STEM OPT Iam Engineer Jobs
IAM Engineer roles in identity governance, access provisioning, and zero-trust architecture sit squarely within STEM OPT eligibility. Your STEM degree qualifies you for a 24-month extension beyond your initial 12-month OPT period, giving you up to 36 months total, as long as your employer is enrolled in E-Verify.
Find STEM OPT Iam Engineer JobsOverview
Showing 5 of 10+ Iam Engineer jobs










See all Iam Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Iam Engineer roles.
Get Access To All Jobs
POWER UP A CAREER WITH US
Our people power everything we do.
At Tampa Electric, dependable electricity starts with dedicated individuals whose talent, skill and passion drive our success. We’ve been lighting the way for West Central Florida for more than 125 years—and we’re just getting started.
Join us and build a rewarding career with competitive pay, comprehensive benefits and a culture that supports your growth. Your potential finds its purpose at Tampa Electric.
We proudly deliver 99.98% electric service reliability to nearly 860,000 customers across 2,000 square miles of Hillsborough County and parts of Polk, Pasco and Pinellas counties. Through innovation and strategic investments, we’re creating a cleaner, brighter energy future—while delivering exceptional service every step of the way.
We reflect the communities we serve and foster a workplace where every employee feels welcomed, valued and engaged. Join our team of energy experts and help shape the future of power.
Storm Duty Requirements
Tampa Electric and its sister companies serve a role in providing critical services to our community during an emergency. Team members are required to participate in the response/recovery activities related to emergencies/disasters to maintain service to our Tampa Electric customers. Team members are required to work in their normal job duties or other assigned activities. Proper compensation will be made in accordance with the company's rules and procedures.
Responding to storms will be considered a condition of employment.
Tampa Electric is proud to be an Equal Opportunity Employer. To learn more, please click on link below:
Disclosure Statements
Title: IAM Security Engineer
Company: Tampa Electric Company
Location: Bearss Operations Center
State and City: Florida - LUTZ
Shift: 8 Hr. X 5 Days
TITLE: IAM Security Technologist Progression
PERFORMANCE COACH: Manager/Sr. Manager Cyber Protection
COMPANY: Tampa Electric Company
DEPARTMENT: Technology
Note that this position can be hired at any level within the job family progression based in Education and years of Experience.
FOCUS AREAS:
- Strong hands-on Saviynt IGA experience, including identity lifecycle management, access reviews, application onboarding and integrations
- CyberArk PAM experience
- Microsoft Entra ID / Active Directory, RBAC and access governance
- IAM integrations, connectors, APIs, scripting and automation
- Ability to work strategically while also being hands-on and extend support for implementations and activities outside the standard MSS scope
IAM Security Technologist Associate
POSITION CONCEPT
The IAM Security Technologist Associate is responsible for supporting the company’s information security systems, ensuring that all procedures are followed on a daily, weekly, and monthly basis. Supports all systems used to secure the enterprise information technology assets, the scope includes all network infrastructure, operating systems, and web server platforms throughout TECO Energy and its subsidiaries. Assists with the development and enhancing of IAM systems including SSO, authentication, and access controls ensuring confidentiality, integrity, and availability of IAM systems and data. Provides IAM Security support for the TECO environment primarily focusing IT corporate applications and OT/NERC applications. Responsible for adhering to established policies, following best practices, developing and possessing a solid understanding of exploits and vulnerabilities, resolving issues by following the appropriate escalation procedures. Supports the enforcement of corporate, regulatory, and risk management policies and assists in developing, maintaining, and publishing corporate IAM security standards, procedures, and guidelines for enterprise computing platforms. Position will be responsible for collaborating with multiple business units across multiple Emera affiliates.
PRIMARY DUTIES AND RESPONSIBILITIES
-
Assist in Developing and maintaining a roadmap for Identity and Access Management (IAM) including Governance and Administration (IGA), Privileged Access Management (PAM), authentication, SSO, directory services, and access governance. Collaborate closely with teams including Cyber Security, Human Resources, Technology, Architecture and Lines of Business (LoBs) to create efficient and user-friendly IAM solutions.
-
Assist in designing, implementing, and maintaining access governance processes, including Joiner/Mover/Leaver workflows, access requests, RBAC, access certifications/reviews, application onboarding, and least-privilege controls. Support enterprise IGA capabilities, including Saviynt, and integrations with business applications and directories.
-
Support Privileged Access Management (PAM) capabilities, including privileged account onboarding, credential management, access controls, and privileged access remediation with emphasis on platforms such as CyberArk.
