More jobs:
Lead Hybrid Identity Lead Engineer; IAM
Job in
New York, New York County, New York, 10261, USA
Listed on 2026-03-12
Listing for:
Kforce Technology Staffing
Full Time
position Listed on 2026-03-12
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer -
Engineering
Cybersecurity, Systems Engineer
Job Description & How to Apply Below
Location: New York
RESPONSIBILITIES:
Lead IAM Engineer Responsibilities
Kforce is partnering with a mission-driven organization in New York, NY seeking a Hybrid Identity Lead Engineer to help lead enterprise-wide IAM initiatives supporting a modern Zero Trust architecture. This is a hands-on, lead-level role focused on hybrid identity across on-prem and cloud environments, with core emphasis on Microsoft Entra (Azure AD) and AWS IAM (Google Cloud Platform is a plus, not required).
You'll play a key role in designing secure, scalable identity solutions, driving automation and governance, and partnering closely with security and infrastructure teams. The role is super flexible (about once per week onsite) and offers a strong overall package including a 403(b), generous PTO, excellent medical benefits, tuition reimbursement, and a discretionary bonus.
Lead IAM Engineer Lead IAM Engineer What You'll Do:
* Identity Lead Engineer will architect and maintain a unified IAM framework across AD, Azure AD, AWS, and Google Cloud Platform
* Implement enterprise identity standards including RBAC, naming conventions, and lifecycle automation
* Lead the adoption of Zero Trust principles and enforce least privilege access across multi-cloud environments
* Collaborate with Dev Ops and cloud teams to ensure secure, auditable access models
* Administer and optimize on-prem Active Directory and Entra l Access policies
* Automate provisioning and group management using Power Shell, Python, or Terraform
* As an Identity Lead Engineer, you will respond to audit findings and security assessments with expert-level IAM solutions
* Mentor engineers and contribute to cross-functional initiatives across IT security, infrastructure, and compliance
REQUIREMENTS:
Lead IAM Engineer Requirements
* Bachelor's degree in a related field
* Cloud certifications such as:
Microsoft Certified:
Identity and Access Administrator Associate; AWS Certified Security Specialty;
Google Cloud Platform Cloud Security Engineer
* 7+ years of experience in identity and access management
* Hands-on experience with Active Directory, Azure AD, AWS IAM, and Google Cloud Platform IAM
* Strong scripting skills (Power Shell, Python, Terraform)
* Familiarity with PAM tools (e.g., Cyber Ark, Beyond Trust) and IGA solutions (e.g., SailPoint)
The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.
We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.
Note:
Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.
This job is not eligible for bonuses, incentives or commissions.
Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
By clicking ?
Apply Today? you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×