RVC
JobsFor Employers
  1. Jobs
  2. /
  3. Lead Associate Engineer, Identity and Access Management

Lead Associate Engineer, Identity and Access Management

becn | Building products distribution and installation
1h 21m ago
On-site
Full Time
IC
United States of America
$101.3k - $172k USD/yr

As a Lead Associate Engineer, Identity and Access Management at QXO, you'll serve as the recognized subject matter expert leading the engineering behind QXO's new Identity Governance and Automation (IGA) program: a greenfield deployment, from connectors and provisioning workflows through access certification, with no legacy platform to inherit or migrate from. The role is expected to grow into a broader IAM remit — including coaching and reviewing the work of other IAM engineers — as QXO's identity portfolio expands.

QXO is a leading distributor and installer of building products serving an $800 billion market. The company’s mission is to modernize the building products industry through advanced technology and a best-in-class customer experience. QXO is North America’s largest distributor and installer of insulation, the second-largest distributor of roofing products, the second-largest publicly traded distributor of lumber and building materials, and the largest distributor of waterproofing products. The company is targeting $50 billion in annual revenue within the decade through accretive acquisitions and organic growth. For more information, visit QXO.com.


What you'll do:
  • Push automation as the default: treat every manual, ticket-driven, or spreadsheet-based step as something to simplify, standardize, and automate — not a process to maintain.
  • Implement and configure QXO's selected IGA platform including connectors, provisioning logic, and workflow automation.
  • Build automated joiner-mover-leaver (JML) workflows that connect authoritative HR data to birthright and requestable access across target systems.
  • Design and build integrations to target systems where out-of-the-box connectors don't already cover the gap.
  • Configure segregation-of-duties (SoD) detection rules and access-certification campaign workflows, and build the audit trail and reporting these depend on.
  • Serve as the subject matter expert and technical partner to Infrastructure, Engineering, Enterprise Applications, and HR Ops on integration points as the program scales.
  • Serve as the liaison to GRC and the broader Cybersecurity team on risk remediation, hardening, and control issues that surface in the IGA platform, partnering to resolve them as they arise.
  • Stay engaged with QXO's broader identity landscape — access management, privileged access management, and directory services — as the identity portfolio ownership expands beyond IGA.
  • Take a POC/POV-validated design into production build-out — standing up the platform, connectors, and workflows for the first time, with no legacy IGA system to unwind.
  • Deliver IGA build work on time and within scope, translating business-unit access requirements directly into automated workflows rather than one-off manual accommodations.
  • Document configuration decisions, policy exceptions, and workflow logic clearly enough that automation is auditable and repeatable, not tribal knowledge.
  • Drive the technical direction of the IGA program as a large-scale, cross-functional engineering initiative with limited oversight from the Director, architecting the connectors, workflows, and integration build-out.
  • Coach, review, and delegate work to other IAM engineers and analysts, ensuring quality and consistency in configuration and design decisions as the team scales.

What you'll bring:
  • 10+ years of hands-on IAM/IGA engineering experience, with the depth to serve as a recognized subject matter expert configuring and building on an IGA/IAM platform (Saviynt, SailPoint, Linx, or similar) — not just administering it.
  • Experience building or configuring connectors and integrations: SCIM, REST/SOAP APIs, or a vendor connector framework.
  • Solid understanding of identity lifecycle (JML) processes, RBAC/role modeling, and segregation-of-duties concepts.
  • A holistic understanding of IAM beyond governance — access management, privileged access management (PAM), and directory services — and how they interlock with IGA.
  • Scripting or automation ability (Python, PowerShell, or similar) for custom integration and provisioning logic.
  • Strong cross-functional communication; you'll work directly with HR, Enterprise Applications, Infrastructure, and Engineering stakeholders, not just other security engineers.
  • Experience coaching, reviewing, and delegating work to less-experienced engineers, with sound judgment on when to guide versus when to step in directly.
  • Demonstrated ability to solve difficult and often complex, ambiguous problems in identity infrastructure and access controls with limited precedent to draw on, applying least-privilege thinking as a default rather than an afterthought.
  • Preferred: experience standing up a greenfield IAM/IGA deployment — building a program from zero rather than extending or migrating an existing one — including working alongside managed-services or implementation partners during a POC/POV phase.
  • Preferred: awareness of non-human identity (NHI) and agentic AI access-control concepts. QXO's identity program will eventually extend to governing machine and AI-agent identities as that footprint grows — applicants should be able to speak to how least privilege, certification, and SoD principles extend to non-human actors.

