Haystack
← Back to Jobs
Technology

Security Engineer, IAM

PelleraUnited States🇺🇸United StatesPosted 11 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Position Title: Security Engineer, IAM

Position Location: Remote in the United States

Job Summary:

The Security Engineer, Identity & Access Management (IAM), serves within the Office of the CISO as the operational bridge between Security and Internal IT for identity and access governance, remediation tracking, and exception management. This role is responsible for maintaining independent security oversight while driving timely, auditable execution of access governance activities across the organization. The ideal candidate combines hands-on IAM expertise with strong governance discipline, documentation rigor, and the ability to coordinate recurring operational processes such as access reviews, remediation tracking, and risk-based exception handling.

Essential Functions:
  • Serve as the primary liaison between Security and Internal IT for access control, remediation tracking, and security control implementation.
  • Administer identity and access governance activities, including account lifecycle management, entitlement reviews, privileged access reviews, and account cleanup.
  • Coordinate recurring access review cycles, including monthly, quarterly, and annual certifications, privileged account reviews, role-change validations, inactive account reviews, and exception management processes.
  • Manage the operational aspects of security exception requests, including intake, documentation, risk assessment support, approval routing, renewals, and status reporting.
  • Partner with People Operations and Internal IT to reconcile identity data, review orphaned accounts, and drive appropriate deprovisioning activities.
  • Support vulnerability remediation governance processes, including issue tracking, escalation, and maintenance of formal exception documentation.
  • Prepare audit and compliance evidence related to access governance, privileged access management, remediation activities, and exception management programs.
  • Develop and maintain dashboards, metrics, and reporting to communicate review completion rates, remediation status, exception aging, and ownership accountability.
  • Collaborate with Security, Internal IT, GRC, application owners, and business stakeholders to advance remediation efforts and governance objectives.



Required Skills/Abilities/Competencies:
  • Strong knowledge of identity lifecycle administration, access governance, privileged access management, entitlement governance, and deprovisioning workflows.
  • Knowledge of enterprise identity platforms, directory services, role-based access control (RBAC), and privileged access principles.
  • Experience coordinating access reviews, resolving account exceptions, and collaborating effectively with technical and non-technical stakeholders.
  • Strong written and verbal communication skills with the ability to facilitate structured review and approval processes.
  • Ability to maintain audit-ready documentation and evidence records while working within defined operational processes, SLAs, and governance frameworks.
  • Knowledge of formal exception management processes, including approvals, renewals, compensating controls, and risk acceptance procedures.
  • Familiarity with vulnerability governance, remediation tracking, security metrics, and reporting.
  • Experience creating dashboards, structured reporting, and metrics to support governance and operational decision-making.
  • Scripting or automation experience to support access reviews, remediation tracking, reporting, or evidence collection.
  • Demonstrated competencies in Identity and Access Management, Access Governance, Privileged Access Management, Exception and Risk Management, Audit Readiness, Stakeholder Coordination, Reporting and Metrics, and Process Improvement.


Education and Experience:
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field; or an equivalent combination of education and professional experience.
  • Minimum of 4-6 years of experience in Identity and Access Management, Security Operations, Access Governance, or a closely related security engineering discipline.
  • Preferred experience supporting formal exception management programs and audit/compliance activities related to access controls and privileged access governance.
  • Preferred experience with automation, remediation governance, and security operations reporting.
  • Relevant professional certifications such as Security+, SC-300, CISSP, or comparable security and IAM certifications are preferred.



Physical Requirements:
  • Prolonged periods of sitting at a desk and working on a computer.
  • Must be able to lift up to 15 pounds at times.

Similar jobs