Zorky CRMZorky CRM
EN|RU
@termdocs

IAM: market

IAM Engineer (Identity & Access Management) — a security specialty focused on managing identities and access: SSO (Single Sign-On), MFA, provisioning / deprovisioning, privileged access, identity governance, authorization. «Identity is the new perimeter» — central principle of the Zero Trust era 2026. Role family: IAM Engineer (general — workforce identity + SSO + MFA operations), Senior IAM Engineer (multi-system identity architecture + automation + lifecycle management), Identity Architect (org-wide IAM strategy + Zero Trust identity design + protocol expertise), PAM Engineer (Privileged Access Management specialty — CyberArk / Delinea / HashiCorp Boundary deep), IGA Engineer (Identity Governance & Administration — SailPoint / Saviynt — access certification + compliance), CIAM Engineer (Customer IAM — consumer-facing auth — Auth0 / Cognito / modern developer-first platforms), Authorization Engineer (rising 2024+ — fine-grained authorization specialty — OPA / OpenFGA / Cedar / SpiceDB). Stack 2026: Workforce IdP (Identity Providers — employee SSO): Okta (industry leader — Workforce Identity Cloud), Microsoft Entra ID (former Azure AD — dominates Microsoft-shop), Ping Identity (enterprise), OneLogin, JumpCloud (SMB-focused), Keycloak (open-source — Red Hat — popular in RF), Authentik (open-source modern — rising 2024+), Zitadel (open-source modern). Russian workforce IdP: Avanpost (IDM + FAM — leader RF), Solar inRights (IGA), Indeed Identity, RT-IAM (Rostelecom), CryptoPro (certificate-based auth). PAM (Privileged Access Management): CyberArk (industry leader — Privileged Access Manager + Conjur secrets), BeyondTrust (Password Safe + Privileged Remote Access), Delinea (former Thycotic + Centrify merger — Secret Server), HashiCorp Vault + Boundary (modern infrastructure access), Teleport (modern — SSH / Kubernetes / database access — rising 2024+), StrongDM. Russian PAM: Solar SafeInspect, Indeed PAM, Avanpost PAM, SKDPU NT (IT Bastion). IGA (Identity Governance & Administration): SailPoint (industry leader — IdentityIQ + IdentityNow), Saviynt, Microsoft Entra ID Governance, Omada, One Identity. Russian: Solar inRights, Avanpost IDM. Protocols / standards mastery: SAML 2.0 (enterprise SSO standard), OAuth 2.0 / 2.1 (authorization framework), OIDC (OpenID Connect) (authentication layer on OAuth), SCIM (System for Cross-domain Identity Management — provisioning standard), FIDO2 / WebAuthn (passwordless standard), LDAP + Kerberos (legacy directory + auth). MFA / Passwordless: FIDO2 / WebAuthn / Passkeys, YubiKey (hardware tokens — phishing-resistant), Duo Security (Cisco), Okta Verify / Microsoft Authenticator, magic links + OTP (legacy). Secrets management (overlap): HashiCorp Vault + cloud-native (AWS Secrets Manager / GCP Secret Manager / Azure Key Vault). Zero Trust identity: Conditional Access (risk-based authentication), continuous verification, device trust, identity threat detection (ITDR — Identity Threat Detection & Response — rising 2024+). Certifications: Okta Certified (Professional / Administrator / Consultant / Developer), Microsoft Identity (SC-300 Identity and Access Administrator), SailPoint certifications, CyberArk certifications (Defender / Sentry / Guardian), CIDPRO (Certified Identity Professional — IDPro). Languages: Python primary (IAM automation + SCIM connectors + custom integrations), JavaScript / TypeScript (CIAM frontend integration), bash + PowerShell (AD administration). According to Zorky CRM, 8 active openings with explicit IAM focus (the real pool is wider — many IAM roles classified as general Security Engineer / Backend / DevOps), median not published. Top stack: cloud, python, aws, ci/cd, terraform. 38% — remote.

