Senior Engineer, Identity and Access Management

Icemarkets — United States · Posted ~3 hours ago

Senior Full-time Hybrid Visa Sponsored

Skills

Identity and Access Management Security IAM Systems IAM Security Standards Active Directory LDAP SAML

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Join a leading global market infrastructure company as a Senior Engineer in Identity and Access Management. In this critical role, you will design, implement, and maintain comprehensive security systems that protect enterprise IT platforms and applications. You will develop and enforces IAM policies, manage user identities and access controls across diverse systems. This hybrid position offers the opportunity to work with world-class security technologies in a collaborative environment. Relocation assistance is available for exceptional candidates from outside the organization's primary location. You will contribute to the security and integrity of critical global financial and trading infrastructures in a team-based setting.

Highlights

Work with a leading global market infrastructure company on cutting-edge security solutions. Lead IAM initiatives in a collaborative environment with relocation support available for exceptional candidates.

Description

Job Purpose Intercontinental Exchange, Inc. (ICE) is a leading operator of global exchanges, clearing houses, data, and listings services. We connect businesses around the world to unique opportunities in markets that drive the global economy. We are a diverse and inclusive company that values innovation, collaboration, and excellence. ICE team members work across departments and traditional boundaries to innovate and respond to industry demand. A successful candidate will be able to multitask in a dynamic team-based environment demonstrating strong problem-solving and decision-making abilities and the highest degree of professionalism. As an Identity and Access Management (IAM) professional, you will be responsible for ensuring the security and integrity of our IT systems and applications. You will design, implement, and maintain policies and systems that control user identities, credentials, roles, and permissions across various IT platforms and applications. You will also monitor and audit user activities, troubleshoot issues, and comply with IT standards and regulations. To succeed in this role, you will need strong technical skills, analytical thinking, problem-solving abilities, and knowledge of IT security best practices. Responsibilities Application & Infrastructure MaintenanceAdminister, maintain, and support ForgeRock/Ping OpenIDM and OpenDS directory services in production and non-production environmentsMonitor system health, performance, and availability; perform proactive tuning and capacity planningManage directory replication, schema extensions, indexing, and access control policiesPerform upgrades, patching, and configuration changes in accordance with change management processesTroubleshoot and resolve complex issues related to directory services, authentication, and identity workflowsMaintain high availability and disaster recovery configurations for IAM infrastructureLinux AdministrationManage and maintain Linux-based servers hosting IAM applications and directory servicesPerform OS-level troubleshooting, log analysis, and performance diagnosticsImplement and maintain system hardening standards and security configurationsCoordinate with infrastructure teams on server provisioning, networking, and storageScripting & AutomationDevelop and maintain scripts to automate routine operational tasks, monitoring, and reporting (Bash, Python, or similar)Automate provisioning, de-provisioning, and reconciliation workflowsBuild tooling to support bulk directory operations, data migrations, and schema managementMaintain and improve CI/CD pipelines related to IAM configuration and deploymentsAI Adoption & EnablementStay current with emerging AI tools and capabilities relevant to IAM operations, security, and automationIdentify and champion opportunities to incorporate AI-assisted tooling into day-to-day workflows, such as anomaly detection, access pattern analysis, and automated remediationUse AI coding and scripting assistants responsibly to accelerate development of automation and operational toolingContribute to team best practices and guardrails around responsible AI usage in an identity and security contextPartner with security, application, and infrastructure teams to integrate identity services with enterprise applicationsProduce and maintain technical documentation including runbooks, architecture diagrams, and standard operating proceduresParticipate in on-call rotation and provide escalation support for P1/P2 incidentsMentor junior team members and contribute to team knowledge sharingWorks independently on many IT projects as a project team member, more frequently as a project leader.Often provides strategic direction, guidance, and integration of services.Communicate verbally and in writing to technical and non-technical audiences of various levels both internally and externallyDevelop partnership-oriented relationships with business executives and functional leaders, especially as it relates to operations and technologyMultitask in a fast-paced environment with a focus on timeliness, documentation, and communications with peers and business usersInvolved in the evaluation of products and/or procedures to enhance productivity and effectiveness Knowledge And Experience Bachelor’s degree in Computer Science, Information Systems, or an equivalent combination of education, training, or work experience5+ years of experience in Identity & Access Management or directory services engineeringHands-on experience with ForgeRock OpenIDM and/or OpenDS (or Ping Identity directory products)Strong Linux administration skills (RHEL preferred)Proficiency in scripting languages such as Bash and/or Python for automation and operational toolingSolid understanding of LDAP concepts: schema, replication, ACIs, indexing, and directory architectureExperience supporting enterprise IAM in a production environmentExperience designing, implementing, or supporting multi-factor authentication (MFA) solutions, including hardware tokens, YubiKeys, authenticator applications, push notifications, and/or certificate-based authentication.Familiarity with authentication protocols: LDAP, Kerberos, SAML, OAuth2/OIDCStrong troubleshooting and root cause analysis skillsRequires extensive knowledge of relevant IT system issues, techniques, and implications across all existing server platforms.Must have extensive knowledge in networking, databases, systems, and/or Web operations. Preferred Knowledge And Experience Knowledge of ICE business environment and the ability to evaluate implications of changes to IT systems Experience with additional ForgeRock/Ping Identity products (AM, PingFederate, PingDirectory)Familiarity with HashiCorp Vault or other secrets management solutionsExperience with containerization (Docker/Kubernetes) in the context of IAM workloadsKnowledge of SCIM provisioning standardsExposure to cloud environments (AWS, Azure, or GCP) and hybrid identity architecturesForgeRock Certified Identity Professional or equivalent certificationKnowledge of relevant legal and regulatory requirements Knowledge of common Identity Access Management frameworks Experience working with a diverse range of data sources/streams and managing these effectively Excellent analytical, decision-making, and problem-solving skills Knowledge of multiple operating systems and related utilities and hardware Knowledge of storage management, TCP/IP, and network monitoring and tools Strong background in operations, processes, solutions, and technologies Strong understanding of policy, compliance, and best practice Identity Access Management principles Working knowledge of Linux, Windows, and Network Operating Systems Knowledge of infrastructure, key processes, and technology-oriented risk issues, specifically around Identity Access Management and privacy Results oriented, business focused, and successful at interfacing across multiple organizational units Professional certification such as CISSP, CISM, etc. Intercontinental Exchange, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to legally protected characteristics.