Johnson Financial Group logo

Information Security Identity & Access Management Engineer

Johnson Financial Group

On-siteRacine, WIseniorPosted 6h ago

Job description

Overview

The Information Security Identity & Access Management (IAM) Engineer is responsible for engineering, implementing, and supporting enterprise identity and access capabilities that protect JFG systems and data through strong authentication, authorization, and access governance. Working under the direction of the Information Security Engineer & Operations Manager, this position focuses on Identity Lifecycle Management, Identity Governance & Administration (IGA), and Privileged Access Management (PAM) to ensure timely, appropriate, and auditable access aligned to business roles and the principle of least privilege. The engineer partners cross-functionally with IT, architecture, HR, and business stakeholders to deliver scalable identity solutions that enable secure business operations. Consistent with industry trends, this role requires a broad, cross-functional skillset across IAM, security architecture & engineering, and data protection, rather than deep specialization in a single domain. The role contributes to the design and continuous improvement of zero trust-aligned access controls, ensuring integration with cloud, on-prem, and customer identity platforms. This is an individual contributor role that may provide technical leadership and mentorship. Occasional off-hour and on-call support may be required. Less than 5% travel expected.

Key Responsibilities

  • Design, implement, and maintain enterprise IAM solutions, including identity lifecycle, authentication, authorization, and federation

  • Engineer and operate Identity Governance & Administration (IGA) capabilities such as provisioning/deprovisioning, access certifications, and role-based access control (RBAC)

  • Implement and support Privileged Access Management (PAM) controls including vaulting, session management, and least privilege enforcement

  • Support both enterprise identity (EIAM) and customer identity (CIAM) solutions across cloud and hybrid environments

  • Operate and enhance user access reviews (UARs) and certification processes to ensure appropriate access and audit compliance

  • Maintain visibility and reporting on user access activity, entitlements, and privileged usage

  • Partner with Risk and Audit functions to support controls testing, evidence collection, and regulatory requirements

  • Collaborate with IT Architects to design scalable IAM architectures aligned to modern zero trust principles

  • Integrate IAM capabilities with enterprise platforms (e.g., Microsoft Entra ID, SaaS applications, on-prem AD)

  • Contribute to security architecture & engineering initiatives, ensuring identity is embedded into system designs

  • Build and maintain automation for identity provisioning workflows, access enforcement, and reporting

  • Develop and maintain runbooks, workflows, and standard operating procedures

  • Drive continuous improvement through process optimization and measurable efficiency gains

  • Partner with HR, IT, application owners, and business units to align access models to job functions (“need-to-know”)

  • Act as a technical SME for IAM, translating security requirements into business-aligned solutions

  • Demonstrate strong communication and stakeholder management skills, enabling adoption across non-technical teams

  • Support and deliver IAM operational metrics, dashboards, and KPIs

  • Contribute to program maturity improvements across Identity & Access Management services

  • Provide technical leadership and mentorship to junior engineers or project team members

  • Lead IAM-related initiatives or workstreams to ensure delivery of InfoSec services

Education, Knowledge, And Skills

  • Bachelor’s Degree in Information Security, Cybersecurity, Computer Science, Information Systems, or related field

  • 5-8 years' experience

  • Cybersecurity Certifications preferred: Microsoft AZ-500, Security+, SSCP, JFG InfoSec Platforms

  • Experience with Python and PowerShell scripting languages for automation preferred

  • Works without supervision

  • Expert report writing and communication skills

  • Strong collaboration skills to work with other IS and IT engineers and business partners to solve problems effectively

  • Has strong understanding of Information Security platforms at JFG

  • Has strong understanding of common Information Security controls and frameworks

  • Has a strong understanding of networking concepts and technologies

  • Has a strong understanding of Windows and Linux environments

  • Can operate beyond instruction and guidelines where needed

  • Has strong understanding of both cybersecurity industry and financial services industry allowing them to revise existing processes/standards or establish new processes/standards as needed

  • Takes complete ownership of all RunBook, support, and process documentation for their service portfolio

For Senior Level:

  • 8+ years of experience for a Senior level role

  • Ability to guide work of other team members

  • Expert level understanding of security controls

  • Ability to identify operational capability gaps and establish roadmaps / strategies

Come as you are.

Come as You Are.