-
Assist with the deployment, management and enhancement of SSO and authentication solutions, including integrations with enterprise applications, Microsoft Entra ID/Active Directory, and other identity platforms to provide secure and seamless authentication.
-
Assist with the implementation and management of authentication and access control mechanisms, including multi-factor authentication, conditional access, and identity security controls.
-
Assist with the monitoring, troubleshooting and response to identity and access-related incidents and technical issues. Support remediation of unauthorized access, excessive privileges, identity lifecycle failures, and other IAM control issues.
-
Effectively collaborate with both technical and non-technical business owners, application teams, implementation partners, and managed service providers. Identify opportunities to improve IAM automation, integrations, processes and toolsets, and provide hands-on technical support for activities outside standard managed service scope.
SUPERVISION
Direct Supervision: None
Indirect Supervision: None
RELATIONSHIPS
Key Internal: Engaging multiple technology groups and business units. Interactive engagement may require communication with individual contributors, and middle management.
Key External: Little to no key external relationships.
QUALIFICATIONS
Education
Required: Bachelor’s Degree in Computer Science, Information Systems or other technology-related field from an accredited college or university. An associate’s degree with an additional 2 years of required experience may be considered in lieu of a bachelor’s degree. A high school diploma and an additional 4 years of required experience may be considered in lieu of a bachelor’s degree.
Preferred: None.
Licenses/Certifications
Required: None
Preferred: CISSP, CISM, CIAM, ITIL, Sabiynt, CyberArk, Microsoft Identity/Entra, or other relevant IAM/security certifications
Experience
Required: At least one (1) year of experience in IAM or related security engineering experience.
Preferred: Two (2) or more years of experience in IAM or related security engineering experience
Knowledge/Skills/Abilities (KSA)
Required:
- Understanding of Identity and Access Management concepts, including RBAC, least privilege, entitlement management, and access controls.
- Knowledge of identity lifecycle management, including Joiner/Mover/Leaver processes, onboarding, offboarding, access changes, and automated provisioning/deprovisioning.
- Knowledge of Identity Governance and Administration capabilities, including access requests, certifications/access reviews, role management, application onboarding, and governance processes.
- Understanding of Privileged Access Management concepts, including privileged account onboarding, credential management, access controls, and privileged access governance.
- Experience or working knowledge of enterprise IAM technologies such as Saviynt, CyberArk, Microsoft Entra ID, Active Directory, SSO, and MFA.
- Understanding of connectors, REST APIs, scripts, and automation used to integrate IAM platforms with applications, directories, HR systems, and other enterprise technologies.
- Ability to troubleshoot identity, authentication, provisioning, access, and integration-related issues.
- Knowledge of designing and implementing IAM solutions aligned with business requirements, security standards, and enterprise architecture.
- Understanding of access reviews, segregation of duties, excessive access, privileged access, and least-privilege principles.
- Ability to analyze IAM security issues and support remediation of access-related risks and control deficiencies.
- Working knowledge of security and regulatory requirements including NERC CIP, SOX, NIST, and other applicable security frameworks.
- Ability to collaborate effectively with application owners, business teams, Cyber Security, Infrastructure, Architecture, Compliance, implementation partners, and managed service providers.
Preferred:
- None
IAM Security Technologist
POSITION CONCEPT
The IAM Security Technologist is responsible for operating the company’s information security systems, ensuring that all procedures are followed on a daily, weekly, and monthly basis. Provides support, within a team environment, for all systems used to secure the enterprise information technology assets, the scope includes all network infrastructure, operating systems, and web server platforms throughout TECO Energy and its subsidiaries. Direct assistance with the development and enhancing of IAM systems including SSO, authentication, and access controls ensuring confidentiality, integrity, and availability of IAM systems and data. Provides IAM Security support for the TECO environment primarily focusing on IT corporate applications and OT/NERC applications. Responsible for adhering to established policies, following best practices, developing, and possessing an in-depth understanding of exploits and vulnerabilities, resolving issues by taking the appropriate corrective action, or following the appropriate escalation procedures. Supports the enforcement of corporate, regulatory, and risk management policies and assists in developing, maintaining, and publishing corporate IAM security standards, procedures, and guidelines for enterprise computing platforms. Position will be responsible for collaborating with multiple business units across Emera affiliates.
