Über diese Senior IAM Engineer Stelle bei FanDuel
THE POSITION
Our roster has an opening with your name on it
FanDuel is seeking an Identity and Access Management (IAM) Engineer to join its Enterprise Identity Engineering team as a technical specialist driving identity governance and access control across the organization. This role offers a unique opportunity to architect and implement identity solutions that strengthen our security posture while enabling seamless business operations. The ideal candidate brings hands-on expertise in modern identity platforms, cloud infrastructure, and the IAM lifecycle—understanding not just how to provision users, but how to architect scalable access frameworks, automate identity workflows, and ensure compliance through intelligent access controls.
At its core, this role is about designing and operationalizing a unified Identity and Access Management architecture for FanDuel. You will be instrumental in designing identity governance frameworks that ensure the right people have the right access to the right resources at the right time. You'll architect and manage authentication and authorization solutions across our cloud platforms, applications, and infrastructure, ensuring both security and user experience. Beyond implementation, you'll establish standards, procedures, and automation that keep our IAM program running efficiently and adapting to evolving business and security needs.
In addition to the specific responsibilities outlined above, employees may be required to perform other such duties as assigned by the Company. This ensures operational flexibility and allows the Company to meet evolving business needs.
THE GAME PLAN
Everyone on our team has a part to play
- Design and implement a comprehensive Identity and Access Management architecture that spans cloud platforms (AWS), SaaS applications, infrastructure, and on-premises systems, ensuring alignment with FanDuel's security frameworks and industry best practices (NIST, CSA CCM, SOC2, PCI-DSS, GLI-GSF)
- Drive the complete IAM lifecycle—including identity schema design, user provisioning and deprovisioning workflows, access request and approval processes, periodic access reviews and recertification, and identity governance automation with an efficiency-first mindset
- Architect and implement multi-factor authentication (MFA), single sign-on (SSO), and identity federation solutions across diverse platforms and applications to balance security with user experience
- Develop and maintain IAM automation—leveraging APIs, infrastructure-as-code, and workflow orchestration platforms—to scale access management while reducing manual overhead and human error
- Drive Terraform adoption for identity infrastructure-as-code management, implementing version-controlled CI/CD pipelines across Okta, C1, and other identity platforms
- Build continuous identity monitoring and analytics capabilities to detect access anomalies, privilege escalation risks, and unauthorized activities; respond to identity-related security incidents with forensic analysis and remediation
- Build and maintain custom application connectors to support JML (Joiner, Mover, Leaver) lifecycle flows, integrating identity data with HR systems, HRIS platforms, and other business applications to automate onboarding, access changes, and offboarding processes
- Manage authentication and authorization mechanisms across AWS IAM, Okta, C1 GitHub, Atlassian, and other critical systems, ensuring consistent policy enforcement and audit capabilities
- Manage Okta device access controls to enhance security posture and improve user login experience, including device compliance policies, platform integrity monitoring, and risk-based access decisions
- Lead organization-wide FIDO2 security key deployment, partnering with IT support and end-users to ensure proper configuration, adoption, and ongoing management of passwordless authentication across the enterprise
- Establish and maintain identity governance policies, standards, procedures, and technical controls; ensure alignment with enterprise security principles and regulatory requirements
- Partner with Security, Infrastructure, and Application teams to conduct access requirements analysis, design role-based access control (RBAC) and attribute-based access control (ABAC) models, and implement least-privilege principles across technology platforms
- Support the rollout of the AI Agent Governance lifecycle across the organization, encompassing Discovery of AI agents, Onboarding of agents into governance systems, Protecting agents through identity and access controls, and establishing ongoing Governance mechanisms to ensure compliance, security, and operational accountability
- Maintain comprehensive documentation, runbooks, technical playbooks, dashboards, and metrics for identity governance health and access risk posture
- Stay abreast of evolving identity security threats, IAM technologies, and regulatory changes; evaluate and recommend new identity platforms, technologies, and approaches to enhance security and efficiency
- Partner with FanDuel's identity governance and other brands' security teams to align standards and drive efficiencies across the enterprise
- Share knowledge and best practices with team members, contributing to the development of team IAM expertise and promoting continuous improvement across the security engineering function
THE STATS
What we're looking for in our next teammate
- Bachelor's degree preferred in Computer Science, Information Security, or related technical field, or equivalent combination of education, training, and relevant experience.
- 5+ years of hands-on IAM engineering and implementation experience across cloud, hybrid, and on-premises environments.
- Strong proficiency with modern identity platforms including AWS IAM, Azure AD/Entra ID, Okta, and LDAP/Active Directory.
- Hands-on experience with authentication mechanisms (OAuth 2.0, SAML, OIDC, etc.), MFA implementation, and Single Sign-On (SSO) architecture.
