1

Identity Access Management Engineer Jobs in California

next page

Showing results 1-20

Identity Access Management Engineer information

See California salary details

$60.7K

$150.8K

$202.8K

How much do identity access management engineer jobs pay per year?

As of Jul 27, 2026, the average yearly pay for identity access management engineer in California is $150,773.00, according to ZipRecruiter salary data. Most workers in this role earn between $141,100.00 and $156,400.00 per year, depending on experience, location, and employer.

What is an Identity Access Management Engineer job?

An Identity Access Management (IAM) Engineer is responsible for designing, implementing, and managing an organization's access control systems to ensure secure and efficient user authentication and authorization. They configure IAM solutions, enforce security policies, and integrate identity governance frameworks to protect sensitive data. Additionally, they troubleshoot access issues, monitor system performance, and collaborate with security teams to maintain compliance with industry standards.

What are the key skills and qualifications needed to thrive in the Identity Access Management Engineer position, and why are they important?

To thrive as an Identity Access Management (IAM) Engineer, you need a strong background in IT security, directory services, authentication protocols, and typically a degree in computer science or a related field. Familiarity with IAM platforms like Okta, SailPoint, or Microsoft Azure AD, as well as certifications such as CISSP or CompTIA Security+, is highly valued. Attention to detail, analytical thinking, and effective communication skills help IAM engineers troubleshoot issues and convey complex security concepts to both technical and non-technical stakeholders. These competencies are crucial for safeguarding organizational data, ensuring regulatory compliance, and enabling seamless user access management.

What are some typical daily responsibilities for an Identity Access Management Engineer?

As an Identity Access Management Engineer, your daily tasks often include configuring and managing user access rights, monitoring authentication systems for security events, and troubleshooting access-related issues. You may also be responsible for implementing new IAM solutions, conducting regular audits to ensure compliance with security policies, and coordinating with IT and security teams to address vulnerabilities. Collaboration is key, as you'll often work with HR, compliance, and application owners to ensure users have the correct access while upholding security and privacy standards. This role provides a dynamic environment where problem-solving and proactive thinking are essential.

What are the most commonly searched types of Identity Access Management Engineer jobs in California? The most popular types of Identity Access Management Engineer jobs in California are:
What job categories do people searching Identity Access Management Engineer jobs in California look for? The top searched job categories for Identity Access Management Engineer jobs in California are:
Infographic showing various Identity Access Management Engineer job openings in California as of July 2026, with employment types broken down into 1% As Needed, 70% Full Time, 22% Part Time, and 7% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $150,773 per year, or $72.5 per hour.
Senior Identity Access Management Engineer

Senior Identity Access Management Engineer

Roku

San Jose, CA โ€ข Remote

$158K - $279K/yr

Other

Medical, Life, PTO

Posted 11 days ago


Job description

About role

Roku is seeking a senior-level Identity Engineer to enhance its Zero-Trust architecture, drive standardization initiatives, and optimize its Microsoft-centric identity platform for a geographically distributed workforce. The ideal candidate has hands-on experience in identity and access management (IAM) and securing cloud environments within the Microsoft ecosystem, with deep expertise in Azure Entra ID. Equally important is a strong automation mindset-designing, scripting, and building repeatable workflows. The role also requires the ability to communicate complex technical concepts clearly to both technical and non-technical audiences.ย 

For California Only - The estimated annual salary for this position is between $158,000 - $279,000 annually.ย  Compensation packages are based on factors unique to each candidate, including but not limited to skill set, certifications, and specific geographical location. This role is eligible for health insurance, equity awards, life insurance, disability benefits, parental leave, wellness benefits, and paid time off.

What you'll be doing
  • Lead enterprise-wide IAM standardization, including identity lifecycle, access governance, and policy enforcement across global regions.
  • Drive automation across IAM to streamline administration and deliver a smoother user experience.
  • Support enterprise applications onboarding into Azure Entra ID, including SSO, Conditional Access, and role-based access control (RBAC).
  • Enhance privileged access management and implement scalable monitoring, alerting, and auditability solutions to support a secure, geographically distributed workforce.
  • Collaborate with IT, Networking, and Security teams to troubleshoot identity-related issues and support global infrastructure initiatives.
  • Advance Zero Trust Identity Fabric principles like continuous verification, least-privilege access, and identity-aware policy enforcement across users, devices, workloads, and non-human identities.
  • Build identity automation with a DevOps mindset, writing scripts, developing pipelines, and engineering tooling from scratch rather than just configuring them.
We're excited if you have
  • 8+ years of hands-on experience with identity and access management and automating cloud technologies, particularly within the Microsoft ecosystem.
  • Strong analytical skills and attention to detail, with the ability to troubleshoot complex infrastructure and identity-related issues.
  • Excellent communication skills, with the ability to clearly explain technical concepts to both technical and non-technical stakeholders.
  • Deep experience with Microsoft Entra ID, including Conditional Access, Identity Governance, and Privileged Identity Management.
  • Familiarity with Microsoft 365 services: Exchange Online, Defender, Purview, Sentinel, Intune, and related platforms.
  • Automation and scripting skills using PowerShell, Azure CLI, and Microsoft Graph API; working knowledge of Azure services such as Function Apps and Logic Apps.
  • Experience in onboarding and managing enterprise applications in Azure Entra ID.
  • Advanced knowledge of Azure Single Sign-On (SSO) login methods, including OAuth2, OpenID Connect, and SAML, and their integration with enterprise applications.
  • Knowledge of privileged access tools (Azure PIM, CyberArk, etc), secrets management (HashiCorp or Azure Key Vault), and workload identity patterns SPIFEE & SPIRE.
  • Familiarity with NHI governance concepts for service accounts and AI agents, and exposure to OPA / Rego or similar policy-as-code frameworks.
  • Good to have familiarity with Microsoft Purview for DLP and data classification.
  • Strong understanding of multi-factor authentication and FIDO2.
  • Familiarity with IT security frameworks and compliance standards.
  • Knowledge of logging, monitoring, and alerting practices for identity and access events.
  • Basic understanding of email security and DNS.
  • Experience with backup and recovery strategies for identity-related services.
  • Understanding of Zero Trust Architecture principles.
  • Familiarity with Jira and Confluence.
  • B.S. in Computer Science, Information Technology, Engineering, or equivalent experience.ย 
#LI-RN1