8
open jobs
—
median $/mo
—
observed supply
50%
remote

The IAM market currently has 8 open roles, 0 of them freshly observed. Median salary not published. Observed candidate pool — not published.

38% of IAM vacancies — remote or hybrid. IAM work primarily cloud-based (IdP consoles + SaaS + API integrations). Outsourcers — almost always remote. Russian banks + state companies — hybrid/office due to regulatory + identity-data sensitivity + security clearances (especially PAM — high-trust). International tech companies — full-remote standard. CIAM Engineers (Backend-leaning) — full-remote-friendly.

⚠ salary known for 0 of 8 jobs; remote share from 6 with a stated format; 0 counted as fresh observations; trend and hiring difficulty are not shown

Demand and observed supply

Open demand8
Observed supply— not published

⚠ candidates matching a vacancy are not counted yet: demand and the observed pool are shown

Demand geography

countryjobs
US2
TH1
ES1
IN1

Leader by IAM job count — Russia (0 positions). Russia — banks + Russian IAM vendors (Avanpost / Solar / Indeed Identity / RT-IAM / CryptoPro / IT Bastion) + EPAM Security Practice dominate. Poland — IAM-friendly EU hub. Germany — Berlin + Munich enterprise. Large international remote via Okta / Microsoft Entra / Ping Identity / SailPoint / CyberArk / BeyondTrust / WorkOS / Auth0 / Clerk / Stytch.

⚠ job counts only: salary by country is not published

Used together with

cloud 7python 6aws 5terraform 4azure 3grafana 2gcp 2google cloud 2cdk 1api gateway 1ansible 1prometheus 1

Learning roadmap: identity fundamentals (AAA + RBAC/ABAC/ReBAC) → protocols deep (SAML + OAuth + OIDC + SCIM) → Active Directory fundamentals → workforce IdP hands-on (Okta / Entra ID / Keycloak) → MFA/Passwordless → CIAM or PAM or IGA specialization → authorization (OPA / OpenFGA) → IAM automation (Python) → certifications (Okta Certified / Microsoft SC-300 / SailPoint / CyberArk / CIDPRO).

Demand by grade

gradejobs
senior4

Junior — typical entry Sysadmin (AD admin) / Security Middle / Backend Middle + IAM focus. Career flow: Sysadmin / Security / Backend Middle (2-3 years) + IAM focus → IAM Junior (1-2 years) → Middle (2-3 years) → Senior → either Identity Architect, or PAM specialist, or IGA specialist, or CIAM Engineer (Backend-leaning), or Authorization Engineer (OPA / OpenFGA — rising).

⚠ demand side only: the grade of the observed pool is unknown for most of it

Where Zorky sees this market

Observed across 5 sources; the largest accounts for 37.5% — this market does not rest on a single channel.

Recent openings

All jobs →

Latest open IAM Engineer jobs — most recent positions in the sample (narrow pool of explicit IAM roles — real market wider due to overlap with Security / Backend / DevOps). Full list — in our CRM or via the «see all» link below. For a broader view check the security-engineer + backend pages.

Adjacent markets

SecuritySecurity EngineerAppSecDevSecOpsCloud SecurityPentest / Red TeamSOC AnalystNetwork Security

IAM Engineer overlaps with Security Engineer general (IAM is one security domain — 40% overlap), Backend Engineer (CIAM auth implementation — 50% overlap in consumer context), DevOps (machine identity + secrets + service-to-service auth — 30%), Cloud Security (cloud IAM — IAM Access Analyzer / privilege management), Identity Architect (career evolution). Comparison with security-engineer/appsec/cloud-security/pentest/soc/network-security — in the SiblingSubnichesChart above.

