We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

IAM Cybersecurity Engineer

Zayo Group
life insurance, vision insurance, parental leave, paid time off, 401(k)
United States, Colorado, Denver
1401 Wynkoop Street (Show on map)
May 12, 2026

Company Description

Zayo provides mission-critical bandwidth to the world's most impactful companies, fueling the innovations that are transforming our society. Zayo's 141,000-mile network in North America and Europe includes extensive metro connectivity to thousands of buildings and data centers. Zayo's communications infrastructure solutions include dark fiber, private data networks, wavelengths, Ethernet, and dedicated Internet access. Zayo serves wireless and wireline carriers, media, tech, content, finance, healthcare and other large enterprises.

The IAM Engineer role is responsible for protecting Zayo computer networks from cybersecurity attacks and unauthorized access. This position focuses on the design, implementation, and operation of Identity and Access Management (IAM) solutions, with a strong emphasis on SailPoint Identity Security Cloud (ISC).The ideal candidate will support cloud-native identity governance capabilities, including lifecycle automation, access certifications, and application onboarding. This role partners with IT and Cybersecurity architects, engineers, and application owners to deliver scalable, compliant identity solutions aligned with business and regulatory objectives. This role may require rotating 24x7 on-call support.

Job Responsibilities:

* Design, implement, and manage IAM solutions with a focus on SailPoint Identity Security Cloud (ISC).

* Configure and support Identity Governance and Administration (IGA) capabilities including:

* Access certifications

* Identity lifecycle management

* Policy enforcement

* Implement and maintain Joiner, Mover, Leaver (JML) workflows using ISC lifecycle events and provisioning policies.

* Onboard and integrate applications using ISC connectors, including:

* Active Directory

* Azure Entra ID

* SaaS applications

* Support API-based integrations (REST/SCIM) for identity provisioning and application connectivity.

* Configure and execute access certification campaigns and ensure audit readiness.

* Ensure IAM governance processes align with regulatory and compliance requirements (e.g., SOX, GDPR, HIPAA, NIST, ISO 27001).

* Monitor, troubleshoot, and resolve provisioning failures and lifecycle-related issues.

* Generate and analyze reports related to provisioning, access, and compliance tracking.

* Collaborate with cross-functional teams to define and implement role-based access controls (RBAC).

* Support and integrate Privileged Access Management (PAM) solutions where applicable.

* Participate in audits, incident response, and remediation efforts related to IAM systems.

* Develop and maintain IAM documentation, including policies, procedures, and configurations.

* Stay current with IAM, IGA, and SailPoint ISC best practices and emerging technologies.

Experience and Education Requirements:

* Bachelor's degree in computer science, cybersecurity, or a related field (or equivalent experience).

* Minimum of three (3) years of experience in IAM, IGA, or PAM solutions.

* Minimum of two (2) years of hands-on experience with SailPoint ISC (IdentityNow / Identity Security Cloud).

* Strong understanding of identity lifecycle management and governance models.

* Experience with REST APIs, JSON, and SCIM integrations.

* Experience with directory services such as Active Directory and LDAP.

* Familiarity with cloud platforms (AWS, Azure, GCP).

* Experience with scripting/automation (e.g., PowerShell, Python) is preferred.

* Knowledge of security frameworks and compliance standards (NIST, ISO 27001, GDPR, SOX).

* Strong analytical, troubleshooting, and problem-solving skills.

* Excellent communication and collaboration abilities.

Preferred Qualifications:

* Experience migrating from SailPoint IdentityIQ to ISC.

* Familiarity with enterprise integrations such as:

o ServiceNow

o Workday

o SAP

* Exposure to CyberArk or other PAM tools.

* SailPoint ISC certification or other IAM-related certifications (CISSP, CISM, CIAM, etc.).

---

Tech Stack:

* SailPoint Identity Security Cloud (ISC)

* REST / SCIM APIs

* JSON

* Active Directory / Azure Entra ID

* ServiceNow

Estimated base salary range: $77,100 - $118,600 USD/annually

The base pay range shown is a guideline and reasonable estimate for this role. It takes into account the wide variety of factors that are considered in making compensation decisions. Actual compensation offered may vary from the posted range based upon geographic location, work experience, skill level, certifications, and other business and organizational needs. Non- sales roles may be eligible to participate in a discretionary annual incentive plan. Sales roles may be eligible to participate in a sales incentive plan.

Additionally, this position may be eligible for certain benefits, such as health insurance, life insurance, disability retirement plans, paid time off.

The posting will be active for a minimum of 3 days. The active posting will continue to extend by 3 days until the position is filled.

Benefits, Rewards & Wellness

  • Excellent Health, Dental & Vision Insurance

  • Retirement 401(k) Savings Plan

  • Generous paid time off policy including paid parental leave

Zayo provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, provincial or local laws.

This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Applied = 0

(web-bd9584865-ngh6r)