Senior IAM Engineer
FanDuel is seeking an Identity and Access Management (IAM) Engineer to join its Enterprise Identity Engineering team as a technical specialist driving identity governance and access control across the organisation. This role offers a unique opportunity to architect and implement identity solutions that strengthen FanDuel's security posture while enabling seamless business operations.
The ideal candidate brings hands-on expertise in modern identity platforms, cloud infrastructure, and the IAM lifecycle. This role involves not just provisioning users, but architecting scalable access frameworks, automating identity workflows, and ensuring compliance through intelligent access controls.
At its core, this role is about designing and operationalising a unified Identity and Access Management architecture for FanDuel. The successful candidate will be instrumental in designing identity governance frameworks that ensure the right people have the right access to the right resources at the right time. They will architect and manage authentication and authorisation solutions across cloud platforms, applications, and infrastructure, ensuring both security and user experience. Beyond implementation, the role involves establishing standards, procedures, and automation that keep the IAM program running efficiently and adapting to evolving business and security needs.
- Design and implement a comprehensive Identity and Access Management architecture that spans cloud platforms (AWS), SaaS applications, infrastructure, and on-premises systems, ensuring alignment with FanDuel's security frameworks and industry best practices (NIST, CSA CCM, SOC2, PCI-DSS, GLI-GSF).
- Drive the complete IAM lifecycle-including identity schema design, user provisioning and deprovisioning workflows, access request and approval processes, periodic access reviews and recertification, and identity governance automation with an efficiency-first mindset.
- Architect and implement multi-factor authentication (MFA), single sign-on (SSO), and identity federation solutions across diverse platforms and applications to balance security with user experience.
- Develop and maintain IAM automation-leveraging APIs, infrastructure-as-code, and workflow orchestration platforms-to scale access management while reducing manual overhead and human error.
- Drive Terraform adoption for identity infrastructure-as-code management, implementing version-controlled CI/CD pipelines across Okta, C1, and other identity platforms.
- Build continuous identity monitoring and analytics capabilities to detect access anomalies, privilege escalation risks, and unauthorised activities; respond to identity-related security incidents with forensic analysis and remediation.
- Build and maintain custom application connectors to support JML (Joiner, Mover, Leaver) lifecycle flows, integrating identity data with HR systems, HRIS platforms, and other business applications to automate onboarding, access changes, and offboarding processes.
- Manage authentication and authorisation mechanisms across AWS IAM, Okta, C1 GitHub, Atlassian, and other critical systems, ensuring consistent policy enforcement and audit capabilities.
- Manage Okta device access controls to enhance security posture and improve user login experience, including device compliance policies, platform integrity monitoring, and risk-based access decisions.
- Lead organisation-wide FIDO2 security key deployment, partnering with IT support and end-users to ensure proper configuration, adoption, and ongoing management of passwordless authentication across the enterprise.
- Establish and maintain identity governance policies, standards, procedures, and technical controls; ensure alignment with enterprise security principles and regulatory requirements.
- Partner with Security, Infrastructure, and Application teams to conduct access requirements analysis, design role-based access control (RBAC) and attribute-based access control (ABAC) models, and implement least-privilege principles across technology platforms.
- Support the rollout of the AI Agent Governance lifecycle across the organisation, encompassing Discovery of AI agents, Onboarding of agents into governance systems, Protecting agents through identity and access controls, and establishing ongoing Governance mechanisms to ensure compliance, security, and operational accountability.
- Maintain comprehensive documentation, runbooks, technical playbooks, dashboards, and metrics for identity governance health and access risk posture.
- Stay abreast of evolving identity security threats, IAM technologies, and regulatory changes; evaluate and recommend new identity platforms, technologies, and approaches to enhance security and efficiency.
- Partner with FanDuel's identity governance and other brands' security teams to align standards and drive efficiencies across the enterprise.
- Share knowledge and best practices with team members, contributing to the development of team IAM expertise and promoting continuous improvement across the security engineering function.
- Bachelor's degree preferred in Computer Science, Information Security, or related technical field, or equivalent combination of education, training, and relevant experience (preferred).
- 5+ years of hands-on IAM engineering and implementation experience across cloud, hybrid, and on-premises environments (required).
- Strong proficiency with modern identity platforms including AWS IAM, Azure AD/Entra ID, Okta, and LDAP/Active Directory (required).
- Hands-on experience with authentication mechanisms (OAuth 2.0, SAML, OIDC, etc.), MFA implementation, and Single Sign-On (SSO) architecture (required).
- Experience designing and implementing role-based access control (RBAC) and attribute-based access control (ABAC) models aligned to business requirements (required).
- Hands-on experience with identity provisioning tools, user lifecycle management, and workflow automation platforms (e.g., Okta Workflows, MuleSoft, custom API development) (required).
- Solid programming and scripting skills (Python, Bash, Go, or similar) to automate identity tasks and integrate systems via APIs (required).
- Experience implementing and managing identity governance programs including access reviews, segregation of duties, and continuous access monitoring (required).
- Proficiency with cloud platforms (AWS, Azure, or GCP) and their native IAM/identity services (required).
- Experience architecting and implementing MFA and passwordless authentication solutions (required).
- Knowledge of identity security best practices, frameworks, and standards including NIST SP 800-63, NIST CSF, Zero Trust principles, and compliance requirements (SOC2, PCI-DSS, GLI-GSF) (required).
- Familiarity with DevOps practices, infrastructure-as-code (Terraform, CloudFormation), and CI/CD pipelines as they relate to identity and access automation (required).
- Experience integrating identity solutions with SaaS applications, GitHub, Atlassian products, and other critical enterprise software (required).
- Excellent troubleshooting and problem-solving skills with ability to debug complex identity-related issues across distributed systems (required).
- Strong written and verbal communication skills to articulate IAM concepts to both technical and non-technical stakeholders (required).
- Relevant professional certifications such as CISSP, CISM, IAM specialist certifications (Okta, AWS, Azure, or similar), or industry-recognized IAM credentials are preferred (preferred).
- Experience working as a consultant or in senior IAM roles in regulated industries is a plus (nice-to-have).
- Health plans to choose from (some as low as $0 per paycheck) that include programs for fertility and family planning, mental health support, and fitness benefits.
- Generous paid time off (PTO & sick leave).
- Annual bonus and long-term incentive opportunities (based on performance).
- 401k with up to a 5% match.
- Commuter benefits.
- Pet insurance.
- Medical, vision, and dental insurance.
- Life insurance.
- Disability insurance.
- 14 paid company holidays.
FanDuel Group is an innovative sports-tech entertainment company that is changing the way consumers engage with their favorite sports, teams, and leagues. The premier gaming destination in the North America, FanDuel Group consists of a portfolio of leading brands across gaming, sports betting, daily fantasy sports, advance-deposit wagering, and TV/media, including FanDuel, Stardust Casino and TVG. The company is based in New York with US offices in Los Angeles, Atlanta, and Jersey City, as well as global offices in Canada and Scotland. The company’s affiliates have offices worldwide, including in Ireland, Portugal, Romania, and Australia. FanDuel Group is a subsidiary of Flutter Entertainment, the world's largest sports betting and gaming operator with a portfolio of globally recognized brands and traded on the New York Stock Exchange (NYSE: FLUT).