Demo

Lead Hybrid Identity Lead Engineer (IAM)

Kforce Inc
York, NY Full Time
POSTED ON 3/18/2026
AVAILABLE BEFORE 5/5/2026
Responsibilities

Lead IAM Engineer Responsibilities Kforce is partnering with a mission-driven organization in New York, NY seeking a Hybrid Identity Lead Engineer to help lead enterprise-wide IAM initiatives supporting a modern Zero Trust architecture. This is a hands-on, lead-level role focused on hybrid identity across on-prem and cloud environments, with core emphasis on Microsoft Entra ID (Azure AD) and AWS IAM (GCP is a plus, not required). You'll play a key role in designing secure, scalable identity solutions, driving automation and governance, and partnering closely with security and infrastructure teams. The role is super flexible (about once per week onsite) and offers a strong overall package including a 403(b), generous PTO, excellent medical benefits, tuition reimbursement, and a discretionary bonus. Lead IAM Engineer Lead IAM Engineer What You'll Do:

  • Identity Lead Engineer will architect and maintain a unified IAM framework across AD, Azure AD, AWS, and GCP
  • Implement enterprise identity standards including RBAC, naming conventions, and lifecycle automation
  • Lead the adoption of Zero Trust principles and enforce least privilege access across multi-cloud environments
  • Collaborate with DevOps and cloud teams to ensure secure, auditable access models
  • Administer and optimize on-prem Active Directory and Entra ID Conditional Access policies
  • Automate provisioning and group management using PowerShell, Python, or Terraform
  • As an Identity Lead Engineer, you will respond to audit findings and security assessments with expert-level IAM solutions
  • Mentor engineers and contribute to cross-functional initiatives across IT security, infrastructure, and compliance

Requirements

Lead IAM Engineer Requirements

  • Bachelor's degree in a related field
  • Cloud certifications such as: Microsoft Certified: Identity and Access Administrator Associate; AWS Certified Security Specialty; GCP Cloud Security Engineer
  • 7 years of experience in identity and access management
  • Hands-on experience with Active Directory, Azure AD, AWS IAM, and GCP IAM
  • Strong scripting skills (PowerShell, Python, Terraform)
  • Familiarity with PAM tools (e.g., CyberArk, BeyondTrust) and IGA solutions (e.g., SailPoint)

The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.

We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.

Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.

This job is not eligible for bonuses, incentives or commissions.

Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.

By clicking “Apply Today” you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.

Salary : $150,000 - $170,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Lead Hybrid Identity Lead Engineer (IAM)?

Sign up to receive alerts about other jobs on the Lead Hybrid Identity Lead Engineer (IAM) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$76,585 - $97,644
Income Estimation: 
$96,445 - $123,608
Income Estimation: 
$94,625 - $127,578
Income Estimation: 
$132,795 - $178,786
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Kforce Inc

  • Kforce Inc Miami, FL
  • Business Partner Description: Kforce is a solutions firm specializing in technology, finance & accounting, and professional staffing services. Each year, w... more
  • 9 Days Ago

  • Kforce Inc Smithfield, RI
  • Responsibilities Kforce has a client in Smithfield, RI that is seeking an Azure Data Cloud Engineer. Requirements Bachelor's degree required 7 years of han... more
  • 9 Days Ago

  • Kforce Inc Merrimack, NH
  • Responsibilities Kforce has a client in Merrimack, NH that is seeking a Business Analyst with a solid understanding of the current application and ensure t... more
  • 9 Days Ago

  • Kforce Inc Merrimack, NH
  • Responsibilities Kforce has a client in Merrimack, NH that is seeking an Oracle Developer. Responsibilities: Analyzing and designing technology solutions C... more
  • 9 Days Ago


Not the job you're looking for? Here are some other Lead Hybrid Identity Lead Engineer (IAM) jobs in the York, NY area that may be a better fit.

  • Lead Advisor York, NY
  • Lead Advisor is a wealth management consulting and search firm. This role is for a client based in Midtown Manhattan but open to a hybrid schedule. Core Re... more
  • 3 Days Ago

  • ADDSOURCE Manhattan, NY
  • Title: Identity Lead Engineer Position Type: Contract Location: NYC, NY (onsite) Job Description: In this role, the experienced Hybrid Identity Lead Engine... more
  • 1 Day Ago

AI Assistant is available now!

Feel free to start your new journey!