PRIMARY DUTIES AND RESPONSIBILITIES
-
Support the development and maintenance of a strategic roadmap for Identity and Access Management (IAM) including Governance and Administration (IGA), Privileged Access Management (PAM), authentication, SSO, directory services, and access governance. Collaborate closely with teams including Cyber Security, Human Resources, Technology, Architecture and Lines of Business (LoBs) to create efficient and user-friendly IAM solutions.
-
Support the design, implementation and maintenance of access governance processes, including Joiner/Mover/Leaver workflows, access requests, RBAC, access certifications/reviews, application onboarding, and least-privilege controls. Support enterprise IGA capabilities, including Saviynt, and integrations with business applications and directories.
-
Support Privileged Access Management (PAM) capabilities, including privileged account onboarding, credential management, access controls, and privileged access remediation with emphasis on platforms such as CyberArk.
-
Deploy, manage, and enhance SSO and authentication solutions, including integrations with enterprise applications, Microsoft Entra ID/Active Directory, and other identity platforms to provide secure and seamless authentication.
-
Support the implementation and management of authentication and access control mechanisms, including multi-factor authentication, conditional access, and identity security controls.
-
Monitor, troubleshoot, and respond to identity and access-related incidents and technical issues. Support remediation of unauthorized access, excessive privileges, identity lifecycle failures, and other IAM control issues.
-
Effectively collaborate with both technical and non-technical business owners, application teams, implementation partners, and managed service providers. Identify opportunities to improve IAM automation, integrations, processes and toolsets, and provide hands-on technical support for activities outside standard managed service scope.
SUPERVISION
Direct Supervision: None
Indirect Supervision: May provide guidance and mentorship to associate-level technologists, contractors or co-ops assigned to the team.
RELATIONSHIPS
Key Internal: Engaging multiple technology groups and business units, including Finance and HR. Interactive engagement will require communication with individual contributors, middle management.
Key External: Engaging external contacts including vendors, contractors, regulatory agencies, industry associations, and other utility partners.
QUALIFICATIONS
Education
Required: Bachelor’s Degree in Computer Science, Information Systems or other technology-related field from an accredited college or university. An associate’s degree with an additional 2 years of required experience may be considered in lieu of a bachelor’s degree. A high school diploma and an additional 4 years of required experience may be considered in lieu of a bachelor’s degree.
Preferred: Master’s Degree in Computer Science, Information Systems, or other technology-related field from an accredited college or university.
Licenses/Certifications
Required: Will require at least one certification in one of the following: CISSP, CISM, CIAM, ITIL, Sabiynt, CyberArk, Microsoft Identity/Entra, or other relevant IAM/security certifications
Preferred: None
Experience
Required: 3 years of experience in IAM or related security engineering experience
Preferred: 4 or more years of experience in IAM or related security engineering experience.
Knowledge/Skills/Abilities (KSA)
Required:
- Understanding and demonstration of Identity and Access Management concepts, including RBAC, least privilege, entitlement management, and access controls.
- Knowledge of identity lifecycle management, including Joiner/Mover/Leaver processes, onboarding, offboarding, access changes, and automated provisioning/deprovisioning.
- Knowledge of Identity Governance and Administration capabilities, including access requests, certifications/access reviews, role management, application onboarding, and governance processes.
- Understanding of Privileged Access Management concepts, including privileged account onboarding, credential management, access controls, and privileged access governance.
- Experience or working knowledge of enterprise IAM technologies such as Saviynt, CyberArk, Microsoft Entra ID, Active Directory, SSO, and MFA.
- Understanding of connectors, REST APIs, scripts, and automation used to integrate IAM platforms with applications, directories, HR systems, and other enterprise technologies.
- Demonstrated ability to troubleshoot identity, authentication, provisioning, access, and integration-related issues.
- Knowledge of designing and implementing IAM solutions aligned with business requirements, security standards, and enterprise architecture.
- Understanding of access reviews, segregation of duties, excessive access, privileged access, and least-privilege principles.
- Ability to analyze IAM security issues and support remediation of access-related risks and control deficiencies.
- Working knowledge of security and regulatory requirements including NERC CIP, SOX, NIST, and other applicable security frameworks.
- Ability to collaborate effectively with application owners, business teams, Cyber Security, Infrastructure, Architecture, Compliance, implementation partners, and managed service providers.
Preferred:
- Knowledge of Saviynt IGA, including application onboarding, access requests, certifications, lifecycle workflows, and integrations.
- Experience with CyberArk PAM administration, privileged account onboarding, and credential management.
- Experience with Microsoft Entra ID and Active Directory, including authentication, SSO, MFA, and access management.