⚠ adjacent markets for comparison are not defined yet

How this is measured
Vacancy
an open job that cleared the quality gate and lists at least two technologies
Observed candidate
a candidate whose stack contains this technology; an aggregate — not a single record leaves the perimeter
Matchable candidate
not counted yet
Window
jobs open at the moment the snapshot was built

About the data

  • Some breakdowns are hidden: their data coverage is not yet sufficient.
  • Statistics are shown only where the sample clears a quality gate.
  • A missing block does not mean a value of zero.

Breakdowns currently hidden: 10.

Data as of 2026-09-27

Direction: Security

Related specializations

AppSecCloud SecurityNetwork SecurityPentest / Red TeamSecurity EngineerSOC Analyst

Frequently asked questions

The most common questions about IAM Engineer: pay (stable premium — «identity is the new perimeter»), IAM Engineer vs Identity Architect vs Security Engineer vs Backend Engineer (4-way + workforce vs CIAM split), IAM platforms 2026 decision tree (Okta vs Entra ID vs Ping vs Keycloak vs Auth0 vs WorkOS — 14 options), PAM Engineer / IGA Engineer / CIAM / Authorization Engineer specializations, remote, how to become one (4-8 months from Sysadmin AD admin / Security / Backend Middle), Senior skills (protocols mastery + workforce IdP + PAM/IGA + authorization OPA/OpenFGA + IAM automation). Answers recompute automatically.

What stack is most often required from IAM Engineer?

Top 5: cloud, python, aws, ci/cd, terraform. Workforce IdP mastery: one of Okta (industry leader — Workforce Identity Cloud — premium knowledge) / Microsoft Entra ID (former Azure AD — dominates Microsoft-shop) / Ping Identity (enterprise) / OneLogin / JumpCloud / Keycloak (open-source Red Hat — popular RF) / Authentik (open-source modern rising) / Zitadel. Russian: Avanpost (leader RF) / Solar inRights / Indeed Identity / RT-IAM / CryptoPro. PAM (Privileged Access Management): CyberArk (leader — PAM + Conjur secrets) / BeyondTrust / Delinea (Thycotic + Centrify merger) / HashiCorp Vault + Boundary / Teleport (modern infrastructure access — rising 2024+) / StrongDM. Russian: Solar SafeInspect / Indeed PAM / Avanpost PAM / SKDPU NT (IT Bastion). IGA (Identity Governance & Administration): SailPoint (leader — IdentityIQ + IdentityNow) / Saviynt / Microsoft Entra ID Governance / Omada / One Identity. Russian: Solar inRights / Avanpost IDM. Protocols / standards mastery — must: SAML 2.0 (enterprise SSO), OAuth 2.0 / 2.1 (authorization framework — grant types, PKCE, token rotation), OIDC (OpenID Connect — authentication layer), SCIM (provisioning standard — joiner-mover-leaver automation), FIDO2 / WebAuthn (passwordless), LDAP + Kerberos (legacy directory + auth). MFA / Passwordless: FIDO2 / WebAuthn / Passkeys, YubiKey (hardware tokens), Duo Security (Cisco), Okta Verify / Microsoft Authenticator, magic links + OTP (legacy). Zero Trust identity: Conditional Access policies (risk-based authentication), continuous verification, device trust, ITDR (Identity Threat Detection & Response — rising 2024+). Secrets management (overlap): HashiCorp Vault + cloud-native. Languages: Python primary (IAM automation + SCIM connectors + custom integrations) + JavaScript / TypeScript (CIAM frontend integration) + bash + PowerShell (AD administration).

IAM Engineer vs Identity Architect vs Security Engineer vs Backend Engineer — what's the difference?