What you'll earn
  • Base pay range: $101,300 - $172,000
  • Annual performance bonus
  • 401(k) with employer match
  • Medical, dental, and vision insurance
  • PTO, company holidays, and parental leave
  • Paid Time Off/Paid Sick Leave: Applicants can expect to accrue 15 days of paid time off during their first year (4.62 hours for every 80 hours worked) and increased accruals after five years of service.
  • Paid training and certifications
  • Legal assistance and identity protection
  • Pet insurance
  • Employee assistance program (EAP)

To comply with Pay Transparency laws, employers must disclose an annual salary range. Actual offers depend on factors such as location, experience, skills, and market data. This position may also offer variable compensation.

QXO is an Equal Opportunity Employer. We value diversity and do not discriminate on the basis of race, color, religion, gender or sexual orientation, national origin, age, disability, or any other protected status.


Salary Range:

USD $101,300.00 - USD $172,000.00 /Yr.
  • Push automation as the default: treat every manual, ticket-driven, or spreadsheet-based step as something to simplify, standardize, and automate — not a process to maintain.
  • Implement and configure QXO's selected IGA platform including connectors, provisioning logic, and workflow automation.
  • Build automated joiner-mover-leaver (JML) workflows that connect authoritative HR data to birthright and requestable access across target systems.
  • Design and build integrations to target systems where out-of-the-box connectors don't already cover the gap.
  • Configure segregation-of-duties (SoD) detection rules and access-certification campaign workflows, and build the audit trail and reporting these depend on.
  • Serve as the subject matter expert and technical partner to Infrastructure, Engineering, Enterprise Applications, and HR Ops on integration points as the program scales.
  • Serve as the liaison to GRC and the broader Cybersecurity team on risk remediation, hardening, and control issues that surface in the IGA platform, partnering to resolve them as they arise.
  • Stay engaged with QXO's broader identity landscape — access management, privileged access management, and directory services — as the identity portfolio ownership expands beyond IGA.
  • Take a POC/POV-validated design into production build-out — standing up the platform, connectors, and workflows for the first time, with no legacy IGA system to unwind.
  • Deliver IGA build work on time and within scope, translating business-unit access requirements directly into automated workflows rather than one-off manual accommodations.
  • Document configuration decisions, policy exceptions, and workflow logic clearly enough that automation is auditable and repeatable, not tribal knowledge.
  • Drive the technical direction of the IGA program as a large-scale, cross-functional engineering initiative with limited oversight from the Director, architecting the connectors, workflows, and integration build-out.
  • Coach, review, and delegate work to other IAM engineers and analysts, ensuring quality and consistency in configuration and design decisions as the team scales.

  • 10+ years of hands-on IAM/IGA engineering experience, with the depth to serve as a recognized subject matter expert configuring and building on an IGA/IAM platform (Saviynt, SailPoint, Linx, or similar) — not just administering it.
  • Experience building or configuring connectors and integrations: SCIM, REST/SOAP APIs, or a vendor connector framework.
  • Solid understanding of identity lifecycle (JML) processes, RBAC/role modeling, and segregation-of-duties concepts.
  • A holistic understanding of IAM beyond governance — access management, privileged access management (PAM), and directory services — and how they interlock with IGA.
  • Scripting or automation ability (Python, PowerShell, or similar) for custom integration and provisioning logic.
  • Strong cross-functional communication; you'll work directly with HR, Enterprise Applications, Infrastructure, and Engineering stakeholders, not just other security engineers.
  • Experience coaching, reviewing, and delegating work to less-experienced engineers, with sound judgment on when to guide versus when to step in directly.
  • Demonstrated ability to solve difficult and often complex, ambiguous problems in identity infrastructure and access controls with limited precedent to draw on, applying least-privilege thinking as a default rather than an afterthought.
  • Preferred: experience standing up a greenfield IAM/IGA deployment — building a program from zero rather than extending or migrating an existing one — including working alongside managed-services or implementation partners during a POC/POV phase.
  • Preferred: awareness of non-human identity (NHI) and agentic AI access-control concepts. QXO's identity program will eventually extend to governing machine and AI-agent identities as that footprint grows — applicants should be able to speak to how least privilege, certification, and SoD principles extend to non-human actors.

Required Skills

scimrestapisoappythonpowershell

Required Languages

🇬🇧 English

Related searches

  • Jobs in USA
  • Senior Jobs
1 jobs
Sort by
1h 21m ago

Lead Associate Engineer, Identity and Access Management

becn·Building products distribution and installation
$101.3k - $172k USD/yr
scimrestapisoappythonpowershell
🏢On-site
|United States of America
General InfoSec
No similar jobs match these filters. Try changing or clearing a filter.
Remote roles
PythonJavaReactGoDevOpsNode.jsC# / .NET
Countries
United StatesUnited KingdomCanadaUS & EMEAGermanyPolandSpainNetherlandsPortugal
Experience
SeniorMid-levelJunior
R© 2026 RVC Globalbuild 1a9371bf
AboutMCPPricingContactPrivacyCookiesRefundsTerms & ConditionsFor Employers