Remote job
Staff Engineer, Identity & Access Management (IAM)
Job details
About this role
Role overview Staff-level engineering role shaping the Identity and Access Management (IAM) strategy across products, platforms, cloud and on-premise infrastructure, and corporate applications within a biotechnology organisation. The position partners deeply with IT, security, and engineering teams to embed zero-trust principles and deliver secure, compliant identity services that accelerate scientific work.
Responsibilities - Assess the current IAM landscape and revamp the IAM strategy across products, platforms, cloud/on-premise infrastructure, and corporate applications. - Drive IAM implementation as part of a broader zero-trust security strategy. - Architect and design cloud-based identity governance, access management, and directory solutions. - Implement RBAC and ABAC workflows for onboarding and ongoing identity lifecycle management. - Act as a key technical and strategic advisor across IT, security, and development to embed IAM principles into broader security architecture. - Partner with engineering and IT to ensure applications are built with appropriately scoped access privileges and aligned to risk. - Define KPIs, KCIs, and KRIs that surface IAM control effectiveness and support continuous improvement. - Collaborate with compliance partners to ensure IAM solutions meet SOX, GxP, and other regulatory standards.
Requirements - Bachelor's or Master's degree in Computer Science, Information Security, or a related field. - 7+ years of experience across Identity and Access Management and broader information security domains. - Proven track record leading large-scale IAM initiatives from strategy through execution in cloud-first and hybrid environments. - Proficiency in at least one programming language such as Java, C++, or Python as it relates to IAM products. - Expert-level experience with enterprise identity administration and governance platforms. - Expert-level experience with adaptive authentication, OAuth, OpenID, and SAML. - Deep familiarity with the identity stack including Enterprise Active Directory and cloud IAM products such as Okta, AWS IAM, Azure AD, or Duo. - Hands-on experience with privileged access management solutions such as Delinea or CyberArk. - Working knowledge of UNIX/Linux, macOS, Windows, and database management systems. - Strong communication and leadership skills, with the ability to influence across multiple teams and disciplines; experience acting as a business systems analyst to elicit technology-agnostic requirements is valued. - Continuous-improvement mindset and awareness of emerging IAM trends. - Relevant security certifications such as CISSP, OSCP, or GWAPT are highly desirable.
Benefits and work setup - Remote-eligible position; Salt Lake City is the preferred home base, with regular on-site visits expected for routine work and team events. - Estimated annual base salary range of $180,600–$212,900, plus eligibility for an annual bonus, equity compensation, and a comprehensive benefits package.