Demo

Senior IAM Engineer

Kestra Financial
Kestra Financial Salary
Tempe, AZ Full Time
POSTED ON 1/9/2026
AVAILABLE BEFORE 2/6/2026
Kestra Holdings offers industry-leading wealth management platforms for independent wealth management professionals nationwide. Kestra is dedicated to empowering independent financial professionals—including traditional and hybrid RIAs—to grow their businesses and deliver exceptional client service. We combine advanced business management technology with personalized consulting to provide unmatched scale, efficiency, and support. Our advisor-focused culture is built on innovation and advocacy, enabling advisors to offer comprehensive securities and investment advisory solutions to their clients.

Lead with Purpose. Partner with Impact.

We are seeking a Sr. IAM Engineer with deep experience assessing current state, designing target-state architectures, and implementing/maturing Role-Based (RBAC) and Attribute-Based (ABAC) access models at enterprise scale. This leader will serve as the SailPoint technical expert, engineering policy, integration, and governance processes that meet financial-services compliance expectations. The role partners with enterprise architects, risk/compliance, platform teams, and app owners to operationalize identity as a control across SaaS, on-prem, and cloud.

What you’ll Do:

  • Define RBAC/ABAC standards, pattern libraries, and guardrails; author architecture decision records (ADRs).
  • Drive role engineering (role discovery, consolidation, birthright access, SoD matrices) and ABAC policy design (attribute inventory, policy enforcement integration).
  • Maintain the IGA reference architecture spanning SailPoint, Okta, directories (AD/LDAP), HR/ERP, and cloud providers.
  • Partner with AppSec and platform teams to externalize authorization using federation and standardized protocols (SAML 2.0, OIDC, OAuth 2.0; SCIM for provisioning).
  • Configure sources/authorities, connectors, aggregation & correlation rules, identity profiles, entitlement catalogs, lifecycle policies, workflows, access request, and certification campaigns in SailPoint; implement Okta connector patterns.
  • Build monitoring/health checks, metrics, and dashboards for access governance KPIs; automate evidence collection.
  • Define policies/standards for access control, attribute quality, identity proofing, certification cadence, and exception handling; ensure alignment with enterprise risk appetite.
  • Support audits and regulatory examinations with defensible evidence, including certification results, SoD analyses, and access recertification trails.
  • Mentor engineers and analysts; partner with business/application owners to onboard apps at scale under governance; establish repeatable app-onboarding playbooks (federation provisioning role modeling).
  • SailPoint (IdentityIQ Engineer/Architect or Identity Security Cloud) and/or Okta certifications; experience integrating SailPoint with Okta via connectors/APIs.
  • Cloud IAM concepts (Azure AD/Entra ID, AWS IAM), and experience mapping ABAC to cloud entitlements/metadata.
  • Financial-services experience with audit/regulatory expectations (e.g., access certification cadence, evidence, SoD rigor).

What You Bring:

  • 8 years in IAM with 5 years leading RBAC/ABAC design and enterprise deployment; demonstrable delivery of role mining/engineering and attribute-driven authorization.
  • Hands-on SailPoint expertise (IdentityIQ or Identity Security Cloud/IdentityNow) across connectors, lifecycle automation, certifications, SoD, policy, and analytics; Okta SSO/MFA and federation patterns.
  • Strong command of federated identity protocols and provisioning standards (SAML 2.0, OIDC, OAuth 2.0, SCIM).
  • Working knowledge of directory services (AD/LDAP), identity data modeling, and integration architectures; familiarity with crypto & tokenization fundamentals for identity.
  • Experience establishing access governance processes (access reviews, recertifications, SoD, exception management) consistent with industry best practices.
  • Proficiency in at least one scripting language (e.g., Beanshell/Java for IIQ, Python/PowerShell for automation), and SQL for identity analytics.

Internal Application Policy:

Internal applicants must be in good standing and have a minimum of 1 year of service with Kestra. Internal applicants must also have a minimum of 1 year service in current role unless approved by EVP.

Benefits to support you:

  • Competitive pay and benefits with a large employer (over 1600 employees nationwide)
  • 401(k), health insurance, and a competitive benefits package
  • Work in a supportive, collaborative environment committed to professional excellence
  • Help clients navigate meaningful financial decisions with confidence
  • Opportunities for training, development, and long-term growth within the firm
  • Tuition reimbursement for qualified expenses

Kestra Values:

Our Mission is Powering Financial Independence, enabling the growth and success of investing clients and the advisors who serve them. We do that by living our values: Serve, Make it Happen, and One team.

Explore Life at Kestra

Kestra Holdings Website: https://www.kestrafinancial.com/

Careers Portal: https://jobs.dayforcehcm.com/en-US/kestra/KESTRACAREERSITE

LinkedIn: https://www.linkedin.com/company/kestra-financial

Apply Today

Lead with purpose. Apply now and help shape the future of Kestra.

Disclosure By applying to a job at Kestra Financial, Inc., you are agreeing to the following statements:

  • You acknowledge that if hired, Kestra Financial, Inc. may, obtain and use background information concerning your credit, character, general reputation, personal characteristics, work habits, performance and experience for evaluation for your potential employment.
  • It is the policy of Kestra Financial to ensure equal employment opportunity without discrimination or harassment on the basis of race, color, religion, sex, sexual orientation, gender, identity or expression, age, disability, marital status, citizenship, national origin, genetic information, or any other characteristic protected by law. Kestra Financial prohibits any such discrimination or harassment.

Salary.com Estimation for Senior IAM Engineer in Tempe, AZ
$61,187 to $77,547
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Senior IAM Engineer?

Sign up to receive alerts about other jobs on the Senior IAM Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$129,363 - $167,316
Income Estimation: 
$145,845 - $177,256
Income Estimation: 
$147,836 - $182,130
Income Estimation: 
$154,597 - $194,610
Income Estimation: 
$86,891 - $130,303
Income Estimation: 
$59,454 - $77,232
Income Estimation: 
$74,206 - $95,716
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Kestra Financial

  • Kestra Financial Tempe, AZ
  • Kestra Financial is a wealth management platform dedicated to empowering independent financial professionals—including traditional and hybrid RIAs—to grow ... more
  • 12 Days Ago

  • Kestra Financial Austin, TX
  • ABOUT US: Come join the dynamic team at Kestra Financial! Kestra Financial provides a leading independent advisor platform that empowers sophisticated, ind... more
  • 15 Days Ago

  • Kestra Financial Tempe, AZ
  • Kestra Holdings offers industry-leading wealth management platforms for independent wealth management professionals nationwide. Kestra is dedicated to empo... more
  • 3 Days Ago

  • Kestra Financial Tempe, AZ
  • Kestra Holdings offers industry-leading wealth management platforms for independent wealth management professionals nationwide. Kestra is dedicated to empo... more
  • 3 Days Ago


Not the job you're looking for? Here are some other Senior IAM Engineer jobs in the Tempe, AZ area that may be a better fit.

  • Edward Jones Tempe, AZ
  • This job posting is anticipated to remain open for 30 days, from 01-Dec-2025. The posting may close early due to the volume of applicants. Join a financial... more
  • 1 Month Ago

  • Carvana Tempe, AZ
  • About Carvana At Carvana, we’re changing the way people buy and sell cars. With an ambitious vision and a fundamentally different approach designed to be f... more
  • 7 Days Ago

AI Assistant is available now!

Feel free to start your new journey!