IAM Engineer (this page) — focus on identity & access management implementation: SSO + MFA + provisioning + privileged access + governance. Specialty within security. Identity Architect — Senior IAM with org-wide strategy focus: Zero Trust identity architecture design + protocol expertise + technology selection + compliance leadership. Less programming, more strategy. Career evolution from Senior IAM Engineer. Security Engineer (general) — broad coverage of all security domains (SIEM + EDR + network + IAM — but IAM is just one part). See Security Engineer (general). Backend Engineer (auth-focused) — implements authentication / authorization in product code (OAuth flows + session management + JWT handling + RBAC implementation). Not an IAM specialist, but overlap in CIAM context. Pay varies — backend tier. Reality 2026 (overlap heatmap): IAM ↔ Security Engineer: 40% (IAM is one security domain). IAM ↔ Backend (auth): 50% in CIAM context (consumer-facing auth — Backend Engineers often implement, IAM Engineers design). IAM ↔ DevOps: 30% (machine identity + secrets management + service-to-service auth). Workforce IAM vs CIAM split: Workforce IAM — employee identity (Okta / Entra ID — SSO for internal apps + lifecycle management) — closer to traditional IT / security. CIAM (Customer IAM) — consumer-facing auth (Auth0 / Cognito / Clerk — millions of users + scalability + UX) — closer to Backend engineering + product. These two IAM directions require different skill sets. Career pivots: Sysadmin (AD admin) → Workforce IAM Engineer — 4-8 months. Backend Engineer → CIAM Engineer — 3-6 months (auth knowledge translates). Security Engineer → IAM Engineer — 3-6 months. IAM Senior → Identity Architect — 2-4 years.

IAM platforms 2026 decision tree — Okta vs Entra ID vs Ping vs Keycloak vs Auth0 vs WorkOS?

Strengths: deep Microsoft ecosystem, Conditional Access, free tier with M365. Weaknesses: complex licensing tiers, weaker non-Microsoft app integration historically. 2) Okta (Workforce Identity Cloud) — best for multi-vendor environments + best-of-breed approach. Strengths: 7000+ pre-built app integrations (largest catalog), vendor-neutral, polished UX, strong lifecycle management. Weaknesses: premium pricing, 2022 breach reputational hit (recovered). Use case: non-Microsoft-centric orgs + want best integration coverage. 3) Ping Identity — enterprise-heavy, complex hybrid environments. Use case: large enterprises with on-prem + cloud hybrid + complex federation needs. 4) Keycloak (open-source — Red Hat) — best for self-hosted + zero-budget + technical teams. Strengths: free, full-featured (SAML + OIDC + identity brokering), customizable. Weaknesses: operational burden (you run it), steeper learning curve. Use case: budget-constrained + technical team + popular in RF context (self-hosted preference). 5) Authentik / Zitadel — open-source modern alternatives to Keycloak (better UX). Rising 2024+. 6) Russian workforce IdP (after import substitution): Avanpost (leader RF) / Solar inRights / Indeed Identity / RT-IAM — for RF-only organizations + state companies. CIAM (consumer-facing auth): 7) Auth0 (Okta-owned) — developer favorite, best DX (developer experience), extensive SDK / docs. Use case: startups → mid-market, fast time-to-market. Pricing scales aggressively at high MAU (Monthly Active Users). 8) Amazon Cognito — best for AWS-native applications. Cheap at scale. Weaknesses: clunky DX, limited customization. 9) WorkOS — B2B SSO-as-a-service — «enterprise readiness in one API» (SAML + SCIM + directory sync for B2B SaaS selling to enterprises). Rising fast 2024+ — best for B2B SaaS that needs to support enterprise customers' SSO. 10) Clerk — modern developer-friendly, React-first, beautiful pre-built UI components. Use case: modern web apps (Next.js / React), fast iteration. 11) Stytch — passwordless-first, modern API. 12) Firebase Authentication — best for mobile apps + Firebase ecosystem. 13) Ory (open-source — Kratos + Hydra + Keto) — best for self-hosted CIAM + full control. 14) SuperTokens — open-source CIAM alternative. Default 2026 recommendations: Microsoft-shop workforce → Entra ID. Multi-vendor workforce → Okta. Zero-budget self-hosted workforce → Keycloak (or Authentik / Zitadel for better UX). RF-only org → Avanpost / Solar. Consumer app CIAM → Auth0 (fast) or Clerk (modern React) or Cognito (AWS-native). B2B SaaS needing enterprise SSO → WorkOS. Self-hosted CIAM → Ory or SuperTokens. Authorization layer (separate from authentication): OPA (general policy) / OpenFGA or SpiceDB (relationship-based, Zanzibar-style) / Cedar (AWS) / Oso or Permit.io (embedded).

