Senior IAM Engineer
FanDuel · Atlanta, Georgia, United States
📍 Atlanta, Georgia, United States💰 $138,000 - 173,000via greenhousePosted 2026-09-14
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to FanDuel.
THE POSITION
Our roster has an opening with your name on it
FanDuel is seeking an Identity and Access Management (IAM) Engineer to join its Enterprise Identity Engineering team as a technical specialist driving identity governance and access control across the organization. This role offers a unique opportunity to architect and implement identity solutions that strengthen our security posture while enabling seamless business operations. The ideal candidate brings hands-on expertise in modern identity platforms, cloud infrastructure, and the IAM lifecycle—understanding not just how to provision users, but how to architect scalable access frameworks, automate identity workflows, and ensure compliance through intelligent access controls.
At its core, this role is about designing and operationalizing a unified Identity and Access Management architecture for FanDuel. You will be instrumental in designing identity governance frameworks that ensure the right people have the right access to the right resources at the right time. You'll architect and manage authentication and authorization solutions across our cloud platforms, applications, and infrastructure, ensuring both security and user experience. Beyond implementation, you'll establish standards, procedures, and automation that keep our IAM program running efficiently and adapting to evolving business and security needs.
In addition to the specific responsibilities outlined above, employees may be required to perform other such duties as assigned by the Company. This ensures operational flexibility and allows the Company to meet evolving business needs.
THE GAME PLAN
Everyone on our team has a part to play
Design and implement a comprehensive Identity and Access Management architecture that spans cloud platforms (AWS), SaaS applications, infrastructure, and on-premises systems, ensuring alignment with FanDuel's security frameworks and industry best practices (NIST, CSA CCM, SOC2, PCI-DSS, GLI-GSF)
Drive the complete IAM lifecycle—including identity schema design, user provisioning and deprovisioning workflows, access request and approval processes, periodic access reviews and recertification, and identity governance automation with an efficiency-first mindset
Architect and implement multi-factor authentication (MFA), single sign-on (SSO), and identity federation solutions across diverse platforms and applications to balance security with user experience
Develop and maintain IAM automation—leveraging APIs, infrastructure-as-code, and workflow orchestration platforms—to scale access management while reducing manual overhead and human error
Drive Terraform adoption for identity infrastructure-as-code management, implementing version-controlled CI/CD pipelines across Okta, C1, and other identity platforms
Build continuous identity monitoring and analytics capabilities to detect access anomalies, privilege escalation risks, and unauthorized activities; respond to identity-related security incidents with forensic analysis and remediation
Build and maintain custom application connectors to support JML (Joiner, Mover, Leaver) lifecycle flows, integrating identity data with HR systems, HRIS platforms, and other business applications to automate onboarding, access changes, and offboarding processes
Manage authentication and authorization mechanisms across AWS IAM, Okta, C1 GitHub, Atlassian, and other critical systems, ensuring consistent policy enforcement and audit capabilities
Manage Okta device access controls to enhance security posture and improve user login experience, including device compliance policies, platform integrity monitoring, and risk-based access decisions
Lead organization-wide FIDO2 security key deployment, partnering with IT support and end-users to ensure proper configuration, adoption, and ongoing management of passwordless authentication across the enterprise
Establish and maintain identity governance policies, standards, procedures, and technical controls; ensure alignment with enterprise security principles and regulatory requirements
Partner with Security, Infrastructure, and Application teams to conduct access requirements analysis, design role-based access control (RBAC) and attribute-based access control (ABAC) models, and implement least-privilege principles across technology platforms
Support the rollout of the AI Agent Governance lifecycle across the organization, encompassing Discovery of AI agents, Onboarding of agents into governance systems, Protecting agents through identity and access controls, and establishing ongoing Governance mechanisms to ensure compliance, security, and operational accountability
Maintain comprehensive documentation, runbooks, technical playbooks, dashboards, and metrics for identity governance health and access risk posture
Stay abreast of evolving identity security threats, IAM technologies, and regulatory changes; evaluate and recommend new identity platforms, technologies, and approaches to enhance security and efficiency
Partner with FanDuel's identity governance and other brands' security teams to align standards and drive efficiencies across the enterprise
Share knowledge and best practices with team members, contributing to the development of team IAM expertise and promoting continuous improvement across the security engineering function
THE STATS
What we're looking for in our next teammate
Bachelor's degree preferred in Computer Science, Information Security, or related technical field, or equivalent combination of education, training, and relevant experience.
5+ years of hands-on IAM engineering and implementation experience across cloud, hybrid, and on-premises environments.
Strong proficiency with modern identity platforms including AWS IAM, Azure AD/Entra ID, Okta, and LDAP/Active Directory.
Hands-on experience with authentication mechanisms (OAuth 2.0, SAML, OIDC, etc.), MFA implementation, and Single Sign-On (SSO) arch
Browse all locations