368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$100k – $125k per year
Location
In office (United States)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
IDEXX Laboratories is a multinational corporation headquartered in Westbrook, Maine, and was founded in 1983. The company develops, manufactures, and distributes diagnostic products, equipment, and software for the veterinary, livestock, poultry, and dairy markets, as well as testing solutions for water quality. It operates globally through a network of reference laboratories and sales offices, serving customers in over 175 countries and maintaining a listing on the NASDAQ Stock Market.

IT accelerates the success of IDEXX employees and customers by providing scalable and innovative solutions and leadership. We are a global organization that supports all technology needed to deliver products and solutions to customers enabling them to focus on delivering high quality patient care. We strive to provide exceptional customer service and experience in the most efficient means possible, requiring alignment and cross-functional communication.

We are seeking an experienced Identity and Access Management (IAM) Engineer to lead the design, implementation, and operational maturity of Identity Governance and Administration (IGA) capabilities across the enterprise. This role focuses on securing and governing both human and non-human identities, including service accounts, managed identities, workload identities, automation accounts, API integrations, and AI agents.

The IAM Engineer will be responsible for developing scalable identity governance processes, automating lifecycle management, enforcing least-privilege access, and reducing risk associated with service accounts and machine identities. This individual will work closely with Security, Infrastructure, Cloud Engineering, Application Owners, and Compliance teams to improve identity visibility, governance, and operational efficiency.

In this role, you will be responsible for...

Identity Governance & Administration (IGA)

  • Implement and maintain enterprise Identity Governance and Administration (IGA) solutions.
  • Design and manage access certification, access review, and entitlement management processes.
  • Develop and optimize joiner, mover, and leaver workflows.
  • Support role-based access control (RBAC) and access governance initiatives.
  • Partner with business stakeholders to define access models and governance controls.
  • Support audit, compliance, and regulatory requirements through reporting and attestation processes.

Service Account Governance

  • Establish governance standards for service accounts across on-premises and cloud environments.
  • Create and maintain inventory, ownership, classification, and lifecycle processes for service accounts.
  • Reduce interactive use of service accounts and implement secure authentication methods.
  • Design controls for credential rotation, privileged access management, and monitoring.
  • Conduct periodic reviews to identify orphaned, stale, or over-privileged service accounts.

Managed Identities & Workload Identities

  • Design and govern Azure Managed Identities and other cloud-native workload identities.
  • Develop standards for application authentication and authorization.
  • Partner with application teams to eliminate embedded credentials and secrets.
  • Implement least-privilege access models for cloud workloads and services.
  • Monitor and review workload identity permissions for excessive privilege.

AI Agents & Non-Human Identity Management

  • Define governance frameworks for AI agents, automation platforms, bots, APIs, and machine identities.
  • Establish controls for identity creation, ownership, access reviews, and lifecycle management.
  • Develop policies for agent-to-agent and agent-to-application access.
  • Ensure visibility and traceability of non-human activity across enterprise systems.
  • Partner with security teams to mitigate emerging risks associated with autonomous systems and AI-enabled workflows.

Automation & Engineering

  • Develop automation using PowerShell, Graph API, REST APIs, and cloud-native tooling.
  • Automate provisioning, deprovisioning, access reviews, reporting, and governance workflows.
  • Build integrations between IAM platforms, cloud providers, HR systems, ServiceNow, and enterprise applications.
  • Continuously improve IAM operational efficiency through scripting and workflow optimization.

Security & Compliance

  • Enforce least privilege and separation-of-duties controls.
  • Support security assessments, audit requests, and compliance reviews.
  • Develop metrics and reporting related to identity governance maturity.
  • Participate in incident response and investigations involving identity-related risks.
  • Maintain alignment with industry frameworks such as NIST, ISO 27001, SOC 2, and CIS controls.

What you will need to succeed...

  • Location: we are looking someone preferably driving distance to our HQ in Westbrook, Maine where we have a flexible hybrid requirement of only 8 days per month. We are also open to those in NH or MA that can come on site less frequently.
  • 5+ years of experience in Identity and Access Management, Identity Governance, or Security Engineering.
  • Experience implementing or administering IGA platforms such as:
    • Microsoft Entra ID Governance
    • SailPoint IdentityNow / IdentityIQ
    • Saviynt
    • Okta Identity Governance
  • Strong understanding of:
    • RBAC
    • Access Certifications
    • Entitlement Management
    • Identity Lifecycle Management
  • Experience managing:
    • Service Accounts
    • Managed Identities
    • Application Identities
    • API Credentials
    • Workload Identities
  • Experience with:
  • Microsoft Entra ID
  • Active Directory
  • Azure
  • AWS IAM
  • Google Cloud IAM
  • Proficiency with PowerShell, REST APIs, and automation scripting.

Preferred Qualifications

  • Experience with Privileged Access Management (CyberArk, BeyondTrust, Delinea, Microsoft PAM, etc.).
  • Experience governing AI agents, automation platforms, and machine identities.
  • Knowledge of cloud-native authentication methods and secrets management.
  • Experience integrating IAM solutions with HR, ITSM, and enterprise application ecosystems.
  • Microsoft, SailPoint, CISSP, Security+, or relevant IAM certifications.