- Experience with REST APIs, PowerShell, connectors, or other IAM automation technologies.
- Experience supporting IAM solutions in a regulated enterprise or utility environment.
- Ability to work hands-on, supporting IAM implementations, operational improvements, and activities beyond standard managed service scope.
IAM Security Technologist Sr.
POSITION CONCEPT:
The IAM Security Technologist Sr is responsible for operating the company’s information security systems, ensuring that all procedures are followed on a daily, weekly, and monthly basis. Provides expert level support, within a team environment, for all systems used to secure the enterprise information technology assets, the scope includes all network infrastructure, operating systems, and web server platforms throughout TECO Energy and its subsidiaries. Direct assistance with the development and enhancing of IAM systems including SSO, authentication, and access controls ensuring confidentiality, integrity, and availability of IAM systems and data. Provides IAM Security support for the TECO environment primarily focusing on IT corporate applications and OT/NERC applications. Responsible for adhering to established policies, following best practices, developing, and possessing an in-depth understanding of exploits and vulnerabilities, resolving issues by taking the appropriate corrective action, or following the appropriate escalation procedures. Supports the enforcement of corporate, regulatory, and risk management policies and assists in developing, maintaining, and publishing corporate IAM security standards, procedures, and guidelines for enterprise computing platforms. Position will be responsible for collaborating with multiple business units across all Emera affiliates.
PRIMARY DUTIES AND RESPONSIBILITIES
-
Oversight of the development and implementation of a strategic roadmap for Identity and Access Management (IAM) including Governance and Administration (IGA), Privileged Access Management (PAM), authentication, SSO, directory services, and access governance. Collaborate closely with teams including Cyber Security, Human Resources, Technology, Architecture and Lines of Business (LoBs) to create efficient and user-friendly IAM solutions.
-
Leading efforts in designing, implementing, and maintaining access governance processes, including Joiner/Mover/Leaver workflows, access requests, RBAC, access certifications/reviews, application onboarding, and least-privilege controls. Support enterprise IGA capabilities, including Saviynt, and integrations with business applications and directories.
-
Leading Privileged Access Management (PAM) capabilities, including privileged account onboarding, credential management, access controls, and privileged access remediation with emphasis on platforms such as CyberArk.
-
Deploy, manage, and enhance SSO and authentication solutions, including integrations with enterprise applications, Microsoft Entra ID/Active Directory, and other identity platforms to provide secure and seamless authentication.
-
Lead and support the implementation and management of authentication and access control mechanisms, including multi-factor authentication, conditional access, and identity security controls.
-
Monitor, troubleshoot, and respond to identity and access-related incidents and technical issues. Support remediation of unauthorized access, excessive privileges, identity lifecycle failures, and other IAM control issues.
-
Effectively collaborate with both technical and non-technical business owners, application teams, implementation partners, and managed service providers. Identify opportunities to improve IAM automation, integrations, processes and toolsets, and provide hands-on technical support for activities outside standard managed service scope.
-
Serve as the Subject Matter Expert (SME) for audit, compliance, and regulatory efforts related to IAM, SOX and PII through investigating, documenting, and reporting findings to management.
SUPERVISION
Direct Supervision: None
Indirect Supervision: May provide guidance and mentorship to associate-level technologists and security technologists, contractors or co-ops assigned to the team.
RELATIONSHIPS
Key Internal: Engaging multiple I.T. groups and business units, including Finance and HR. Interactive engagement will require communication with individual contributors, middle management.
Key External: Engaging external contacts including vendors, contractors, regulatory agencies, industry associations, and other utility partners.
QUALIFICATIONS
Education
Required: Bachelor’s Degree in Computer Science, Information Systems or other technology-related field from an accredited college or university. An associate’s degree with an additional 2 years of required experience may be considered in lieu of a bachelor’s degree. A high school diploma and an additional 4 years of required experience may be considered in lieu of a bachelor’s degree.
Preferred: Master’s Degree in Computer Science, Information Systems or other technology-related field from an accredited college or university.
Licenses/Certifications
Required: One or more of the following: CISSP, CISM, CIAM, ITIL, Sabiynt, CyberArk, Microsoft Identity/Entra, or other relevant IAM/security certifications
Preferred: Two or more of the above required certifications.
Experience
Required: 5 years of experience in IAM or related security engineering experience
Preferred: 6 or more years of experience in IAM or related security engineering experience.
Knowledge/Skills/Abilities (KSA)
- Advanced knowledge and deployment of Identity and Access Management concepts, including RBAC, least privilege, entitlement management, and access controls.