Can you work IAM Engineer remotely?

Yes, 38% of IAM Engineer vacancies — full-remote or hybrid. IAM work is primarily cloud-based (IdP consoles + SaaS platforms + API integrations). Outsourcers — almost always remote on US IAM projects. Russian banks — hybrid/office due to regulatory + identity-data sensitivity + security background-check. Russian IAM vendors (Avanpost / Solar / Indeed Identity / CryptoPro) — hybrid or remote after background-check. State companies — hybrid/office due to security clearances (especially for PAM work — privileged access — high-trust roles). Big Tech identity teams — hybrid standard. CIAM Engineers (consumer-facing — Backend-leaning) — full-remote friendly due to product-engineering nature. Relocant hubs: Poland (Security-friendly EU) / Germany / Canada / Serbia. English for international IAM remote — must (protocol specs — SAML / OAuth / OIDC RFCs + vendor docs Okta / Microsoft / SailPoint + community are English-language).

How is PAM Engineer different from a regular IAM Engineer?

IAM Engineer (general) — focus on workforce identity broadly: SSO + MFA + provisioning + access management for all users. PAM Engineer (Privileged Access Management specialty) — focus specifically on privileged accounts (administrator / root / service accounts — highest-risk identities). Day-to-day: 1) PAM platform deployment (CyberArk / BeyondTrust / Delinea / HashiCorp Boundary / Teleport), 2) Privileged credential vaulting (secrets rotation + checkout / checkin workflows), 3) Session recording + monitoring (record admin sessions for audit + forensics), 4) Just-In-Time (JIT) privileged access (grant admin rights temporarily, auto-revoke), 5) Privilege escalation control + least-privilege enforcement, 6) Service account / machine identity management (non-human identities — often 10× more than human accounts), 7) Break-glass access procedures (emergency access). Why a specialty: privileged accounts — primary target of ransomware + APT attacks (compromise admin → game over). Regulatory mandate (PCI-DSS / SOX / 187-FZ require PAM controls). Pay: PAM Engineer — premium over general IAM +10-20% due to rare-skill + high-trust nature. IGA Engineer (Identity Governance & Administration specialty) — another specialty: focus on access governance — access certification campaigns (periodic review «does this person still need this access?»), Segregation of Duties (SoD) policy enforcement, access request workflows, compliance reporting (SOC 2 / ISO 27001 / SOX access audits). Tools: SailPoint / Saviynt. CIAM Engineer — consumer-facing auth (millions of users — scalability + UX + Backend-engineering-leaning). See decision tree above. Authorization Engineer (rising 2024+) — fine-grained authorization specialty (OPA / OpenFGA / Cedar / SpiceDB) — «who can do what on which resource» at scale. Career choice: general IAM if breadth + workforce identity, PAM if high-trust + privileged-account-deep + security-critical, IGA if governance + compliance + audit-focused, CIAM if consumer-scale + product engineering, Authorization Engineer if fine-grained authz + modern policy engines.

How to start in IAM in 2026?

