Identity & Access Management (IAM)
As companies pile on more SaaS apps, cloud accounts, and remote employees, controlling who can get into what has become one of the fastest-growing corners of the field, from day-to-day access requests up through privileged access, governance, and full identity architecture.
Customer IAM (CIAM)Machine & Non-Human Identity SecurityIdentity Threat Detection & Response (ITDR)Directory Services
IAM Engineer
You build and wire up the systems that create, authenticate, and retire every identity in the company.
What it's about & how to get in
You configure identity providers (Okta, Entra ID, Ping, etc.), build provisioning/de-provisioning workflows, set up SSO integrations via SAML/OIDC, script automation for identity lifecycle tasks, and troubleshoot authentication failures across dozens of connected applications.
Most people arrive here from systems/software engineering or general IT administration, then specialize in identity. It sits next to PAM Engineer and IAM Analyst, and is a common path toward IAM Architect.
Where you can work
- Enterprise IT/security teams building out internal IAM platforms
- SaaS companies building customer-facing identity (CIAM) systems
- MSSPs and managed identity service providers
- Consulting firms implementing Okta/Entra ID/SailPoint for clients
- Financial services and healthcare organizations
- Large tech companies with in-house identity platforms
What it pays
Certifications that open doors
Where you can actually learn it
IAM Analyst
You manage the day-to-day access requests, reviews, and audits that keep 'who can access what' under control.
What it's about & how to get in
You process access requests and approvals, run periodic access certifications, investigate segregation-of-duties conflicts, maintain role/entitlement catalogs, and pull evidence for internal and external audits.
This is often the entry point into IAM, hired from help desk, systems administration, or general IT support. It leads naturally into IAM Engineer or Identity Governance & Administration (IGA) Analyst roles.
Where you can work
- Enterprise IAM/security teams
- Banks, insurers, and other heavily audited financial institutions
- Healthcare systems managing HIPAA-driven access controls
- MSSPs and identity-as-a-service providers
- Government agencies
- Large retail and manufacturing companies
What it pays
Certifications that open doors
Where you can actually learn it
Privileged Access Management (PAM) Engineer
You lock down the 'keys to the kingdom' — admin and service accounts — with vaulting, rotation, and just-in-time access.
What it's about & how to get in
You deploy and manage PAM platforms, onboard privileged and service accounts into a credential vault, configure session recording and automatic password rotation, set up just-in-time elevation, and integrate PAM with IAM and SIEM tooling for alerting on misuse.
People usually move into this from systems administration or IAM engineering, since it requires deep knowledge of both operating systems/infrastructure and identity concepts. It's closely tied to IAM Engineer and often reports into the same team.
Where you can work
- Enterprises with regulatory PAM requirements (banking, healthcare, critical infrastructure)
- MSSPs offering managed PAM services
- Large IT organizations with significant admin-account sprawl
- Consulting/implementation partners for PAM platforms
- Government and defense contractors
What it pays
Certifications that open doors
Where you can actually learn it
Identity Governance & Administration (IGA) Analyst
You run the access-certification campaigns and role models that prove people only have the access they need.
What it's about & how to get in
You configure identity governance platforms, run periodic access-certification campaigns for managers to review, define birthright and role-based access models, and pull evidence to support SOX, HIPAA, or other regulatory audits.
This role usually grows out of an IAM Analyst position once someone specializes in the governance/compliance side of identity rather than day-to-day provisioning. It feeds toward IAM Architect or GRC-focused roles.
Where you can work
- Regulated enterprises: banking, insurance, healthcare, pharma
- Consulting firms implementing identity governance platforms
- MSSPs with governance/compliance practices
- Government agencies
- Large enterprises undergoing SOX or HIPAA audit remediation
What it pays
Certifications that open doors
Where you can actually learn it
Identity & Access Management Architect
You design the enterprise-wide identity strategy spanning SSO, MFA, governance, and privileged access.
What it's about & how to get in
You design the organization's target-state IAM architecture, evaluate and select IAM/PAM/IGA vendors, set integration standards for SSO and MFA across applications, and advise engineering teams so every new system is built identity-aware from day one.
This is a senior role reached from IAM Engineer or a general security architect track, usually 8+ years in. It works closely with the CISO's office and enterprise architecture team, sitting above IAM Engineer, PAM Engineer, and IGA Analyst.
Where you can work
- Large enterprises running multi-year IAM transformation programs
- Consulting firms (Big 4 and boutique IAM specialty shops)
- Financial services and healthcare systems
- Government agencies modernizing identity infrastructure
- Large SaaS/tech companies building enterprise-grade identity platforms