Senior Identity and Access Management Engineer

Wintrust Financial Corporation — United States · Posted ~20 hours ago

Senior

Skills

Identity and access management

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

An established financial services organization is seeking a senior identity and access management engineer to support its enterprise technology environment. The opportunity is part of a broad banking and financial services business with a relationship-focused culture and an established employee recognition record.

Highlights

Join an established financial institution with a relationship-focused culture, a broad range of financial services, and a workplace recognized for its employee experience.

Description

Wintrust provides community and commercial banking, specialty finance and wealth management services through its 16 bank charters and nine non-bank businesses. Wintrust delivers the sophisticated solutions of a large bank while staying true to the relationship-focused, personalized service of our community banking roots. We serve clients in all 50 states with more than 200 branch banking locations in Illinois, southwestern Florida, northwestern Indiana, west Michigan and southern Wisconsin and commercial banking offices in Chicago, Denver, Milwaukee, Grand Rapids, Mich., and in key branch banking locations throughout Illinois. Our people are the heart of our business and we are proud to rank consistently as a top place to work. Wintrust is a $66 billion financial institution based in Rosemont, Illinois, and listed on the NASDAQ Global Select Market under the symbol “WTFC.” Why join us? An award-winning culture! We are rated a Top Workplace by the Chicago Tribune (past 12 years) and Employee Recommended award by the Globe & Mail (past 6 years)Competitive pay and discretionary or incentive bonus eligibleComprehensive benefit package including medical, dental, vision, life, a 401k plan with a generous company match and tuition reimbursement to name a fewPromote from within culture Why join this team? This position has the opportunity to interface with and have a positive impact on multiple areas of Wintrust's businessWe hold ourselves accountable to high standards, share wins, operate ethically, and have fun Position Overview The Senior Identity Access Management Engineer is responsible for designing, implementing, and maintaining critical security systems within the Identity domain. This role serves as the subject matter expert (SME) focused on privileged access management and NHI. As the technical leader experienced in managing hybrid IAM environments, this role requires a strong understanding of IAM best practices, emerging technologies, and the evolving threat landscape. What You’ll Do Contribute to IAM roadmap and vision. Working with security architecture, champion zero trust implementation, least privilege, and Just-in-Time elevation.Expert understanding of Delinea/Thycotic products offerings on-prem and cloud. Deep understanding of account discovery, automated account management, custom scripts and hybrid environment operations/maintenance.Govern Non-Human Identity (NHI) – Lead the lifecycle management of NHI and emerging AI agents, identify and manage standing privilege and secure machine to machine (m2m) interactions across the hybrid environment.Cross-Functional liaison to IT – A thorough understanding of Active Directory, EntraID, authentication protocols (Kerberos/SAML/OIDC), Conditional Access and AD sync will be used to implement secure and scalable systems.Automation and Scripting – Using bash, python, or PowerShell etc., support programmatic credential rotation, API integrations and administrative tasks.Define IT Policy Standards and Security Governance related to privileged accounts Qualifications Bachelor’s degree or equivalent experience5-7 years of prior hands-on professional experienceProven experience in architecting, deploying, and managing an enterprise PAM environment with specialized knowledge related to Delinea Secret Server or EntraID PIMDemonstrated ability in removing standing privilege by leveraging just-in-time access or other dynamic elevation modelsHands-on experience with cloud migrations while managing complex hybrid Active Directory environments Benefits Medical Insurance Dental Vision Life insurance Accidental death and dismemberment Short-term and long-term Disability Insurance Parental Leave Employee Assistance Program (EAP) Traditional and Roth 401(k) with company match Flexible Spending Account (FSA) Employee Stock Purchase Plan at 5% discount Critical Illness Insurance Accident Insurance Transportation and Commuting Benefits Banking Benefits Pet Insurance Compensation The estimated salary range for this role is $135,000.00 - $165,000.00, along with eligibility to earn an annual bonus. Actual salaries may vary based on several factors, such as a candidate’s qualifications, skills and experience. #JB1 From our first day in business, Wintrust has been proud to serve a variety of unique communities and people from all walks of life. To build a company that reflects the communities we serve, we believe that fostering a unique and inclusive workplace where everyone feels valued and empowered to succeed will support our ongoing success. Wintrust Financial Corporation, including community banking and financial services subsidiaries, is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information, and other legally protected categories.