The Lead IAM Quality Assurance Engineer is responsible for ensuring the quality, security, and compliance of Identity and Access Management (IAM) solutions across enterprise applications and platforms. This role partners with IAM architects, security engineers, product owners, and application teams to validate authentication, authorization, and access governance capabilities. The ideal candidate has strong expertise in IAM technologies, security testing, and test automation, with a deep understanding of RBAC, ABAC, and PBAC models. This position plays a key role in ensuring that IAM solutions meet business, regulatory, and security requirements while delivering a seamless user experience.
Req#1060218352
The recruiting efforts for this position are intended to fill an existing vacancy for a new position.
Responsibilities
- Lead end-to-end QA strategy, planning, and execution for IAM platforms and security solutions
- Design, develop, and maintain test plans, test cases, and automation frameworks to ensure comprehensive test coverage
- Validate IAM capabilities, including SSO, MFA, Federation (SAML, OIDC, OAuth 2.0), Identity Lifecycle Management, and Access Governance
- Test and verify authorization models (RBAC, ABAC, PBAC) and validate PDP/PEP integrations and policy enforcement
- Perform API, integration, regression, and end-to-end testing across IAM systems and security applications
- Verify provisioning, deprovisioning, role management, entitlement management, access reviews, and certification processes while managing defects through resolution and root cause analysis
- Collaborate with business, security, architecture, and engineering teams to support compliance requirements, ensure high-quality deliverables, and drive successful UAT execution
Requirements
- 6+ years of QA/QE experience, including 3+ years supporting Identity & Access Management (IAM), cybersecurity, or identity governance initiatives
- Hands-on experience with IAM platforms such as Ping Identity, ForgeRock, Okta, SailPoint, Saviynt, CyberArk, or Microsoft Entra ID
- Strong knowledge of authentication, federation, and access management concepts, including SSO, MFA, access governance, and privileged access management
- Proven experience validating authorization models and access control workflows, including RBAC, ABAC, and PBAC
- Solid understanding of identity and security protocols such as SAML, OAuth 2.0, OIDC, LDAP, and SCIM
- Familiarity with API testing and validation using tools such as Postman, REST Assured, or Swagger
- Knowledge of policy-based authorization technologies, including OPA, Cedar, or XACML
- Exposure to Zero Trust security frameworks and modern access management practices
- Experience working within CI/CD pipelines and DevSecOps environments