Tanium

Staff Identity and Access Management Engineer

Tanium$180K — $230K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Computer Science, IT, or a related field (or equivalent experience)
  • 8-10 years in identity and access management, including integrations with HRIS systems
  • Experience with IGA products like Lumos, SailPoint, or Saviynt
  • Hands-on expertise in Entra ID and Active Directory with hybrid environments
  • Proficiency in scripting, particularly PowerShell
  • Knowledge of security/compliance frameworks like ISO 27001 and GDPR
  • Experience with SSO, MFA, and PAM tooling

Responsibilities

  • Design and manage IAM/IGA solutions including SSO, MFA, and PAM
  • Build and maintain identity automation for onboarding, off-boarding, and approval workflows
  • Own, monitor, and continuously improve the identity lifecycle
  • Collaborate with GRC to develop and maintain IAM/IGA policies and standards
  • Regularly assess IAM systems for security gaps and ensure compliance
  • Lead technical delivery on IAM/IGA projects including upgrades and integrations
  • Respond to and resolve IAM-related incidents
  • Mentor engineers and track industry trends

Benefits

  • Equity awards
  • Generous medical, dental, and vision plans
  • Health savings account and flexible spending account
  • 401(k) retirement savings plan with company match
  • Life, accident, and disability coverage
  • Employee assistance programs and well-being benefits
Full Job Description
The Basics

We're looking for a Staff IAM engineer to design, implement, and manage identity and access management (IAM) and identity governance (IGA) solutions across Tanium's corporate infrastructure. You'll evaluate new IAM/IGA technologies, partner with cross-functional teams on strategy, and keep our identity ecosystem secure, compliant, and efficient.

This position follows the Company's hybrid schedule which currently requires employees to work in the office at one of the following locations a minimum of three days per week: Addison, TX; Bellevue, WA; Durham, NC; Emeryville, CA; or Reston, VA.

What you'll do
  • Design and manage IAM/IGA solutions across corporate infrastructure, including SSO, MFA, and PAM
  • Build and maintain identity automation - onboarding, off-boarding, entitlements, and approval workflows - and troubleshoot issues surfaced by testing, user, or peer feedback
  • Own the identity lifecycle: monitor, document, and continuously improve it
  • Partner with GRC to develop and maintain IAM/IGA policies and standards that satisfy regulatory requirements (ISO 27001, FedRAMP, GDPR, HIPAA, etc.)
  • Assess IAM systems regularly for security gaps and insure ongoing patch and policy compliance
  • Lead technical delivery on IAM/IGA projects - upgrades, migrations, integrations - and monitor system performance to identify optimizations
  • Respond to and resolve IAM-related incidents
  • Mentor engineers across IT and Security and track industry trends to keep our IAM/IGA approach current
  • Maintain system design documentation

We're looking for someone with
  • Education
    • Bachelor's Degree in Computer Science, IT or other relevant degree or equivalent work experience
  • Experience
    • 8-10 years in identity and access management, including IGA integrations with HRIS systems (Workday, SuccessFactors, or similar)
    • Experience implementing, configuring, and managing an IGA product like Lumos, SailPoint, Saviynt, etc
    • Hands-on expertise with Entra ID and Active Directory (preferably in a hybrid environment) with respect to identity and access
    • Solid grasp of onboarding/off-boarding standards and lifecycle workflows
    • Scripting proficiency (PowerShell)
    • Working knowledge of security/compliance frameworks - ISO 27001, FedRAMP, GDPR, HIPAA
    • Experience with SSO, MFA, and PAM tooling
    • Strong problem-solving skills and the communication chops to work across IT, Security, and business teams
  • Other
    • Comfortable working independently and juggling multiple priorities in a fast-paced environment

What you'll get

The annual base salary range for this full-time position is $180,000 to $230,000. This range is an estimate for what Tanium will pay a new hire. The actual annual base salary offered may be adjusted based on a variety of factors, including but not limited to, location, education, skills, training, and experience.

In addition to an annual base salary, team members will receive equity awards and a generous benefits package consisting of medical, dental and vision plan, family planning benefits, health savings account, flexible spending account, transportation savings account, 401(k) retirement savings plan with company match, life, accident and disability coverage, business travel accident insurance, employee assistance programs, disability insurance, and other well-being benefits.

About Tanium

Tanium is an American cybersecurity and systems management company. The company provides security and IT operations solutions for enterprises and government organizations. Tanium's platform provides real-time visibility and control over endpoints, including laptops, servers, virtual machines, containers, and cloud infrastructure. The company's products are used by organizations in a variety of industries, including finance, healthcare, retail, and government. Tanium was founded in 2007 by Orion Hindawi and his father David Hindawi. The company is headquartered in Santa Clara, California.
Learn more about Tanium
Size
1,500 employees
Industry
Founded
2007

Similar Jobs

More Jobs at Tanium

More Information Technology Jobs

Find similar Staff Identity and Access Management Engineer jobs: