
Security Engineer, IAM
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Act as the main point of contact between the Security team and Internal IT for matters related to access control, remediation tracking, and the implementation of security controls.
• Oversee identity and access governance initiatives, which include managing account lifecycles, conducting entitlement reviews, performing privileged access assessments, and ensuring account cleanup.
• Organize recurring access review cycles, encompassing monthly, quarterly, and annual certifications, privileged account evaluations, role-change validations, inactive account assessments, and managing exceptions.
• Handle security exception requests, which involve intake, documentation, risk assessment support, approval routing, renewals, and reporting on status.
• Collaborate with People Operations and Internal IT to reconcile identity data, examine orphaned accounts, and facilitate deprovisioning efforts.
• Assist in vulnerability remediation governance, which includes issue tracking, escalation, and the formal documentation of exceptions.
• Compile audit and compliance evidence pertaining to access governance, privileged access management, remediation efforts, and exception management.
• Create and sustain dashboards, metrics, and reports on review completion rates, remediation statuses, exception aging, and accountability for ownership.
• Work together with Security, Internal IT, GRC, application owners, and business stakeholders to achieve remediation and governance goals.
• Extensive knowledge of identity lifecycle administration, access governance, privileged access management, entitlement governance, and deprovisioning workflows.
• Familiarity with enterprise identity platforms, directory services, role-based access control (RBAC), and principles of privileged access.
• Proven experience in coordinating access reviews, addressing account exceptions, and working with both technical and non-technical stakeholders.
• Excellent written and verbal communication skills to support structured review and approval processes.
• Capability to maintain audit-ready documentation and evidence within operational processes, SLAs, and governance frameworks.
• Understanding of formal exception management, including approvals, renewals, compensating controls, and procedures for risk acceptance.
• Knowledge of vulnerability governance, remediation tracking, security metrics, and reporting practices.
• Experience in creating dashboards, structured reporting, and metrics that aid governance and operational decision-making.
• Experience with scripting or automation that supports access reviews, remediation tracking, reporting, or evidence collection.
• Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or an equivalent combination of education and professional experience.
• At least 4–6 years of experience in Identity and Access Management, Security Operations, Access Governance, or closely related security engineering fields.
• Preferred experience with formal exception management programs and audit/compliance activities.
• Preferred experience in automation, remediation governance, and reporting within security operations.
• Relevant certifications such as Security+, SC-300, CISSP, or similar security and IAM certifications are desirable.
• Ability to sit for extended periods and work at a computer.
• Capacity to lift up to 15 pounds occasionally.
• Comprehensive health, dental, and vision insurance plans.
• Retirement savings plan with employer matching contributions.
• Flexible work arrangements and opportunities for remote work.
• Professional development and training programs.
• Generous paid time off and holidays.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.