimizing impact on the organization.<\/li>\n\n\n\n<li><strong>Automation:<\/strong> You will drive efficiency and consistency by <strong>developing scripts and workflows<\/strong> using languages like <strong>PowerShell, Python, or similar tools<\/strong>. These automation efforts will streamline routine IAM tasks, improve operational response times, and enhance the overall reliability of identity and access management processes.<\/li>\n\n\n\n<li><strong>Stakeholder Engagement:<\/strong> You will foster strong relationships and <strong>partner effectively with IT, security, and business teams<\/strong> to define and implement comprehensive IAM strategies. This requires excellent communication and interpersonal skills to translate technical requirements into business value and secure buy-in across diverse organizational functions.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">What&#8217;s Needed? Your Expertise in IAM Engineering<\/h3>\n\n\n\n<p>To excel as a Lead IAM Engineer, you&#8217;ll need extensive experience in IAM engineering, a deep understanding of security architecture, and strong proficiency in scripting and cloud security.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Extensive IAM Engineering Experience:<\/strong> You must possess a minimum of <strong>6 years of verifiable experience in IAM engineering, security architecture, or a related field<\/strong>. This extensive background demonstrates a seasoned professional capable of tackling complex identity and access management challenges in an enterprise environment.<\/li>\n\n\n\n<li><strong>Educational Background:<\/strong> A <strong>Bachelor&#8217;s degree in a related field<\/strong> (e.g., Computer Science, Cybersecurity, Information Systems) is required. Alternatively, <strong>10 years of relevant cybersecurity experience<\/strong> can be considered in lieu of a degree, indicating a strong practical foundation.<\/li>\n\n\n\n<li><strong>Deep Expertise in IAM Platforms and Protocols:<\/strong> You bring <strong>deep expertise in IAM platforms<\/strong> (e.g., Okta, SailPoint, CyberArk, Azure AD), demonstrating hands-on experience with these leading solutions. This is coupled with a strong understanding of <strong>authentication protocols<\/strong> (e.g., OAuth, OpenID Connect, SAML) and <strong>cloud security<\/strong> principles.<\/li>\n\n\n\n<li><strong>Proficiency in Scripting Languages:<\/strong> You possess <strong>proficiency in scripting languages<\/strong> such as <strong>PowerShell, Python, and Bash<\/strong>. This is crucial for automating IAM tasks, managing system configurations, and enhancing operational efficiency within complex IT environments.<\/li>\n\n\n\n<li><strong>Strong Understanding of Zero Trust and Risk-Based Authentication:<\/strong> You have a <strong>strong understanding of Zero Trust principles<\/strong> (never trust, always verify) and <strong>identity-centric security concepts<\/strong>. You also possess knowledge of <strong>risk-based authentication<\/strong> methodologies, where access decisions are dynamically adjusted based on context and risk levels.<\/li>\n\n\n\n<li><strong>Excellent Problem-Solving, Communication, and Leadership Skills:<\/strong> You demonstrate <strong>excellent problem-solving skills<\/strong> to diagnose and resolve complex IAM issues effectively. This is complemented by strong communication skills (verbal and written) for stakeholder engagement and proven <strong>leadership skills<\/strong> to guide teams and initiatives.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Preferred Qualifications: Enhancing Your Leadership Profile<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Certifications:<\/strong> Certifications such as <strong>CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager)<\/strong>, or <strong>IAM-specific credentials<\/strong> (e.g., CIAM, GIAC Identity Management) are highly desirable, validating advanced expertise in information security and identity management.<\/li>\n\n\n\n<li><strong>DevSecOps Experience:<\/strong> Experience integrating IAM with <strong>CI\/CD (Continuous Integration\/Continuous Delivery) pipelines<\/strong> and familiarity with <strong>DevSecOps practices<\/strong> would be a significant plus, showcasing your ability to embed security into modern software development workflows.<\/li>\n\n\n\n<li><strong>API Security and IAM SDKs:<\/strong> Familiarity with <strong>securing APIs<\/strong> and experience using <strong>IAM SDKs (Software Development Kits)<\/strong> would be beneficial, indicating hands-on development skills related to identity solutions.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>If this <strong>Lead IAM Engineer<\/strong> role in <strong>Newark, NJ, or New York, NY<\/strong>, aligns with your extensive IAM engineering experience, leadership capabilities, and passion for driving enterprise-level security solutions, then this <strong>full-time, permanent<\/strong> opportunity is an excellent chance to make a significant impact within a leading energy\/utilities organization.<\/p>\n\n\n\n<p>Are you ready to lead the future of Identity and Access Management?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>An opportunity has come through our network for a Lead IAM Engineer at a leading energy\/utilities organization. This full-time, permanent position offers hybrid\/remote flexibility, allowing you to be based out of Newark, New Jersey, or New York, New York, with a competitive salary ranging from $140,000 &#8211; $165,000 annually. This is a senior-level, hands-on technical [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"menu_order":0,"template":"","jobpost_category":[426,231],"jobpost_job_type":[348,230],"jobpost_location":[357,2860,813],"jobpost_tag":[286,442,604,272,3243,576,3244,848,746,682,603,334,248,3240,1592,3245,3241,1969,837,525,3242,566,833,840,593,863,829,3246,260,591,845,279,1484,243,245,835,844,847,586,843],"class_list":["post-2761","jobpost","type-jobpost","status-publish","hentry","jobpost_category-it","jobpost_category-security","jobpost_job_type-hybrid","jobpost_job_type-permanent","jobpost_location-new-york-city-ny","jobpost_location-new-york-ny","jobpost_location-newark-nj","jobpost_tag-access-control","jobpost_tag-active-directory","jobpost_tag-api-security","jobpost_tag-automation","jobpost_tag-aws-iam","jobpost_tag-azure-ad","jobpost_tag-azure-iam","jobpost_tag-bash","jobpost_tag-cism","jobpost_tag-cissp","jobpost_tag-cloud-iam","jobpost_tag-compliance","jobpost_tag-devsecops","jobpost_tag-energy-utilities","jobpost_tag-hybrid-remote","jobpost_tag-iam-certifications","jobpost_tag-iam-solutions","jobpost_tag-identity-access-management","jobpost_tag-identity-governance","jobpost_tag-incident-response","jobpost_tag-jit-access","jobpost_tag-ldap","jobpost_tag-lead-iam-engineer","jobpost_tag-least-privilege","jobpost_tag-mfa","jobpost_tag-new-york-ny","jobpost_tag-newark-nj","jobpost_tag-newark-tech-jobs","jobpost_tag-nist","jobpost_tag-oauth","jobpost_tag-openid-connect","jobpost_tag-pam","jobpost_tag-permanent-job","jobpost_tag-powershell","jobpost_tag-python","jobpost_tag-rbac","jobpost_tag-saml","jobpost_tag-sox","jobpost_tag-sso","jobpost_tag-zero-trust"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/jobpost\/2761","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/jobpost"}],"about":[{"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/types\/jobpost"}],"author":[{"embeddable":true,"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/users\/1"}],"wp:attachment":[{"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/media?parent=2761"}],"wp:term":[{"taxonomy":"jobpost_category","embeddable":true,"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/jobpost_category?post=2761"},{"taxonomy":"jobpost_job_type","embeddable":true,"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/jobpost_job_type?post=2761"},{"taxonomy":"jobpost_location","embeddable":true,"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/jobpost_location?post=2761"},{"taxonomy":"jobpost_tag","embeddable":true,"href":"https:\/\/estreetsecurity.com\/services\/wp-json\/wp\/v2\/jobpost_tag?post=2761"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}