Posted on: 21/08/2026
Role Overview:
Fanatics Commerce is looking for an IAM Engineer who places a strong emphasis on usable security and scaling successfully through automation. In this role, you will own the overall strategy, planning, development, and support of Fanatics' IAM solutions and associated processes, providing direction across federation, privileged access management, authentication and authorization, certificate management, and identity provisioning.
What You Will Do:
- Partner closely with service desk, systems engineering, network security, audit, application developers, and other engineers to design and maintain functional, scalable, and secure IAM operations.
- Act as the functional technical leader during IAM implementations, driving technology selection and setting engineering direction.
- Define and enforce a least-privilege access security model across all systems and platforms.
- Produce privileged access usage reports and support audit evidence requests for SOC 2, PCI DSS, and ITGC controls.
- Partner with application and engineering teams to onboard new applications into Okta.
- Support emerging identity controls for AI agents and machine identities, including scoped OAuth tokens and service-to-service authentication.
- Identify, evaluate, and drive decision-making around new and emerging IAM technologies, including CIEM, ITDR, and IGA platforms.
- Build automated monitoring and renewal pipelines for TLS/SSL certificate lifecycle management.
- Implement adaptive MFA, conditional access policies, and passwordless authentication initiatives.
- Own the full PAM platform lifecycle to reduce standing privilege across the organization.
Tech Stack & Requirements:
- A minimum of 5 years of experience designing, implementing, and managing complex IAM solutions, with expertise in PAM platforms such as CyberArk, Delinea, or BeyondTrust.
- Proficiency in SSO and identity protocols including Okta administration, SAML, OIDC, OAuth, Active Directory, and LDAP.
- Working knowledge of certificate management and PKI concepts (TLS, CA hierarchies, key rotation) with experience building automated renewal pipelines.
- Experience with CIEM, ITDR, and IGA platforms, and familiarity with emerging authorization mechanisms based on Zanzibar/ReBAC.
- Proficiency with cloud technologies (AWS, Azure, GCP, or OCI), configuration management tools (Terraform or Ansible), DevOps tools (Bitbucket, GitLab, GitHub, Jenkins), and advanced programming experience in Python, Go, or equivalent.
- Exceptional communication skills with the ability to translate complex technical security topics to stakeholders.
Education:
Bachelor's degree in Computer Science, Information Systems, or equivalent combination of education and experience; relevant security certifications required.
Work Location:
Hybrid: The primary place of performance of this role is the Company's office located in Hyderabad.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1665181