Iam Engineer Jobs in New York
Iam Engineer jobs in New York are among the most active in the country, concentrated in financial services, healthcare, and large-scale technology operations where identity and access management is a core security function, with openings at every level from junior IAM analyst through principal engineer. Most hiring is anchored in New York City, with additional demand in Albany and Buffalo, where employers such as JPMorgan Chase, Citigroup, and New York-Presbyterian Hospital maintain substantial security engineering teams. Cloud identity platforms, privileged access management, and zero-trust architecture are the specialties drawing the strongest interest from New York hiring managers right now. Find a role that fits below and apply directly.
Find Iam Engineer JobsOverview
Showing 5 of 7+ Iam Engineer jobs











Company Overview
Monroe University, founded in 1933, is a national leader in higher education access, affordability, and attainment. We believe in the power of education to facilitate social mobility and transform communities, and embrace our responsibility to advocate national policies that serve students’ best interests. We are proud of our outcomes and unique caring environment, especially for first-generation college students, newly arriving immigrants, and international students. Our innovative curriculum, taught by experienced industry professionals, integrates local, national, and global perspectives. Our academic programs align with industries that drive the New York and international economies that we serve. Our graduates are prepared for continued scholarship, professional growth, and career advancement.
Overview of the Position:
The Senior IAM Engineer is a senior individual contributor within the Cybersecurity team at Monroe University. This role owns the identity perimeter across Monroe’s hybrid environment — including the cloud identity tenant, on-premises directory services, and integrations with the Student Information System, Human Resources, and cloud applications. The Senior IAM Engineer serves as the primary technical authority on identity architecture, authentication, access lifecycle, and privileged access. This role partners closely with the CIO’s IT team on day-to-day operations while reporting to the Chief Information Security Officer for strategic direction and governance. The Senior IAM Engineer works in close coordination with Monroe’s student-serving functions to enable secure access for students, faculty, staff, and student workers across the Bronx, New Rochelle, and Saint Lucia campuses.
Core Responsibilities:
- Design, implement, and operate Monroe’s cloud identity architecture (Microsoft Entra ID / Azure AD) as the authoritative identity perimeter for students, faculty, staff, and third parties.
- Own identity segmentation strategy — establishing attribute-driven conditional access policies that separate student access from staff and faculty access, while enabling flexible handling of dual roles such as student workers.
- Administer and evolve multi-factor authentication coverage across the full user population, ensuring phishing-resistant authentication for privileged and sensitive roles.
- Implement and manage privileged access management (PAM) for administrative and service accounts across on-premises and cloud environments, including VMware, Microsoft 365, and critical business systems.
- Partner with HR and the Student Information System owners to establish authoritative, attribute-driven identity lifecycle automation — provisioning, deprovisioning, role changes, and academic calendar-aligned access adjustments.
- Own the identity governance function — access reviews, separation of duties enforcement, dormant account cleanup, and regular audits of privileged group membership.
- Manage integrations between the identity platform and cloud applications, including the Learning Management System, financial aid systems, and productivity tools, using modern federation standards (SAML, OAuth, OIDC, SCIM).
- Serve as the identity lead for incident response, providing rapid account investigation, credential compromise assessment, and containment support.
- Collaborate with the Senior Vulnerability and Threat Analyst on identity-centric threat detection, including anomalous sign-in patterns, impossible travel events, and privileged account misuse.
- Document identity architecture, policies, and procedures to support the institution’s GLBA Safeguards Rule compliance posture and to enable knowledge transfer across the Cybersecurity Nucleus and IT teams.
- Support the Student Cyber Corps program by designing secure, sandboxed access patterns for student-led security engagements that never touch production PII.
- Participate in Monroe’s incident response on-call rotation once established.
Skills and Attributes:
- Deep technical expertise with Microsoft Entra ID (Azure AD), including conditional access, Identity Protection, PIM, and hybrid join configurations.
- Strong working knowledge of on-premises Active Directory, Group Policy, and hybrid identity architectures.
- Hands-on experience with privileged access management platforms (CyberArk, BeyondTrust, Delinea, or Microsoft Privileged Identity Management).
- Fluency in modern authentication and federation protocols — SAML 2.0, OAuth 2.0, OIDC, SCIM, and WS-Federation.
- Scripting and automation skills — PowerShell, Microsoft Graph API, and basic Python or equivalent.
- Experience with identity governance platforms (Microsoft Entra ID Governance, SailPoint, Saviynt, or Okta Identity Governance) is strongly preferred.
- Understanding of higher-education identity contexts — FERPA, Family Educational Rights, GLBA Safeguards Rule — or demonstrated ability to learn rapidly.
- Excellent collaboration and communication skills; comfort working across IT, HR, academic, and student-facing functions.
- Strong documentation habits and a bias toward operationalizing solutions so others can run them.
- Calm, deliberate judgment during incidents; ability to work under pressure without compromising rigor.
Qualifications
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field; equivalent professional experience considered.
- Minimum 6–8 years of progressive experience in identity and access management, with at least 3 years in a senior or lead technical role.
- Professional certifications such as Microsoft Certified: Identity and Access Administrator Associate, CISSP, or SC-300 strongly preferred.
- Experience in higher education, healthcare, financial services, or another regulated environment is preferred.
- Demonstrated experience supporting MFA rollouts, conditional access implementations, or PAM deployments in production environments.
- Ability to work on-site at Monroe’s Bronx and New Rochelle campuses at least four days per week.
Pay: $54,629.72 - $65,790.63 per year
Benefits:
- 401(k)
- Dental insurance
- Flexible spending account
- Health insurance
- Health savings account
- Life insurance
- Paid time off
- Tuition reimbursement
- Vision insurance
Work Location: In person
See All 7 Iam Engineer Jobs in New York
Find roles in New York that match your experience and apply in just a few clicks.
Find Iam Engineer JobsIam Engineer Jobs by City in New York
Where New York roles are concentrated, by current openings.
Iam Engineer Job Market in New York
A snapshot from current New York openings, updated as new roles post.
Who's Hiring
- New York Life2

