CAF America logo
CAF America
Posted 18 days agoVerified live 1d ago

Identity and Access Management Technical Lead

Brief overview

Remote
UndergradOr in progress
2+ yrsMinimum
Identity and Access ManagementIdentity GovernanceRole-Based Access Control (RBAC)Identity Lifecycle ManagementSingle Sign-On (SSO)Multi-Factor Authentication (MFA)Identity FederationMicrosoft Entra IDOktaMicrosoft 365SAML, OAuth, and OpenID Connect

About the company

CAF America logo
CAF Americacafamerica.org

CAF America is a global grantmaking organization assisting corporations, foundations, and individuals.

Job description

Summary

CAF America is a leader in enabling cross-border charitable giving through a global network of vetted charitable organizations. The Identity and Access Management Technical Lead will lead identity governance, secure provisioning, authentication, access audits, compliance, integrations, automation, and incident response across enterprise systems and SaaS platforms.

Responsibilities

  • Define identity governance policies, access control standards, and compliance requirements to ensure security, regulatory compliance, and risk reduction across all enterprise systems
  • Define and govern authentication strategy, including SSO, MFA, and identity federation configurations, ensuring security and compliance. Provide standards and oversight for identity provider configurations
  • Define policies and standards for provisioning and deprovisioning user and group accounts across M365, Azure Entra ID, CRM, and integrated SaaS platforms, and monitor adherence to these standards
  • Maintain RBAC structures and enforce least privilege principles
  • Define and implement access control policies and standards
  • Own and Conduct periodic access audits and ensure compliance with SOC2, PCI, GDPR. Partner and collaborate with Cybersecurity and other internal teams (Risk & Compliance, and Privacy) to conduct these audits
  • Manage SSO, MFA, and identity federation configurations
  • Optimize authentication flows for security and usability
  • Partner with Cyber Security and Risk teams to meet regulatory requirements
  • Prepare audit reports and support compliance reviews
  • Integrate identity solutions with enterprise applications and SaaS platforms
  • Enable and consult on automation initiatives for onboarding/offboarding workflows
  • Act as identity SME during security incidents
  • Implement corrective actions and strengthen identity posture
  • Collaborate with Cyber Security and Enterprise Apps personnel on security posture and access strategies
  • Coordinate with MSPs and SaaS vendors for identity integrations and compliance validation
  • Own and lead audit preparation and reporting for identity and access controls across all enterprise systems
  • Maintain detailed IAM documentation and evidence logs for SOC2, PCI, GDPR compliance. Coordinate with Risk & Compliance, Privacy, and Cyber Security team members to ensure timely completion of annual and periodic access reviews. Deliver audit reports to leadership and regulatory bodies as required
  • Support end-user training on MFA, SSO, and secure access practices
  • Provide technical input during security incidents and remediation efforts
  • Research emerging IAM technologies and recommend improvements for automation and efficiency

Skills

  • Strong knowledge of IAM principles, RBAC, and identity governance frameworks
  • Experience defining IAM policies and governance standards
  • Bachelor's degree (B.A./B.S.) in IT or related field; or equivalent combination of education and experience
  • 2–4 years of experience in IAM or IT security roles, with hands-on expertise in identity lifecycle management, authentication protocols, and compliance support
  • Must be eligible to work legally in the United States
  • Experience with Azure Entra ID, Okta, M365, and SaaS integrations
  • Experience with compliance frameworks (SOC2, PCI, GDPR) and audit related audits
  • Familiarity with authentication protocols (SAML, OAuth, OpenID Connect)
  • Hands-on expertise in identity and access management, including federation, SSO (SAML/OIDC), MFA
  • Strong familiarity with enterprise CRM and productivity platforms, including user provisioning and password management
  • Hands-on experience with identity and access management tools such as Microsoft Entra ID, including configuring SSO and MFA for third-party SaaS applications
  • Proficiency in administering collaboration and file-sharing platforms (e.g., Dropbox, Google Shared Drives) with a focus on secure access
  • Advanced knowledge of Microsoft 365 and Azure Entra ID environments
  • Experience using compliance and audit tools or processes for SOC2, PCI, GDPR evidence collection
  • Experience managing internal ticketing systems and support workflows, including triage and resolution of identity-related issues
  • Exposure to cloud and web hosting environments (e.g., AWS) and IAM systems, with the ability to assist in maintenance and monitoring tasks
  • Knowledge of security frameworks and IAM governance best practices. (NIST/ISO)
  • Work with multiple entities (internal teams, vendors, users, etc.) simultaneously while resolving complex system issues
  • Maintain resilience, positive attitude, and supportive disposition while resolving difficult technical problems with complex decentralized SaaS and Cloud solutions
  • Return and report to supervisor and peers, and demonstrate accountability for tasks
  • Excellent documentation and communication skills, with experience maintaining IT knowledge bases and delivering user training
  • This position is U.S.-based.  All duties must be carried out from within the United States
  • Exposure to automation tools and scripting (PowerShell, MS Power Automate) preferred

Qualifications

Must Haves

  • Strong knowledge of IAM principles, RBAC, and identity governance frameworks
  • Experience defining IAM policies and governance standards
  • Bachelor's degree (B.A./B.S.) in IT or related field; or equivalent combination of education and experience
  • 2–4 years of experience in IAM or IT security roles, with hands-on expertise in identity lifecycle management, authentication protocols, and compliance support
  • Must be eligible to work legally in the United States
  • Experience with Azure Entra ID, Okta, M365, and SaaS integrations
  • Experience with compliance frameworks (SOC2, PCI, GDPR) and audit related audits
  • Familiarity with authentication protocols (SAML, OAuth, OpenID Connect)
  • Hands-on expertise in identity and access management, including federation, SSO (SAML/OIDC), MFA
  • Strong familiarity with enterprise CRM and productivity platforms, including user provisioning and password management
  • Hands-on experience with identity and access management tools such as Microsoft Entra ID, including configuring SSO and MFA for third-party SaaS applications
  • Proficiency in administering collaboration and file-sharing platforms (e.g., Dropbox, Google Shared Drives) with a focus on secure access
  • Advanced knowledge of Microsoft 365 and Azure Entra ID environments
  • Experience using compliance and audit tools or processes for SOC2, PCI, GDPR evidence collection
  • Experience managing internal ticketing systems and support workflows, including triage and resolution of identity-related issues
  • Exposure to cloud and web hosting environments (e.g., AWS) and IAM systems, with the ability to assist in maintenance and monitoring tasks
  • Knowledge of security frameworks and IAM governance best practices. (NIST/ISO)
  • Work with multiple entities (internal teams, vendors, users, etc.) simultaneously while resolving complex system issues
  • Maintain resilience, positive attitude, and supportive disposition while resolving difficult technical problems with complex decentralized SaaS and Cloud solutions
  • Return and report to supervisor and peers, and demonstrate accountability for tasks
  • Excellent documentation and communication skills, with experience maintaining IT knowledge bases and delivering user training
  • This position is U.S.-based.  All duties must be carried out from within the United States

Nice to Haves

  • Exposure to automation tools and scripting (PowerShell, MS Power Automate) preferred

Benefits

  • 100% paid premium for Employee Medical, Dental and Vision insurance
  • Health Savings Account (HSA)
  • Life Insurance
  • Accidental Death and Dismemberment Insurance
  • Short- and Long-Term Disability
  • 401k program with up to 15% match
  • Lifestyle Savings Account
  • Employee Assistance Program (EAP)
  • Robust Time Off programs

More jobs like this