Job Description
We are seeking an experienced Identity Security Engineer to help design, implement, and mature enterprise identity security capabilities across our organization. This role serves as a technical owner and security steward for key identity functions, including identity governance, provisioning workflows, access control standards, authentication policy, privileged access, and SaaS identity integration patterns.
The ideal candidate is a hands-on technical engineer who can operate at both the architecture and implementation level. This individual should be able to support the implementation and maturity of an Identity Governance and Administration platform, design and validate provisioning workflows, advise on Conditional Access and MFA policies, and help configure or govern privileged access capabilities.
This position requires strong technical judgment, practical implementation skills, and the ability to communicate identity risk, access control requirements, and operational expectations clearly to Security, Helpdesk, Infrastructure, Application Owners, Risk, Compliance, and Audit stakeholders. The successful candidate should be comfortable implementing controls, documenting standards, influencing operational teams, and progressively taking ownership of identity security architecture decisions, design patterns, and roadmap execution.
Key Responsibilities
- Support implementation, configuration, and ongoing maturity of Identity Governance and Administration capabilities, including access requests, approvals, birthright access, role-based access, access reviews, certification campaigns, separation of duties, provisioning, deprovisioning, and lifecycle automation.
- Design, review, and validate Conditional Access, sign-in, password, session, and MFA policies across platforms such as Okta, Microsoft Entra ID, or similar identity providers.
- Support and troubleshoot privileged access management capabilities, including vaulting, credential rotation, privileged account onboarding, session brokering, RDP/SSH access patterns, just-in-time access, and privileged access reviews.
- Partner with Infrastructure and Application teams to onboard applications into provisioning, SSO, MFA, and privileged access processes using approved identity patterns.
- Develop and maintain identity integrations using standards and technologies such as SAML, OIDC/OAuth, SCIM, REST APIs, API authentication methods, webhooks, and automation workflows.
- Review access models, entitlement structures, groups, roles, and permissions to identify excessive access, orphaned access, toxic combinations, and opportunities for simplification.
- Work with ServiceNow teams to support access request workflows, approval routing, fulfillment tasks, catalog items, and integration between ITSM processes and identity governance capabilities.
- Provide technical oversight and escalation support for identity-related operational processes performed by Helpdesk, Infrastructure, and Application teams, including access fulfillment, application onboarding, MFA, provisioning, and privileged access.
- Collaborate with Risk, Compliance, Audit, and business stakeholders to produce evidence, explain access control designs, remediate findings, and improve control effectiveness.
- Stay current on identity security threats, SaaS identity risks, MFA bypass techniques, privileged access risks, and modern IAM best practices.
Qualifications
Required Experience
- 5+ years of experience in identity and access management, cybersecurity engineering, security operations, infrastructure security, cloud security, or related technical roles.
- Strong understanding of identity security concepts, including authentication, authorization, federation, MFA, access governance, privileged access, least privilege, lifecycle management, and segregation of duties.
- Experience supporting or implementing Identity Governance and Administration capabilities, including access requests, approvals, birthright access, access reviews, certification campaigns, provisioning, deprovisioning, entitlement management, and access reconciliation.
- Experience configuring, reviewing, or monitoring authentication and access enforcement controls, including password policies, sign-in policies, session controls, MFA, Conditional Access, group-based access, and application access controls.
- Familiarity with Privileged Access Management concepts such as credential vaulting, privileged session management, RDP/SSH access, password rotation, service accounts, shared accounts, break-glass access, and just-in-time access.
- Working knowledge of identity protocols, APIs, and integration patterns, including SAML, OIDC/OAuth, SCIM, LDAP, Kerberos, REST APIs, API authentication, JSON, webhooks, certificates, secrets, tokens, and integration troubleshooting.
- Experience creating or maintaining identity standards, implementation patterns, runbooks, operational procedures, escalation paths, and technical documentation.
- Ability to review identity configurations or access control changes performed by other teams, identify security or supportability concerns, and balance risk reduction with user experience and operational needs.
Professional Skills
- Strong analytical, troubleshooting, and problem-solving capabilities.