- Capgemini1

- Deloitte1

- Monroe University1

- NBCUniversal1

Top Industries Hiring
- Insurance2
- Banking & Financial Services1
- Education1
- Science & Research1
- Sports & Recreation1
What New York Employers Look For
The qualifications that appear most often in iam engineer jobs across New York.
- Bachelor's degree in computer science, information security, or a related technical field
- Hands-on experience with enterprise IAM platforms such as SailPoint, Okta, or CyberArk
- Proficiency in directory services including Active Directory, LDAP, and Azure AD
- Experience designing or implementing single sign-on and multi-factor authentication solutions
- Familiarity with regulatory compliance frameworks such as SOX, HIPAA, or NYDFS cybersecurity requirements
- Strong scripting skills in Python, PowerShell, or a comparable language for IAM automation
Iam Engineer Jobs in New York: Frequently Asked Questions
How do you become a iam engineer in New York?
The most direct path into an iam engineer role in New York starts with a bachelor's degree in computer science, cybersecurity, or information systems, followed by vendor certifications such as SailPoint IdentityNow Certified Engineer, Okta Certified Professional, or CyberArk Defender. New York has no state-issued license specific to iam engineers, so employers weigh certifications, demonstrated platform experience, and a portfolio of identity governance or privileged access projects heavily when evaluating candidates.
Which companies hire iam engineers in New York?
Employers hiring iam engineers in New York right now include New York Life, Capgemini, and Deloitte, based on current listings on Migrate Mate as of June 2026. New York's concentration of global financial institutions, major hospital networks, and large technology firms means demand for iam engineers is consistent year-round rather than cyclical.
Which New York cities have the most iam engineer jobs?
The cities with the most iam engineer openings in New York are New York, Bronx, and Brooklyn. New York City dominates the distribution because the financial services sector headquartered in Manhattan requires mature identity governance programs at scale, while Albany and Buffalo contribute openings through state government agencies and regional healthcare systems that have expanded their cybersecurity functions.
Are there remote iam engineer jobs in New York?
Yes, and more than most technical fields, since iam engineer work is largely configuration, policy, and platform administration that does not require physical presence. About 43% of iam engineer openings tied to New York are remote or hybrid as of June 2026, reflecting how broadly distributed IAM tools are managed. The roles most commonly offered fully remote are those focused on cloud identity platforms and identity governance administration rather than on-premise directory management.
How can I get hired as a iam engineer in New York with little or no experience?
The most realistic entry path is moving into IAM from an adjacent IT or security role such as help desk analyst, systems administrator, or junior security analyst, which many large New York employers including major banks and hospital systems treat as natural feeders into identity teams. Pursuing an entry-level certification such as CompTIA Security+ alongside a SailPoint or Okta fundamentals credential signals readiness. New York's financial sector and agencies like the New York State Office of Information Technology Services also post associate-level IAM roles that do not require prior dedicated IAM experience.
Where can I find and apply to iam engineer jobs in New York?
You can find and apply to iam engineer jobs in New York on Migrate Mate, which lists current New York openings updated in real time. Search the listings to find roles that match your experience and specialization, then apply directly to the ones that fit.
See All 7 Iam Engineer Jobs in New York
Find roles in New York that match your experience and apply in just a few clicks.
Find Iam Engineer Jobs