What are the responsibilities and job description for the Security Engineer (Identity and Access Management) position at State of Wisconsin Investment Board?
Our Agency
Making a Difference
The State of Wisconsin Investment Board (SWIB), founded in 1951, is a premier global investment organization responsible for managing the more than $156 billion of assets of the fully funded Wisconsin Retirement System (WRS), the State Investment Fund and other state funds. Through SWIB’s effective and innovative investment management, WRS remains one of the only fully funded US public pensions. We are the 9th largest public pension fund in the U.S. and the 25th largest public or private pension fund in the world. SWIB is recognized by the investment industry for our teamwork and innovation. SWIB pursues sophisticated global investment strategies across the asset and risk allocation spectrum. Providers across the investment ecosystem seek to partner with
SWIB.
Serving more than 677,000 beneficiaries of the WRS, SWIB is a mission-driven organization focused on providing a strong financial future to those who committed their careers to public service. For public employees and the 1,500 Wisconsin employers who contribute on their behalf, we are a trusted partner. Our team innovates continuously to meet the challenges of an evolving investment landscape while growing and protecting the assets of the WRS.
SWIB provides a strong, steady economic pillar for the state of Wisconsin by growing the trust funds under its management, managing risk, and optimizing costs of the long term. We are a mission-driven organization and the participants we serve are our mission. By bringing a disciplined, prudent, and innovative approach to market opportunities, SWIB has been successful in generating required returns and maintaining the trust of the beneficiaries and stakeholders of the funds we oversee.
Home To Top Talent
Our high-performing staff is key to what makes us a premier investment manager. SWIB is committed to investing in talented professionals to implement our robust, sophisticated investment strategies and to keep the organization at the forefront of the investment industry. We encourage innovation and offer professional development opportunities to help staff sharpen and expand their skills. Approximately 61 percent of SWIB’s investment professionals are Chartered Financial Analyst (CFA) charterholders.
Position Overview:
As a Senior Security Engineer (Identity and Access Management), you will play a lead role in designing, implementing, and scaling SWIB’s identity and access management solutions and processes across our hybrid infrastructure. You will be responsible for ensuring secure and efficient access controls by leveraging IAM best practices. This role gives you the flexibility to shape your daily work, collaborating with a team that values your contributions and supports you in achieving the following responsibilities:
Essential activities:
- Deploy, administer, and enhance the following IAM tools:
- Identity Governance and Administration (IGA)
- Privileged Access Management (PAM)
- Endpoint Privilege Management (EPM)
- Configure and integrate applications into the IGA tool, managing provisioning, deprovisioning, and access certification processes.
- Design and leverage role-based access control (RBAC) and attribute-based access control (ABAC) to automate access provisioning.
- Lead periodic access reviews to ensure secure access across our hybrid infrastructure, including on-premise systems, cloud environments, and critical business applications.
- Implement SSO integrations using identity federation protocols such as SAML, OpenID, and OAuth to streamline user access.
- Drive continuous improvements for IAM processes and workflows, ensuring alignment with best practices and compliance frameworks (e.g., NIST CSF, Zero Trust).
- Report on metrics related to IGA, Active Directory (AD), and PAM to provide data-driven insights and support effective risk management.
- Support investigations of security incidents and provide timely responses.
The ideal candidate:
- 7 years of general information security experience with an emphasis on Identity and Access Management.
- Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent work experience).
- Hands-on experience implementing and administering SailPoint IdentityNow or a similar IGA tool.
- Strong working knowledge of AD/Entra ID and its associated services (authentication, authorization, Conditional Access Policies, multifactor authentication, etc.)
- Ability to lead and manage multiple ongoing tasks and projects.
- Strong analytical, communication, and project management skills.
- Deep understanding of IAM and security concepts, such as least privilege, just-in-time access, and zero-trust security model.
- Development experience with languages such as Java/BeanShell, Python, PowerShell, and working with JSON and REST APIs for automations and integrations.
SWIB Offers:
- Competitive total cash compensation, based on AON (formerly McLagan) industry benchmarks
- Comprehensive benefits package
- Educational and training opportunities
- Tuition reimbursement
- Challenging work in a professional environment
- Hybrid work environment
The position requires U.S. work authorization.
Pursuant to our Hybrid Remote Work Policy, all staff have the flexibility to work remotely but are required to have a weekly presence in our offices, the frequency of which is dependent on their distance from office. Staff are not required to reside locally; however, we offer relocation reimbursement to the Dane County area per our policy.
All SWIB employees are subject to SWIB’s Ethics Policy and Personal Trade Approvals Policy. These policies include restrictions on outside business activities and employment and have limits on personal