Tanium
Staff Identity and Access Management Engineer
About this role
The Basics We’re looking for a Staff IAM engineer to design, implement, and manage identity and access management (IAM) and identity governance (IGA) solutions across Tanium’s corporate infrastructure. You’ll evaluate new IAM/IGA technologies, partner with cross-functional teams on strategy, and keep our identity ecosystem secure, compliant, and efficient. This position follows the Company’s hybrid schedule which currently requires employees to work in the office at one of the following locations a minimum of three days per week: Addison, TX; Bellevue, WA; Durham, NC; Emeryville, CA; or Reston, VA. What you’ll do Design and manage IAM/IGA solutions across corporate infrastructure, including SSO, MFA, and PAM Build and maintain identity automation - onboarding, off-boarding, entitlements, and approval workflows - and troubleshoot issues surfaced by testing, user, or peer feedback Own the identity lifecycle: monitor, document, and continuously improve it Partner with GRC to develop and maintain IAM/IGA policies and standards that satisfy regulatory requirements (ISO 27001, FedRAMP, GDPR, HIPAA, etc.) Assess IAM systems regularly for security gaps and insure ongoing patch and policy compliance Lead technical delivery on IAM/IGA projects - upgrades, migrations, integrations - and monitor system performance to identify optimizations Respond to and resolve IAM-related incidents Mentor engineers across IT and Security and track industry trends to keep our IAM/IGA approach current Maintain system design documentation We’re looking for someone with Education Bachelor’s Degree in Computer Science, IT or other relevant degree or equivalent work experience Experience 8–10 years in identity and access management, including IGA integrations with HRIS systems (Workday, SuccessFactors, or similar) Experience implementing, configuring, and managing an IGA product like Lumos, SailPoint, Saviynt, etc Hands-on expertise with Entra ID and Active Directory (preferably in a hybrid environment) with respect to identity and access Solid grasp of onboarding/off-boarding standards and lifecycle workflows Scripting proficiency (PowerShell) Working knowledge of security/compliance frameworks