Roadmap: 1) Identity fundamentals — authentication vs authorization vs accounting (AAA), identity lifecycle (joiner-mover-leaver), least-privilege principle, RBAC vs ABAC vs ReBAC (Role / Attribute / Relationship-Based Access Control). 2) Protocols deep — must: SAML 2.0 (assertions + bindings + SP-initiated vs IdP-initiated flows), OAuth 2.0 / 2.1 (grant types — authorization code + PKCE + client credentials; token types; common pitfalls), OIDC (OpenID Connect) (ID tokens + UserInfo + discovery), SCIM (provisioning standard). Book: «Solving Identity Management in Modern Applications» Yvonne Wilson / Abhishek Hingnikar (canonical — OAuth/OIDC for developers). 3) Active Directory fundamentals — AD structure (forests / domains / OUs), Group Policy, Kerberos authentication, LDAP. Book: «Active Directory» Brian Desmond (O'Reilly). 4) Workforce IdP hands-on — pick one: Okta (Okta Developer free tier — best for learning + Okta Certified Professional cert) or Microsoft Entra ID (Azure free tier + SC-300 cert) or Keycloak (self-host free — learn protocols deeply). Set up SSO for test apps. 5) MFA / Passwordless — understand FIDO2 / WebAuthn / Passkeys (passwordless future), set up YubiKey, configure Conditional Access policies. 6) CIAM hands-on (if consumer-facing track) — Auth0 free tier or Clerk or Keycloak. Implement login flows in test app (React / Next.js). 7) PAM hands-on (if privileged-access track) — HashiCorp Vault (free self-host) + Boundary, or Teleport (free tier). Understand secrets vaulting + session recording + JIT access. 8) IGA basics (if governance track) — SailPoint training (SailPoint University) — access certification + SoD concepts. 9) Authorization (rising 2024+) — OPA (Open Policy Agent — Rego language) + OpenFGA (relationship-based — read Google Zanzibar paper) + Cedar (AWS). Build fine-grained authz demo. 10) IAM automation — Python for SCIM connectors + custom integrations + IdP API automation (Okta API / Microsoft Graph API). 11) Certifications path: Okta Certified (Professional → Administrator → Consultant / Developer) or Microsoft SC-300 (Identity and Access Administrator) — foundational. Advanced: SailPoint certifications / CyberArk certifications (Defender → Sentry → Guardian) / CIDPRO (Certified Identity Professional — IDPro — vendor-neutral). 12) Pet project portfolio: a) full SSO setup (Keycloak / Okta) with multiple apps + SAML + OIDC + SCIM provisioning; b) CIAM demo app with passwordless (WebAuthn / Passkeys); c) fine-grained authorization demo (OpenFGA / OPA). Document on GitHub. RF courses: BI.ZONE Cybersecurity Academy, Otus «IAM» / Security courses, Avanpost training (Russian IAM), Solar training (inRights IGA / SafeInspect PAM). International (eng): Okta Learning (free — best for Okta track), Microsoft Learn SC-300 (free), IDPro Body of Knowledge (vendor-neutral — best foundational resource, free), Auth0 docs + blog (excellent CIAM learning), «OAuth 2 in Action» Justin Richer / Antonio Sanso (Manning — protocols deep). Books-must: «Solving Identity Management in Modern Applications» Wilson / Hingnikar, «OAuth 2 in Action» Richer / Sanso, IDPro Body of Knowledge (online). Conferences: Identiverse (largest identity conference), Gartner IAM Summit, European Identity & Cloud Conference (EIC). Sysadmin (AD admin) / Security Middle / Backend Middle + IAM focus → IAM Junior — 4-8 months.

How many IAM Engineer vacancies are there in CIS and Europe?

8 active open IAM Engineer vacancies with explicit IAM focus in our sample. The real market is significantly wider — many IAM roles classified as general Security Engineer / Backend Engineer (CIAM auth implementation) / DevOps (machine identity + secrets) / IT Administrator (AD administration). True IAM-focused dev jobs in CIS + Europe estimated 150–600 active positions at any moment 2026. Geography: Russia / Poland / remote. The real market is wider due to the international remote segment (Okta / Microsoft Entra / Ping / SailPoint / CyberArk / WorkOS / Auth0 / Clerk / Stytch — full-remote-friendly). Senior IAM Engineer closing time — 6-12 weeks (longer than general Security due to rare-skill — protocols depth + platform expertise + governance knowledge combination).