- Experience designing and implementing role-based access control (RBAC) and attribute-based access control (ABAC) models aligned to business requirements.
- Hands-on experience with identity provisioning tools, user lifecycle management, and workflow automation platforms (e.g., Okta Workflows, MuleSoft, custom API development).
- Solid programming and scripting skills (Python, Bash, Go, or similar) to automate identity tasks and integrate systems via APIs.
- Experience implementing and managing identity governance programs including access reviews, segregation of duties, and continuous access monitoring.
- Proficiency with cloud platforms (AWS, Azure, or GCP) and their native IAM/identity services.
- Experience architecting and implementing MFA and passwordless authentication solutions.
- Knowledge of identity security best practices, frameworks, and standards including NIST SP 800-63, NIST CSF, Zero Trust principles, and compliance requirements (SOC2, PCI-DSS, GLI-GSF).
- Familiarity with DevOps practices, infrastructure-as-code (Terraform, CloudFormation), and CI/CD pipelines as they relate to identity and access automation.
- Experience integrating identity solutions with SaaS applications, GitHub, Atlassian products, and other critical enterprise software.
- Excellent troubleshooting and problem-solving skills with ability to debug complex identity-related issues across distributed systems.
- Strong written and verbal communication skills to articulate IAM concepts to both technical and non-technical stakeholders.
- "Stay Hungry, Stay Humble" mindset that strives to continuously learn new identity technologies and share knowledge with others, embracing the rapid evolution of the IAM landscape.
- "Anything Is Possible" attitude that is highly organized and results-driven to architect and implement IAM solutions that solve critical security challenges.
- Comfortable navigating shifting priorities in a fast-paced environment, with the ability to work independently on architectural challenges while excelling as a collaborative team player who promotes knowledge sharing and cohesiveness.
- Relevant professional certifications such as CISSP, CISM, IAM specialist certifications (Okta, AWS, Azure, or similar), or industry-recognized IAM credentials are preferred.
- Experience working as a consultant or in senior IAM roles in regulated industries is a plus.
ABOUT FANDUEL
FanDuel Group is the premier mobile gaming company in the United States and Canada. FanDuel Group consists of a portfolio of leading brands across mobile wagering including: America’s #1 Sportsbook, FanDuel Sportsbook; its leading iGaming platform, FanDuel Casino; the industry’s unquestioned leader in horse racing and advance-deposit wagering, FanDuel Racing; and its daily fantasy sports product.
In addition, FanDuel Group operates FanDuel TV, its broadly distributed linear cable television network and FanDuel TV+, its leading direct-to-consumer OTT platform. FanDuel Group has a presence across all 50 states, Canada, and Puerto Rico.
The company is based in New York with US offices in Los Angeles, Atlanta, and Jersey City, as well as global offices in Canada and Scotland. The company’s affiliates have offices worldwide, including in Ireland, Portugal, Romania, and Australia.
FanDuel Group is a subsidiary of Flutter Entertainment, the world's largest sports betting and gaming operator with a portfolio of globally recognized brands and traded on the New York Stock Exchange (NYSE: FLUT).
PLAYER BENEFITS
We treat our team right
We offer amazing benefits above and beyond the basics. We have an array of health plans to choose from (some as low as $0 per paycheck) that include programs for fertility and family planning, mental health support, and fitness benefits. We offer generous paid time off (PTO & sick leave), annual bonus and long-term incentive opportunities (based on performance), 401k with up to a 5% match, commuter benefits, pet insurance, and more - check out all our benefits here: FanDuel Total Rewards. *Benefits differ across location, role, and level.
FanDuel is an equal opportunities employer and we believe, as one of our principles states, “We are One Team!”. As such, we are committed to equal employment opportunity regardless of race, color, ethnicity, ancestry, religion, creed, sex, national origin, sexual orientation, age, citizenship status, marital status, disability, gender identity, gender expression, veteran status, or any other characteristic protected by state, local or federal law. We believe FanDuel is strongest and best able to compete if all employees feel valued, respected, and included.
FanDuel is committed to providing reasonable accommodations for qualified individuals with disabilities. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please email [email protected].
The applicable salary range for this position is $138,000 - 173,000 USD, which is dependent on a variety of factors including relevant experience, location, business needs and market demand. This role may offer the following benefits: medical, vision, and dental insurance; life insurance; disability insurance; a 401(k) matching program; among other employee benefits. This role may also be eligible for short-term or long-term incentive compensation, including, but not limited to, cash bonuses and stock program participation. This role includes paid personal time off and 14 paid company holidays. FanDuel offers paid sick time in accordance with all applicable state and federal laws.
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
#LI-Hybrid