Success Measures

  • Reduction in unmanaged service accounts and non-human identities.
  • Increased identity governance coverage across enterprise applications.
  • Successful implementation of automated access reviews and certifications.
  • Improved ownership and accountability for service accounts and managed identities.
  • Increased use of least-privilege access models.
  • Reduction in audit findings related to identity governance and access management.
  • Increased automation of identity lifecycle and governance processes

What you can expect from us:

  • Base annual salary target: $100000 - $125000 (yes, we do have flexibility if needed)
  • Opportunity for annual cash bonus
  • Health / Dental / Vision Benefits Day-One
  • 5% matching 401k
  • Additional benefits including but not limited to financial support, pet insurance, mental health resources, volunteer paid days off, employee stock program, foundation donation matching, and much more!

Why IDEXX?

We’re proud of the work we do, because our work matters. An innovation leader in every industry we serve, we follow our Purpose and Guiding Principles to help pet owners worldwide keep their companion animals healthy and happy, to ensure safe drinking water for billions, and to help farmers protect livestock and poultry from diseases. We have customers in over 175 countries and a global workforce of over 10,000 talented people.

So, what does that mean for you? We enrich the livelihoods of our employees with a positive and respectful work culture that embraces challenges and encourages learning and discovery. At IDEXX, you will be supported by competitive compensation, incentives, and benefits while enjoying purposeful work that drives improvement.

Let’s pursue what matters together.

IDEXX values a diverse workforce and workplace and strongly encourages women, people of color, LGBTQ+ individuals, people with disabilities, members of ethnic minorities, foreign-born residents, and veterans to apply.

IDEXX is an equal opportunity employer. Applicants will not be discriminated against because of race, color, creed, sex, sexual orientation, gender identity or expression, age, religion, national origin, citizenship status, disability, ancestry, marital status, veteran status, medical condition, or any protected category prohibited by local, state, or federal laws.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
United States
$185k – $260k per year • Remote • Full-Time • 8+ years exp • Bachelor's Degree
DevOps
AWS
CI/CD
GCP
Kubernetes
GitHub
Cybersecurity
Clair
Dependabot
OWASP Top 10
OWASP ZAP
Snyk
Trivy
Apply
$169k – $321k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Phoenix
AI/ML
AI Agents
Anomaly Detection
LLM Guardrails
DevOps
AWS
Kong
Amazon S3
API Gateway
Cybersecurity
Zero Trust
Apply
$110k – $131k per year • Remote • Full-Time • 10+ years exp • Bachelor's Degree
DevOps
AWS
Incident Management
VMWare
Apply
$105k – $252k per year • Remote • Full-Time • 18+ years exp • Bachelor's Degree
Python
Java
Java
Gradle
DevOps
Ansible
AWS
CI/CD
CloudFormation
Configuration Management
Docker
GitHub Actions
GitLab CI
Helm
Jenkins
Kubernetes
Platform Engineering
Terraform
GitHub
GitLab
Cybersecurity
Sonatype Nexus IQ
Management
Confluence
Jira
Apply
$54k – $175k per year (Estimated) • Remote • Full-Time
JavaScript
Node JS
TypeScript
Frontend
React.js
Sass
DevOps
AWS
CI/CD
Docker
Kubernetes
Rest API
Apply
$100k – $125k per year • Remote • Full-Time • 7+ years exp • United States
Java
Kotlin
Python
TypeScript
Java
Maven
Databases
DynamoDB
PostgreSQL
AI/ML
AI Agents
Ray
DevOps
AWS
AWS Lambda
Azure
CI/CD
CloudFormation
Git
GitHub Actions
JFrog Artifactory
OpenTelemetry
Platform Engineering
Terraform
Amazon EventBridge
Amazon S3
GitHub
Cybersecurity
Microsoft Entra ID
Apply
$104k – $195k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • United States
Python
SQL
Databases
Databricks
AI/ML
Spark
Amazon SageMaker
Edge AI
DevOps
Amazon EC2
AWS
CI/CD
Docker
Amazon S3
Apply
$200k per year • Equity • In office • Full-Time • United States
Apply
Remote/Hybrid • Full-Time • Auckland
PHP
Python
DevOps
AWS
CI/CD
Apply
$78k – $130k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Cary • San Jose
Analytics
Power BI
Apply
$91k – $182k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • United States
Design
SolidWorks
Apply
$45k – $60k per year • Remote • Full-Time • 2+ years exp • PhD • United States
Cybersecurity
HIPAA
Apply
$117k – $258k per year (Estimated) • Equity • Remote • Full-Time • United States
C++
Java
Python
Cybersecurity
Crowdstrike
Apply
$90k – $184k per year (Estimated) • Equity • Remote • Full-Time • 3+ years exp • United States
AI/ML
Red Teaming
Cybersecurity
Burp Suite
Cobalt Strike
Crowdstrike
Metasploit
MITRE ATT&CK
Nessus
Nmap
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.