IAM Engineer
LEVI STRAUSS & CO
via workday
Apply on company site ↗
CareerRiver pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to LEVI STRAUSS & CO.
Calling all originals: At Levi Strauss & Co., you can be yourself — and be part of something bigger. We’re a company of people who like to forge our own path and leave the world better than we found it. Who believe that what makes us different makes us stronger. So add your voice. Make an impact. Find your fit — and your future.
We are looking for a well-rounded and hands-on IAM Engineer with experience in Saviynt IGA development and a solid foundation in Identity and Access Management principles including Authentication and Privileged Access Management. This role will be instrumental in supporting and evolving our global IAM platforms, driving identity governance, secure access, and regulatory compliance.
About the role:
Serve as the primary technical owner for enterprise Identity and Access Management (IAM) capabilities.
Design, implement, and maintain Microsoft identity services including: Microsoft Entra ID (Azure AD)
Multi-Factor Authentication (MFA)
Single Sign-On (SSO)
Conditional Access
OATH and passwordless authentication technologies
Privileged Identity Management (PIM)
Just-In-Time (JIT) access controls
Microsoft Defender for Identity
Lead engineering and operational activities for Privileged Access Management (PAM) platforms.
Drive Identity Governance and Administration (IGA) initiatives including access certifications, birthright provisioning, role management, segregation of duties, and lifecycle management.
Develop automation solutions to improve identity operations, security controls, and governance processes.
Integrate identity platforms with enterprise applications, cloud services, and security tooling.
Partner closely with Security Operations, Infrastructure, Cloud Engineering, HR, Internal Audit, and Application teams.
Define technical standards, architecture patterns, and roadmaps for identity security services.
Lead troubleshooting and resolution of complex identity-related incidents and escalations.
Required Qualifications: Microsoft Identity Security Expertise
Strong hands-on experience with:
Microsoft Entra ID
MFA and passwordless authentication
SSO federation technologies (SAML, OIDC, OAuth)
Conditional Access
OATH authentication methods
Privileged Identity Management (PIM)
Just-In-Time (JIT) administration
Microsoft Defender for Identity
Microsoft Graph API
Privileged Access Management (PAM)
Hands-on experience with at least one enterprise PAM platform:
Delinea (preferred)
CyberArk
BeyondTrust
Similar enterprise PAM solutions
Identity Governance & Administration (IGA)
Experience implementing and administering one or more:
Saviynt
SailPoint
Microsoft Identity Governance
Similar enterprise IGA platforms
Automation & Engineering
Strong scripting and automation experience with:
Python
PowerShell
KQL (Kusto Query Language)
Microsoft Graph
REST APIs
Preferred Qualifications: xperience securing hybrid Active Directory and cloud environments.
Experience supporting large global enterprises.
Familiarity with Zero Trust security principles.
Experience designing identity architectures at enterprise scale.
Knowledge of compliance frameworks and audit requirements.
Security certifications such as: SC-300
AZ-500
CISSP
Identity-focused Microsoft certifications
We are an Equal Opportunity Employer committed to empowering individuals from all walks of life to achieve their professional goals with us, regardless of race, religion, gender, gender identity, pregnancy, disability, sexual orientation, age, national origin, citizenship status, or genetic information. We actively seek and encourage applications from diverse candidates, including those with disabilities, and offer accommodations throughout the selection process upon request.
To ensure that our products and culture continue to incorporate everyone's perspectives and experience, we never discriminate based on race, religion, national origin, gender identity or expression, sexual orientation, age, or marital, veteran, or disability status.
LOCATION Mexico, D.F., Mexico FULL TIME/PART TIME Full time Current LS&Co Employees, apply via your Workday account.
Browse all locations