What skills does a Senior IAM Engineer need?

Senior IAM Engineer owns the full identity & access management lifecycle + technical leadership. Protocols mastery deep: SAML 2.0 (assertions + bindings + SP/IdP-initiated flows + signing / encryption), OAuth 2.0 / 2.1 (all grant types + PKCE + token rotation + DPoP + common vulnerabilities — token leakage / CSRF / redirect manipulation), OIDC (ID tokens + claims + discovery + session management + back-channel logout), SCIM (provisioning automation — joiner-mover-leaver), FIDO2 / WebAuthn (passwordless implementation), Kerberos + LDAP (legacy directory). Workforce IdP mastery: one of Okta / Microsoft Entra ID / Ping deeply — SSO architecture, lifecycle management automation, Conditional Access / risk-based policies, app integration (7000+ catalog for Okta), custom SAML / OIDC app onboarding, IdP federation (multi-IdP scenarios). Directory services mastery: Active Directory deep (forest / domain / OU architecture + Group Policy + replication + AD security — Kerberoasting / DCSync awareness), Entra ID hybrid (AD Connect / Cloud Sync). PAM mastery (if PAM track): CyberArk / BeyondTrust / Delinea / HashiCorp Boundary / Teleport — privileged credential vaulting, session recording, JIT access, service account management, break-glass procedures. IGA mastery (if governance track): SailPoint / Saviynt — access certification campaigns, Segregation of Duties (SoD) policy, access request workflows, role mining, compliance reporting. CIAM mastery (if consumer track): Auth0 / Cognito / Clerk — scalable consumer auth (millions of MAU), passwordless UX, social login, progressive profiling, account security (credential stuffing protection + bot detection). Authorization mastery (rising 2024+): OPA (Rego policy language), OpenFGA / SpiceDB (relationship-based — Google Zanzibar model), Cedar (AWS), fine-grained authz design at scale. Zero Trust identity: Conditional Access architecture, continuous verification, device trust, ITDR (Identity Threat Detection & Response) integration. IAM automation: Python deep (SCIM connectors + IdP API automation — Okta API / Microsoft Graph API + custom integrations), Terraform for IaC IAM (Okta Terraform provider / Entra Terraform). Identity security: identity attack awareness (phishing / MFA bombing / token theft / OAuth consent phishing / Golden SAML), passwordless migration strategy, MFA hardening. System design for IAM: design enterprise SSO architecture on a whiteboard, design CIAM for millions of users, design Zero Trust identity architecture, design privileged access workflows. Compliance frameworks: SOC 2 + ISO 27001 + SOX (access controls) + PCI-DSS + 152-FZ + 187-FZ — access certification + audit support. Soft: ADRs writing for IAM decisions, technical writing (IAM architecture docs), cross-team collaboration (Security / IT / Backend / DevOps / HR teams — IAM touches everyone), executive communication (identity strategy to CISO / CIO), mentoring Middle IAM Engineers. English for Senior+ MUST — protocols specs (SAML / OAuth / OIDC RFCs) + vendor docs (Okta / Microsoft / SailPoint / CyberArk) + community (IDPro / Identiverse) are English-language. Certifications: Okta Certified Consultant / Developer, Microsoft SC-300, SailPoint / CyberArk certifications, CIDPRO (vendor-neutral). Optional bonus: open-source contributions to IAM tools (Keycloak / Ory / OpenFGA / Authentik), conference talks (Identiverse / EIC), authorization specialty depth (OpenFGA / SpiceDB — rising rare skill) — sharply increase market value for frontier-IAM companies (Okta / WorkOS / Authzed) hiring.

Leave a request

Describe the task and leave a contact — the request goes to our CRM and we reply at the contact you provide.