- Advanced knowledge of identity lifecycle management, including Joiner/Mover/Leaver processes, onboarding, offboarding, access changes, and automated provisioning/deprovisioning.
- Advanced knowledge of Identity Governance and Administration capabilities, including access requests, certifications/access reviews, role management, application onboarding, and governance processes.
- Understanding of Privileged Access Management concepts, including privileged account onboarding, credential management, access controls, and privileged access governance.
- Advanced knowledge of enterprise IAM technologies such as Saviynt, CyberArk, Microsoft Entra ID, Active Directory, SSO, and MFA.
- In-depth knowledge of connectors, REST APIs, scripts, and automation used to integrate IAM platforms with applications, directories, HR systems, and other enterprise technologies.
- Demonstrated ability to troubleshoot identity, authentication, provisioning, access, and integration-related issues.
- Demonstrated knowledge, design, and implementation of IAM solutions
See all STEM OPT Iam Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT Iam Engineer Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as an Iam Engineer
Verify your CIP code before applying
IAM Engineering draws from Computer Science, Information Security, and Systems Engineering CIP codes. Confirm your degree's CIP code with your DSO before applying, because a mismatch delays your I-983 approval and can shorten your authorized work period.
Check E-Verify enrollment before accepting offers
An employer who isn't enrolled in E-Verify cannot legally employ you on STEM OPT extension. Search the E-Verify employer search tool by company name before your final interview to avoid accepting an offer you can't use.
Tailor your I-983 to IAM engineering deliverables
Generic training plans get rejected. List specific learning objectives tied to IAM tools you'll use, such as identity lifecycle management, RBAC policy design, or SCIM integration, so the plan demonstrates a direct connection to your STEM degree field.
Target employers with active identity security teams
Use Migrate Mate to filter for employers who have hired STEM OPT candidates in technology and information security roles, giving you a verified starting point instead of applying blind to companies with no track record of supporting OPT extensions.
Use OFLC Wage Search to benchmark your offer
STEM OPT employers must pay you the same wage as similarly situated U.S. workers. Pull the prevailing wage for your specific IAM role and location using OFLC Wage Search before negotiating, so you can flag any offer that falls below the required threshold.
File your extension application 90 days early
USCIS requires your STEM OPT extension application to be filed at least 90 days before your initial OPT expires. Missing that window means a gap in work authorization, and IAM contract roles often can't absorb even a short break in employment eligibility.
Frequently Asked Questions
Does an IAM Engineer role qualify for the STEM OPT extension?
Yes, provided your underlying degree falls under an eligible STEM CIP code such as Computer Science, Information Technology, or Electrical Engineering, and the IAM Engineer role you're hired into is directly related to that field. Your DSO confirms the CIP code match when endorsing your I-20 for the extension. Roles focused on identity governance, access management, or security architecture consistently satisfy the relatedness requirement.
What does the E-Verify requirement mean for IAM Engineer job seekers?
Every employer who hires you on a STEM OPT extension must be actively enrolled in E-Verify, the federal electronic employment eligibility system. This applies regardless of company size or whether the role is remote. Before accepting any IAM Engineer offer, confirm enrollment through the E-Verify employer search. If the company isn't enrolled, they must join E-Verify before your extension start date or you can't legally begin work.
What goes into an I-983 training plan for an IAM Engineer?
The I-983 must map your IAM Engineer duties to specific learning outcomes tied to your STEM degree. Include concrete objectives such as designing role-based access control policies, integrating identity providers using SAML or OIDC, or auditing privileged access workflows. Generic descriptions like 'gain industry experience' are routinely rejected. Your employer's supervisor signs off, and your DSO reviews it before endorsing your I-20 for the extension.
How does cap-gap protection apply if I'm transitioning from STEM OPT to H-1B?
If your employer files an H-1B visa petition on your behalf before your STEM OPT expires and you're selected in the lottery, cap-gap automatically extends your work authorization through September 30 of that year, or until USCIS adjudicates the petition. You can continue working as an IAM Engineer throughout that period without interruption, as long as your employer remains E-Verify enrolled and your I-983 training plan stays current.
Where can I find IAM Engineer roles where employers already support STEM OPT?
Migrate Mate filters IAM Engineer listings by employers who have a documented history of hiring international students on work authorization, so you're not starting from scratch trying to educate hiring managers about E-Verify or STEM OPT rules. Search by role, location, and authorization type to surface employers prepared to move quickly through the I-983 and E-Verify steps without delays from unfamiliarity.