Senior IAM Engineer

FanDuelNew York, NY
$138,000 - $173,000Hybrid

About The Position

FanDuel is seeking an Identity and Access Management (IAM) Engineer to join its Enterprise Identity Engineering team as a technical specialist driving identity governance and access control across the organization. This role offers a unique opportunity to architect and implement identity solutions that strengthen our security posture while enabling seamless business operations. The ideal candidate brings hands-on expertise in modern identity platforms, cloud infrastructure, and the IAM lifecycle—understanding not just how to provision users, but how to architect scalable access frameworks, automate identity workflows, and ensure compliance through intelligent access controls. At its core, this role is about designing and operationalizing a unified Identity and Access Management architecture for FanDuel. You will be instrumental in designing identity governance frameworks that ensure the right people have the right access to the right resources at the right time. You'll architect and manage authentication and authorization solutions across our cloud platforms, applications, and infrastructure, ensuring both security and user experience. Beyond implementation, you'll establish standards, procedures, and automation that keep our IAM program running efficiently and adapting to evolving business and security needs. In addition to the specific responsibilities outlined above, employees may be required to perform other such duties as assigned by the Company. This ensures operational flexibility and allows the Company to meet evolving business needs.

Requirements

  • Bachelor's degree preferred in Computer Science, Information Security, or related technical field, or equivalent combination of education, training, and relevant experience.
  • 5+ years of hands-on IAM engineering and implementation experience across cloud, hybrid, and on-premises environments.
  • Strong proficiency with modern identity platforms including AWS IAM, Azure AD/Entra ID, Okta, and LDAP/Active Directory.
  • Hands-on experience with authentication mechanisms (OAuth 2.0, SAML, OIDC, etc.), MFA implementation, and Single Sign-On (SSO) architecture.
  • Experience designing and implementing role-based access control (RBAC) and attribute-based access control (ABAC) models aligned to business requirements.
  • Hands-on experience with identity provisioning tools, user lifecycle management, and workflow automation platforms (e.g., Okta Workflows, MuleSoft, custom API development).
  • Solid programming and scripting skills (Python, Bash, Go, or similar) to automate identity tasks and integrate systems via APIs.
  • Experience implementing and managing identity governance programs including access reviews, segregation of duties, and continuous access monitoring.
  • Proficiency with cloud platforms (AWS, Azure, or GCP) and their native IAM/identity services.
  • Experience architecting and implementing MFA and passwordless authentication solutions.
  • Knowledge of identity security best practices, frameworks, and standards including NIST SP 800-63, NIST CSF, Zero Trust principles, and compliance requirements (SOC2, PCI-DSS, GLI-GSF).
  • Familiarity with DevOps practices, infrastructure-as-code (Terraform, CloudFormation), and CI/CD pipelines as they relate to identity and access automation.
  • Experience integrating identity solutions with SaaS applications, GitHub, Atlassian products, and other critical enterprise software.
  • Excellent troubleshooting and problem-solving skills with ability to debug complex identity-related issues across distributed systems.
  • Strong written and verbal communication skills to articulate IAM concepts to both technical and non-technical stakeholders.
  • "Stay Hungry, Stay Humble" mindset that strives to continuously learn new identity technologies and share knowledge with others, embracing the rapid evolution of the IAM landscape.
  • "Anything Is Possible" attitude that is highly organized and results-driven to architect and implement IAM solutions that solve critical security challenges.
  • Comfortable navigating shifting priorities in a fast-paced environment, with the ability to work independently on architectural challenges while excelling as a collaborative team player who promotes knowledge sharing and cohesiveness.

Nice To Haves

  • Relevant professional certifications such as CISSP, CISM, IAM specialist certifications (Okta, AWS, Azure, or similar), or industry-recognized IAM credentials are preferred.
  • Experience working as a consultant or in senior IAM roles in regulated industries is a plus.

Responsibilities

  • Design and implement a comprehensive Identity and Access Management architecture that spans cloud platforms (AWS), SaaS applications, infrastructure, and on-premises systems, ensuring alignment with FanDuel's security frameworks and industry best practices (NIST, CSA CCM, SOC2, PCI-DSS, GLI-GSF)
  • Drive the complete IAM lifecycle—including identity schema design, user provisioning and deprovisioning workflows, access request and approval processes, periodic access reviews and recertification, and identity governance automation with an efficiency-first mindset
  • Architect and implement multi-factor authentication (MFA), single sign-on (SSO), and identity federation solutions across diverse platforms and applications to balance security with user experience
  • Develop and maintain IAM automation—leveraging APIs, infrastructure-as-code, and workflow orchestration platforms—to scale access management while reducing manual overhead and human error
  • Drive Terraform adoption for identity infrastructure-as-code management, implementing version-controlled CI/CD pipelines across Okta, C1, and other identity platforms
  • Build continuous identity monitoring and analytics capabilities to detect access anomalies, privilege escalation risks, and unauthorized activities; respond to identity-related security incidents with forensic analysis and remediation
  • Build and maintain custom application connectors to support JML (Joiner, Mover, Leaver) lifecycle flows, integrating identity data with HR systems, HRIS platforms, and other business applications to automate onboarding, access changes, and offboarding processes
  • Manage authentication and authorization mechanisms across AWS IAM, Okta, C1 GitHub, Atlassian, and other critical systems, ensuring consistent policy enforcement and audit capabilities
  • Manage Okta device access controls to enhance security posture and improve user login experience, including device compliance policies, platform integrity monitoring, and risk-based access decisions
  • Lead organization-wide FIDO2 security key deployment, partnering with IT support and end-users to ensure proper configuration, adoption, and ongoing management of passwordless authentication across the enterprise
  • Establish and maintain identity governance policies, standards, procedures, and technical controls; ensure alignment with enterprise security principles and regulatory requirements
  • Partner with Security, Infrastructure, and Application teams to conduct access requirements analysis, design role-based access control (RBAC) and attribute-based access control (ABAC) models, and implement least-privilege principles across technology platforms
  • Support the rollout of the AI Agent Governance lifecycle across the organization, encompassing Discovery of AI agents, Onboarding of agents into governance systems, Protecting agents through identity and access controls, and establishing ongoing Governance mechanisms to ensure compliance, security, and operational accountability
  • Maintain comprehensive documentation, runbooks, technical playbooks, dashboards, and metrics for identity governance health and access risk posture
  • Stay abreast of evolving identity security threats, IAM technologies, and regulatory changes; evaluate and recommend new identity platforms, technologies, and approaches to enhance security and efficiency
  • Partner with FanDuel's identity governance and other brands' security teams to align standards and drive efficiencies across the enterprise
  • Share knowledge and best practices with team members, contributing to the development of team IAM expertise and promoting continuous improvement across the security engineering function

Benefits

  • array of health plans to choose from (some as low as $0 per paycheck) that include programs for fertility and family planning, mental health support, and fitness benefits.
  • generous paid time off (PTO & sick leave)
  • annual bonus and long-term incentive opportunities (based on performance)
  • 401k with up to a 5% match
  • commuter benefits
  • pet insurance
  • medical, vision, and dental insurance
  • life insurance
  • disability insurance
  • paid personal time off
  • 14 paid company holidays
  • paid sick time in accordance with all applicable state and federal laws
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service