- Strong written and verbal communication skills, including the ability to explain identity risks, control requirements, and technical implementation decisions to technical and non-technical stakeholders.
- Strong organizational and project management skills with the ability to manage multiple priorities simultaneously.
- Collaborative team player with strong stakeholder management skills.
- Strategic thinker with the ability to operate both tactically and operationally in fast-paced environments.
- Self-motivated with a strong sense of accountability and ownership.
Education & Certifications
- Bachelor’s degree in Computer Science, Engineering, Information Security or related discipline preferred; equivalent experience will be considered.
- Industry certifications preferred but not required.
Preferred Attributes
- Experience working in highly regulated industries such as financial services or healthcare.
- Familiarity with security, identity, and access control frameworks and standards such as NIST CSF, NIST 800-53, CIS Controls, ISO 27001, SOC 2, SOX, least privilege, Zero Trust, and privileged access management best practices.
- Experience supporting enterprise-scale identity security, IAM, IGA, PAM, Zero Trust, or access governance transformation initiatives.
- Passion for continuous learning and staying ahead of evolving identity security risks, modern IAM capabilities, and attacker techniques targeting identity systems.
The base salary range for this position is $135,000 - $155,000 per year. This range reflects the minimum and maximum base salary we reasonably expect to pay for this role. In addition, this position may be eligible to participate in the relevant business unit’s incentive compensation plan, and other compensation programs as applicable. Eligible employees may participate in a 401(k) program with a generous profit-sharing contribution, medical, prescription dental, and vision coverage; life insurance; disability coverage; paid holidays; vacation; and sick time, subject to plan terms and Company policies.
About Bessemer Trust:
- Bessemer Trust is a family office, overseeing $250 billion in assets for 3,000 individuals and families of substantial wealth. Its more than 1,300 employees are singularly focused on private wealth management — disciplined investment management, sophisticated wealth planning, comprehensive family office services, and highly personalized client service.
- Established in 1907 as the family office for Annie and Henry Phipps, Bessemer Trust is in its seventh generation of ownership by the Phipps family. As a self-made entrepreneur, Henry Phipps was a founding partner and chief financial officer of Carnegie Steel.
- Bessemer Trust retains its original focus as a privately owned and independent wealth manager deeply committed to its mission of providing peace of mind to its clients. Bessemer’s adherence to putting clients’ interests first, fiduciary mindset, and highly collaborative culture are at the heart of everything the firm does.
Key Facts:
- For more than 119 years, Bessemer Trust has operated continuously in a single line of business, independently owned by one family.
- Headquartered in New York’s Rockefeller Center, Bessemer Trust has 22 offices in total. Woodbridge, NJ, is one of the firm’s largest offices, which hosts a wide range of technology and operations professionals. In addition to its sizable presence in New York and Woodbridge, the firm provides client service through offices in Atlanta, Boston, Chicago, Dallas, Delaware, Denver, Garden City, Grand Cayman, Greenwich, Houston, Los Angeles, Miami, Naples, Nevada, Palm Beach, San Diego, San Francisco, Seattle, Stuart, and Washington, D.C.
- To watch a video about Bessemer Trust’s history, click here
- To learn more about Bessemer Trust, click here
About Our Employee Rewards and Benefits:
- We provide exceptional rewards and benefits that are among the best in the industry, giving our people access to a wide range of options, including:
- Competitive base salary plus discretionary annual bonus for select positions
- A 401(k) plan with a generous annual profit-sharing contribution
- Personalized development and career opportunities, including tuition reimbursement support
- Comprehensive medical, dental, and vision plans with zero contributions for employee coverage
- Employee assistance (EAP) and wellness programs
- Hybrid work environment: 60% in office, 40% remote for most positions
- Paid time off and paid parental leave
- Employer-paid life insurance and short- and long-term disability coverage
- Legal services and financial wellness plans at no cost to employees
Bessemer Trust is committed to creating a diverse and inclusive environment and is proud to be an equal opportunity employer. We encourage candidates of diverse backgrounds to apply.