The Infrastructure Security Engineer - Identity and Access Management, Sr role provides first line defense for the credit union by designing, implementing, operating and supporting Identity and Access Management (IAM) capabilities, including identity lifecycle management, authentication and authorization, SSO/MFA, Role Based Access Control (RBAC)/Attribute Based Access Control (ABAC), Separation of Duties (SoD), Privileged Access Management (PAM), and access reviews. Additionally, engineers and supports identity platforms such as Active Directory, Entra ID, etc., and designs and enforces security controls within these platforms. The role works cross functionally with HR, Platform, Application, Audit, and Risk teams to enforce least privilege and reduce risk. Partners with Cybersecurity on incident response and remediation. At the senior level, the engineer focuses on implementing and supporting modern enterprise IAM systems, integrating secure identity solutions throughout the product lifecycle, executing architected designs, and ensuring IAM services are successfully adopted, integrated, and maintained across the organization. The engineer is also responsible for ensuring secure identity practices and processes across the organization, enabling secure authentication, and partnering with the business to ensure secure by default identity practices.
Essential Functions
β’ Design & Implement: Design and implement IAM solutions including RBAC, ABAC, and identity governance integrations with HR systems, directories, applications, and cloud platforms. Engineer and support Privileged Access Management (PAM) platforms (e. g. , Delinea) including credential vaulting, session management, least-privilege, and break-glass access. Architect and secure Active Directory Domain Services (AD DS) including group policy design, privileged group protection, permission inheritance, and forest recovery from compromise scenarios. Implement and manage cloud identity platforms including PIM, Conditional Access Policies, MFA, and passwordless authentication (Windows Hello for Business, FIDO2). Design and manage Active Directory Certificate Services (AD CS) and PKI infrastructure including certificate templates, enrollment permissions, and lifecycle management. Build and automate identity workflows and integrations using APIs, scripting, and infrastructure-as-code (PowerShell, Python, IaC/PaC). Embed security-by-design into identity architecture, configuration baselines, and change management processes. Partner with engineering, platform teams, and Risk & Compliance to ensure IAM solutions meet security, regulatory, and audit requirements.
β’ Operations: Respond to Level 2 support requests including incidents, outages, bugs, and feature requests across development, QA, and production environments. Monitor IAM platforms and support change management processes across Digital Technology environments. Maintain IAM policies, standards, and procedures. Troubleshoot and resolve complex identity and access issues across the identity technology stack. Coordinate with Cybersecurity Operations to respond to identity-related security events and support incident response and post-incident improvements. Execute user lifecycle operations including onboarding, offboarding, and access request fulfillment.
β’ Research: Stay current on identity technologies, risks and threats and participate in roadmap creation through organic releases and/or from business stakeholders Research, develop, and understand authentication factors, associated risks and benefits, and the impact on user experience Research, evaluate, recommend and implement new technologies/capabilities Maintain up-to-date industry knowledge relative to Identity Security, IAM, PAM technologies and methodologies, risks and threats through courses, webinars, books, and self-study. Recommend changes to leadership based on this knowledge.
β’ Bank Secrecy Act: Remains cognizant of and adheres to Wings policies and procedures, and regulations pertaining to the Bank Secrecy Act.