Engineer, IAM & Endpoint Platforms
Washington, USA
USD 160k-180k / year
Position Summary
Responsibilities
- Serve as a subject matter expert across IGA, PAM, SSO, MFA, and endpoint security; design, automate, and maintain IAM solutions across SailPoint IdentityNow, Okta, Active Directory, Entra ID, and Workday that govern access for internal and external users
- Administer Okta (SSO, MFA, adaptive authentication, Lifecycle Management, Workflows) and enforce Zero Trust controls across IAM and endpoints, including device-compliance-based Conditional Access in Entra ID
- Design and maintain Joiner-Mover-Leaver (JML) workflows and Role-Based Access Control (RBAC) frameworks in SailPoint IdentityNow, including role mining, entitlement mapping, provisioning, access certifications, and automated deprovisioning, to enforce least-privilege access and meet regulatory requirements
- Run day-to-day IAM operations: SSO onboarding, MFA administration, access reviews, entitlement cleanup, HR-driven lifecycle events, and platform upgrades
- Contribute to modernization of identity, endpoint, and access management platforms, driving initiatives that deliver measurable security, efficiency, and compliance value
- Support identity and access workstreams related to mergers, acquisitions, and divestitures
- Apply AI to streamline IAM and endpoint operations within financial-services compliance guardrails, and govern identities for agentic AI and non-human identities (NHIs), including OAuth grant reviews, least-privilege scoping, and extending JML to machine identities
- Operations & Support
- Serve as an escalation point for executive-level technical issues; interface effectively with senior stakeholders and their administrative teams to diagnose and resolve complex problems
- Own technical solutions end-to-end, from design and implementation through steady-state operations, and build automation (PowerShell, Python) to streamline configuration management and reduce manual effort
- Resolve complex technical incidents, perform root-cause analysis on high-impact disruptions, meet SLOs, and serve as escalation point for the Service Desk on IAM and endpoint issues; maintain runbooks and technical documentation to support operational continuity
- Support IAM and endpoint compliance programs (access recertifications, privileged-account audits, endpoint posture assessments) and partner with Information Security, Legal, and Compliance on SOX, NIST, and ISO 27001 obligations
- Cross-EPS Contribution
- Contribute to other Enterprise Productivity Solutions workstreams as needed, including Microsoft 365 administration, broader Microsoft platform initiatives, virtual desktop solutions, and other end-user technology platforms, staying versatile across the EPS portfolio while keeping IAM and endpoints as primary focus
- Cross-EPS Contribution
- Contribute to other Enterprise Productivity Solutions workstreams as needed, including Microsoft 365 administration, broader Microsoft platform initiatives, virtual desktop solutions, and other end-user technology platforms, staying versatile across the EPS portfolio while keeping IAM and endpoints as primary focus
Qualifications
- Bachelor's Degree, or equivalent years of relevant experience, required
- Degree in Information Technology, or similar engineering discipline, strongly preferred
- IAM-focused certifications preferred (e.g., SailPoint IdentityNow Engineer, Okta Certified Professional/Administrator, SC-300: Microsoft Identity and Access Administrator)
- Microsoft endpoint certifications preferred (e.g., MD-102: Microsoft 365 Endpoint Administrator, MS-102: Microsoft 365 Administrator Expert)
- Jamf certifications preferred (e.g., Jamf Certified Associate, Jamf Certified Tech, Jamf Certified Admin)
- 6+ years of overall relevant technical experience, required
- Experience in IT systems engineering with a focus on IAM, endpoint management, or related disciplines, preferred
- Expert-level IAM skills spanning IGA, PAM, SSO, MFA, and RBAC, including role lifecycle, entitlement reviews, segregation of duties (SoD), and access certifications in SailPoint IdentityNow
- Experience supporting access governance audits and regulatory reviews; able to produce audit-ready evidence for internal and external reviewers
- Experience developing automation scripts for IAM provisioning, endpoint configuration, and operational tasks
- Strong analytical and troubleshooting skills across complex, cross-platform issues, including network connectivity fundamentals
- Clear communicator with technical and executive audiences; committed to white-glove support for executive end users
- Proficient with project and service management tools (Jira, Confluence); able to manage and prioritize multiple concurrent initiatives
- Availability for on-call rotation and willingness to support planned and unplanned maintenance during evenings and weekends as needed
- Microsoft Platform Stack (Active Directory, GPO, DNS, DHCP, Azure, Microsoft 365 (Exchange, SharePoint, Teams, OneDrive, Power Automate); PowerShell modules including AAD, Exchange, MSOL)
- AI Coding & Automation (e.g., Cursor, Claude Code, Codex)
- Microsoft Intune & Endpoint Management (Windows/iOS enrollment, Autopilot, Co-management, Device Compliance Policies, Configuration Profiles, App Deployment, Conditional Access, Device Health Attestation, LAPS, Endpoint Security policies, Defender for Endpoint integration)
- Identity & Privileged Access Management (Okta, SailPoint IdentityNow, CyberArk Vault/CPM/PSM, SAML, OIDC, RBAC, JIT access)
- Zero Trust Architecture (Conditional Access, device compliance enforcement, Zscaler, identity-driven network segmentation, continuous verification)
- Compliance & Governance (SOX ITGCs, NIST 800-53, ISO 27001, CIS Benchmarks, access recertification, audit evidence collection, endpoint posture assessment)
- Jamf (macOS/iPadOS Management, App Packaging/Deployments)
- Virtual Desktop Platforms (Azure Virtual Desktop, Windows 365)
- Scripting (PowerShell, Python, Bash, Visual Basic, Batch)
- AI & Agentic Security (Microsoft Copilot, AI-assisted identity governance, agentic AI identity lifecycle management, machine identity governance, OAuth grant discovery, non-human identity (NHI) controls, prompt engineering for IT operations, etc.)
Company Information
The Carlyle Group (NASDAQ: CG) is a global investment firm with $475 billion of assets under management, across 678 investment vehicles as of March 31, 2026. Founded in 1987 in Washington, DC, Carlyle has grown into one of the world's largest and most successful investment firms, with more than 2,500 professionals operating in 28 offices in North America, Europe, the Middle East, Asia and Australia.
Carlyle’s purpose is to connect people, ideas, and capital to fuel growth for companies and performance for investors, which range from public and private pension funds to wealthy individuals and families to sovereign wealth funds, unions and corporations. Carlyle invests across three segments – Global Private Equity, Global Credit and Carlyle AlpInvest – and has deep expertise across industries, markets, and geographies.
At Carlyle, we believe that a wide spectrum of experiences and viewpoints drives performance and success. Our CEO, Harvey Schwartz, has stated that, "To build better businesses and create value for all of our stakeholders, we are focused on assembling leadership teams with the strongest insights from a range of perspectives." Reflecting this view, emphasis is placed on development, retention and inclusion through our internal processes and seven Employee Resource Groups (ERGs). We cultivate a culture where ideas are openly shared and challenged, connecting diverse expertise and perspectives to drive enduring value.