About this role

The IAM Senior Engineer is responsible for designing, implementing, and maintaining enterprise IAM solutions that ensure secure and seamless access to systems and data. This role involves leading technical initiatives, automating identity lifecycle processes, integrating applications, and enforcing security policies across the organization. The engineer collaborates with security, infrastructure, and application teams to ensure IAM aligns with business needs and zero‑trust security principles.

Responsibilities

1. IAM Architecture & Engineering

  • Design and implement IAM architectures, including:
    • Identity lifecycle management
    • Authentication and authorization models
    • Access governance and role-based access control (RBAC/ABAC)
    • Privileged access management (PAM)
  • Implement Zero-Trust aligned identity controls.
  • Develop system integrations using APIs, SSO, federation (SAML, OAuth, OIDC), and SCIM provisioning.

2. Identity Lifecycle & Automation

  • Automate joiner/mover/leaver (JML) workflows.
  • Build custom connectors, provisioning scripts, and automation pipelines using PowerShell, Windows Script
  • Optimize identity data flows between HR systems, directories, and applications.

3. Directory & Authentication Services

  • Manage enterprise identity directories (e.g., Active Directory, Entra ID, LDAP).
  • Implement MFA, passwordless authentication, and adaptive access policies.
  • Troubleshoot authentication issues across protocols: Kerberos, LDAP, SAML, OAuth 2.0, OIDC.

4. Access Governance & Compliance

  • Ensure adherence to access policies and regulatory requirements (ISO 27001, SOX, HIPAA, PCI, etc.).
  • Support access certifications/attestations.
  • Develop and maintain IAM standards, patterns, and playbooks.
  • Conduct periodic access reviews and risk analysis.

5. Privileged Access Management (PAM)

  • Administer PAM platforms (CyberArk, BeyondTrust, Delinea, etc.).
  • Implement vaulting, credential rotation, session monitoring, and just‑in‑time access.
  • Reduce standing privileges and legacy admin accounts.

6. Application Integration

  • Onboard applications for SSO and provisioning using SAML, OAuth, and SCIM
  • Work with developers and product teams to implement secure, modern identity patterns.

7. Incident Response & Troubleshooting

  • Investigate and resolve IAM‑related security incidents.
  • Support SOC with identity‑specific detection, alerts, and forensics.
  • Perform root-cause analysis for identity access failures.

Technical Skills

  • 6 to 8 years of experience in identity and access management (IAM) engineering.
  • Bachelor’s degree in computer science, information security, or a related field.
  • Strong expertise in:
    • IAM platform(s): Okta, Azure AD/Entra ID, Ping, ForgeRock, SailPoint, etc.
    • Directory services (Active Directory, LDAP)
    • SSO/Federation (SAML, OIDC, OAuth)
    • SCIM provisioning
  • Experience designing and implementing enterprise IAM architectures, including identity lifecycle management, authentication and authorization models, access governance, and privileged access management.
  • Experience automating joiner/mover/leaver (JML) workflows and identity lifecycle processes.
  • Ability to build custom connectors, provisioning scripts, and automation pipelines using PowerShell and Windows scripting.
  • Experience with privileged access technologies, including administering PAM platforms such as CyberArk, BeyondTrust, or Delinea for vaulting, credential rotation, session monitoring, and just-in-time access.
  • Familiarity with Zero Trust principles.
  • Understanding of cloud platforms: Azure, AWS, or GCP.
  • Experience implementing MFA, passwordless authentication, and conditional/adaptive access policies.
  • Experience troubleshooting authentication issues across Kerberos, LDAP, SAML, OAuth 2.0, and OIDC.
  • Experience supporting access governance processes such as access reviews and access certifications/attestations.
  • Experience working in environments aligned with ISO 27001; experience with SOX, HIPAA, or PCI is a plus.

Soft Skills

  • Strong problem-solving and analytical mindset.
  • Ability to communicate with both technical and non‑technical stakeholders.
  • Experience leading technical projects and delivering enterprise‑grade solutions.
  • Experience partnering with SOC, security, infrastructure, and application teams to deliver IAM integrations and resolve incidents.
  • Experience investigating and resolving IAM-related security incidents and performing root-cause analysis.
  • Eligibility to work in Saudi Arabia.

Frequently Asked Questions

Is the salary disclosed for the IAM Senior Engineer position at Inbox Business Technologies?
The salary for this IAM Senior Engineer role at Inbox Business Technologies is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the IAM Senior Engineer position at Inbox Business Technologies located?
This IAM Senior Engineer role at Inbox Business Technologies is based in Riyadh, Riyadh Province, Saudi Arabia. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the IAM Senior Engineer role at Inbox Business Technologies full-time or part-time?
This is listed as a Full time position. It is posted as a IAM Senior Engineer role at Inbox Business Technologies.
How do I apply for the IAM Senior Engineer position at Inbox Business Technologies?
Click the "Apply Now" button on this page. You will be redirected to Inbox Business Technologies's official application portal hosted on workable where you can submit your application directly.
When was the IAM Senior Engineer job at Inbox Business Technologies posted?
This IAM Senior Engineer position at Inbox Business Technologies was posted on Jul 29, 2026. Apply as soon as possible — early applications are often reviewed first.
IAM Senior Engineer
Inbox Business Technologies
Apply for this role ↗

You'll be redirected to Inbox Business Technologies's official application page on workable.