IDEXX

Identity & Access Management (IAM) Engineer

IDEXX$100K — $125K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in Identity and Access Management, Identity Governance, or Security Engineering.
  • Experience with IGA platforms like Microsoft Entra, SailPoint, or Okta.
  • Strong knowledge of RBAC, Access Certifications, and Identity Lifecycle Management.
  • Proficient in managing service accounts and various types of identities.
  • Experience with Microsoft Azure, AWS IAM, and Google Cloud IAM.
  • Scripting experience with PowerShell and APIs.

Responsibilities

  • Implement enterprise Identity Governance and Administration solutions.
  • Design access certification and entitlement management processes.
  • Develop joiner, mover, and leaver workflows for identity management.
  • Support role-based access control and governance initiatives.
  • Establish governance standards for service accounts across environments.
  • Design controls for privileged access management and credential rotation.
  • Define governance frameworks for AI agents and automation platforms.

Benefits

  • Health, dental, and vision benefits from day one.
  • 5% matching 401k plan.
  • Annual cash bonus opportunity.
  • Comprehensive support including mental health resources and pet insurance.
  • Paid volunteer days and employee stock program.
Full Job Description
We are seeking an experienced Identity and Access Management (IAM) Engineer to lead the design, implementation, and operational maturity of Identity Governance and Administration (IGA) capabilities across the enterprise. This role focuses on securing and governing both human and non-human identities, including service accounts, managed identities, workload identities, automation accounts, API integrations, and AI agents.

The IAM Engineer will be responsible for developing scalable identity governance processes, automating lifecycle management, enforcing least-privilege access, and reducing risk associated with service accounts and machine identities. This individual will work closely with Security, Infrastructure, Cloud Engineering, Application Owners, and Compliance teams to improve identity visibility, governance, and operational efficiency.

In this role, you will be responsible for...

Identity Governance & Administration (IGA)
  • Implement and maintain enterprise Identity Governance and Administration (IGA) solutions.
  • Design and manage access certification, access review, and entitlement management processes.
  • Develop and optimize joiner, mover, and leaver workflows.
  • Support role-based access control (RBAC) and access governance initiatives.
  • Partner with business stakeholders to define access models and governance controls.
  • Support audit, compliance, and regulatory requirements through reporting and attestation processes.

Service Account Governance
  • Establish governance standards for service accounts across on-premises and cloud environments.
  • Create and maintain inventory, ownership, classification, and lifecycle processes for service accounts.
  • Reduce interactive use of service accounts and implement secure authentication methods.
  • Design controls for credential rotation, privileged access management, and monitoring.
  • Conduct periodic reviews to identify orphaned, stale, or over-privileged service accounts.

Managed Identities & Workload Identities
  • Design and govern Azure Managed Identities and other cloud-native workload identities.
  • Develop standards for application authentication and authorization.
  • Partner with application teams to eliminate embedded credentials and secrets.
  • Implement least-privilege access models for cloud workloads and services.
  • Monitor and review workload identity permissions for excessive privilege.

AI Agents & Non-Human Identity Management
  • Define governance frameworks for AI agents, automation platforms, bots, APIs, and machine identities.
  • Establish controls for identity creation, ownership, access reviews, and lifecycle management.
  • Develop policies for agent-to-agent and agent-to-application access.
  • Ensure visibility and traceability of non-human activity across enterprise systems.
  • Partner with security teams to mitigate emerging risks associated with autonomous systems and AI-enabled workflows.

Automation & Engineering
  • Develop automation using PowerShell, Graph API, REST APIs, and cloud-native tooling.
  • Automate provisioning, deprovisioning, access reviews, reporting, and governance workflows.
  • Build integrations between IAM platforms, cloud providers, HR systems, ServiceNow, and enterprise applications.
  • Continuously improve IAM operational efficiency through scripting and workflow optimization.

Security & Compliance
  • Enforce least privilege and separation-of-duties controls.
  • Support security assessments, audit requests, and compliance reviews.
  • Develop metrics and reporting related to identity governance maturity.
  • Participate in incident response and investigations involving identity-related risks.
  • Maintain alignment with industry frameworks such as NIST, ISO 27001, SOC 2, and CIS controls.


What you will need to succeed...
  • Location: we are looking someone preferably driving distance to our HQ in Westbrook, Maine where we have a flexible hybrid requirement of only 8 days per month. We are also open to those in NH or MA that can come on site less frequently.
  • 5+ years of experience in Identity and Access Management, Identity Governance, or Security Engineering.
  • Experience implementing or administering IGA platforms such as:
    • Microsoft Entra ID Governance
    • SailPoint IdentityNow / IdentityIQ
    • Saviynt
    • Okta Identity Governance
  • Strong understanding of:
    • RBAC
    • Access Certifications
    • Entitlement Management
    • Identity Lifecycle Management
  • Experience managing:
    • Service Accounts
    • Managed Identities
    • Application Identities
    • API Credentials
    • Workload Identities
  • Experience with:
  • Microsoft Entra ID
  • Active Directory
  • Azure
  • AWS IAM
  • Google Cloud IAM
  • Proficiency with PowerShell, REST APIs, and automation scripting.

Preferred Qualifications
  • Experience with Privileged Access Management (CyberArk, BeyondTrust, Delinea, Microsoft PAM, etc.).
  • Experience governing AI agents, automation platforms, and machine identities.
  • Knowledge of cloud-native authentication methods and secrets management.
  • Experience integrating IAM solutions with HR, ITSM, and enterprise application ecosystems.
  • Microsoft, SailPoint, CISSP, Security+, or relevant IAM certifications.

Success Measures
  • Reduction in unmanaged service accounts and non-human identities.
  • Increased identity governance coverage across enterprise applications.
  • Successful implementation of automated access reviews and certifications.
  • Improved ownership and accountability for service accounts and managed identities.
  • Increased use of least-privilege access models.
  • Reduction in audit findings related to identity governance and access management.
  • Increased automation of identity lifecycle and governance processes


What you can expect from us:
• Base annual salary target: $100000 - $125000 (yes, we do have flexibility if needed)
• Opportunity for annual cash bonus
• Health / Dental / Vision Benefits Day-One
• 5% matching 401k
• Additional benefits including but not limited to financial support, pet insurance, mental health resources, volunteer paid days off, employee stock program, foundation donation matching, and much more!

#LI-EV1

About IDEXX

IDEXX Laboratories, Inc. is an American multinational corporation engaged in the development, manufacture, and distribution of products and services for the companion animal veterinary, livestock and poultry, water testing, and dairy markets. Incorporated in 1983 and headquartered in Westbrook, Maine, and EMEA in Hoofddorp, Netherlands, IDEXX offers products to customers in over 175 countries around the world.
Learn more about IDEXX
Size
10,350 employees
Market Cap
$33.7 billion
Industry
Net Income
$581.7 million
Founded
1983
5 Year Trend
+12.6%
Revenue
$2.7 billion
NASDAQ

Similar Jobs

More Jobs at IDEXX

More Information Technology Jobs

Find similar Identity & Access Management (IAM) Engineer jobs: