Identity Security Engineer
Bessemer Trust - Woodbridge, NJ
Hiring: Identity Security Engineer Company: Bessemer Trust Location: Woodbridge, NJ Job Posted Time: 2026-09-10 11:00:06 Employment Type: Remote Target Skills & Keywords : IAM, OAuth, OIDC, Okta, Project Management, REST, SAML, SOC 2, SaaS, ServiceNow, Stakeholder Management, User Experience, Wealth Management, Webhooks, Zero Trust About the job Experience: •5+ years of experience in identity and access management, cybersecurity engineering, security operations, infrastructure security, cloud security, or related technical roles. •In-depth knowledge of identity security concepts, including authentication, authorization, federation, MFA, access governance, privileged access, least privilege, lifecycle management, and segregation of duties. •Operational familiarity with Privileged Access Management concepts such as credential vaulting, privileged session management, RDP/SSH access, password rotation, service accounts, shared accounts, break-glass access, and just-in-time access. •Solid functional working knowledge of identity protocols, APIs, and integration patterns, including SAML, OIDC/OAuth, SCIM, LDAP, Kerberos, REST APIs, API authentication, JSON, webhooks, certificates, secrets, tokens, and integration troubleshooting. •Demonstrated capacity to review identity configurations or access control changes performed by other teams, identify security or supportability concerns, and balance risk reduction with user experience and operational needs. Required Skills: •Design, review, and validate Conditional Access, sign-in, password, session, and MFA policies across platforms such as Okta, Microsoft Entra ID, or similar identity providers. •Support and troubleshoot privileged access management capabilities, including vaulting, credential rotation, privileged account onboarding, session brokering, RDP/SSH access patterns, just-in-time access, and privileged access reviews. •Partner with Infrastructure and Application teams to onboard applications into provisioning, SSO, MFA, and privileged access processes using approved identity patterns. •Develop and maintain identity integrations using standards and technologies such as SAML, OIDC/OAuth, SCIM, REST APIs, API authentication methods, webhooks, and automation workflows. •Review access models, entitlement structures, groups, roles, and permissions to identify excessive access, orphaned access, toxic combinations, and opportunities for simplification. •Interface directly with ServiceNow teams to support access request workflows, approval routing, fulfillment tasks, catalog items, and integration between ITSM processes and identity governance capabilities. •Provide technical oversight and escalation support for identity-related operational processes performed by Helpdesk, Infrastructure, and Application teams, including access fulfillment, application onboarding, MFA, provisioning, and privileged access. •Partner cross-functionally with Risk, Compliance, Audit, and business stakeholders to produce evidence, explain access control designs, remediate findings, and improve control effectiveness. Qualifications: •Support implementation, configuration, and ongoing maturity of Identity Governance and Administration capabilities, including access requests, approvals, birthright access, role-based access, access reviews, certification campaigns, separation of duties, provisioning, deprovisioning, and lifecycle automation. Compensation: •$135,000 - $155,000 / year •Flexible work environment (work from home / hybrid options) Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!