Senior IAM Engineer
Indexed description
About Sygnum
Sygnum is a global digital asset banking group, founded on Swiss and Singapore heritage. We empower professional and institutional investors, banks, corporates and DLT foundations to invest in digital assets with complete trust. Our team enables this through our institutional-grade security, expert personal service and portfolio of regulated digital asset banking, asset management, tokenization and B2B services.
In Switzerland, Sygnum holds a banking licence and has CMS and Major Payment Institution Licences in Singapore. The group is also regulated in the established global financial hubs of Abu Dhabi and Luxembourg.
We believe that the future has heritage. Our crypto-native team of banking, investment and digital asset technology professionals are building a trusted gateway between the traditional and digital asset economies that we call Future Finance. To learn more about how Sygnum’s mission and values are shaping this digital asset ecosystem, please visit sygnum.com and follow us on LinkedIn and X.
Our Values
A key pillar of our success are the Sygnum values that define and unite us a team. We proudly call them our SYGN values:
- S stands for the importance we hold in Seeking and seizing opportunities, and the way we take personal ownership for delivering results for our clients;
- Y represents the way we say Yes to maintaining the highest level of integrity and fairness in everything we do. Sygnumers always display confidence without attitude;
- G reminds us to always Grow and win together. We only succeed by supporting each other and challenging ourselves, and our team-mates, to reach for new heights;
- N is here for Nose for value because we are always looking to focus on what matters most to our clients, partners and team.
Sygnum has one of the most diverse teams in the industry. Diversity plays a central role in keeping our work culture open, our teams productive and energised, and our solutions at the forefront of the industry. In the spirit of our SYGN value to “grow and win together”, we fully embrace an equal opportunity mindset in the way we onboard, develop and promote our team members.
About the role
We're hiring a Senior IAM Engineer to run and grow our Microsoft-based identity platform. The role is weighted toward internal/workforce identity — built on Entra ID, automated with Terraform, and governed to FINMA standards — and also owns the service management of our client-facing identity platform. It's hands-on: you'll own technical delivery, architect solutions, and work across IT, Security, and the business to secure access to everything from corporate apps to custody platforms.
Internal / Workforce Identity (primary focus)
- Design and implement IAM architecture on Microsoft Entra ID — PIM, Conditional Access, entitlement and group management
- Automate identity and access policy with Terraform (IaC), integrating IAM changes into CI/CD pipelines with full auditability
- Lead Joiner-Mover-Leaver lifecycle automation: onboarding, deprovisioning, least privilege, and membership management
- Configure privileged access with PIM, Just-in-Time workflows, MFA, and access approvals
- Ensure Conditional Access aligns with device compliance (Intune) signals
- Drive IAM governance: access reviews, SoD analysis, entitlement attestation, and policy recertifications
- Own audit evidence — Terraform code, policy documentation, logs, and reporting ready for FINMA and internal audit
- Monitor IAM KPIs (provisioning times, review coverage, privileged sessions, policy violations) and report to leadership
- Track the Entra roadmap (Permissions Management, cross-tenant access) and drive adoption of relevant features
Client Identity (service management)
- Own the service management of the client-facing identity and access platform — configuration, releases and patching, availability, and platform lifecycle
- Manage the platform vendor relationship and support escalations
- Maintain client authentication and authorisation flows: MFA / step-up, self-service registration and recovery, and session policy
- Design and support federation and SSO integrations using SAML, OAuth2, and OpenID Connect for client-facing SaaS, third-party, and in-house applications
- Run client identity change management and incident handling within IT service management processes
Across both
- Work with SecOps and the SOC to feed identity events (privilege escalations, failed logins, anomalous access) into the SIEM and incident workflows
- Partner with HR, Risk & Compliance, and Platform Engineering to align identity controls with business and regulatory needs
Our ideal candidate
You're an experienced IAM engineer grounded in Microsoft identity, with a bias toward automation and clean access control. You're equally comfortable running internal Entra-based identity day to day and owning a client-facing identity platform as a managed service. You work well across IT, Security, and the business, and you're at home in a regulated environment where audit-readiness is part of the job.
Essential
- Bachelor's/Master's in Computer Science, Information Security, or equivalent
- 7+ years in IT, with 3+ years dedicated to IAM using Microsoft Entra ID/Azure AD
- Strong infrastructure-as-code experience (Terraform our target stack); applying it to identity and role policy an advantage
- Deep understanding of IAM principles: RBAC/ABAC, least privilege, zero trust, Conditional Access, and privilege management
- Experience integrating IAM with CI/CD pipelines and infrastructure-as-code
- Working knowledge of privileged access tooling, MFA, SSO, and entitlement management
- Hands-on with federation protocols — SAML, OAuth2, and OpenID Connect
- Solid awareness of the regulatory landscape (FINMA, ISO 27001, NIST) and audit-readiness practices
- Excellent stakeholder communication in English; German a plus
Desirable
- Experience operating or service-managing a customer identity (CIAM) / external access platform
- IT service management experience (incident, change, vendor management)
- Azure B2B/B2C and custom SAML/OpenID Connect app integrations
- Certifications: CISSP, CISM, Azure Security Engineer, or Microsoft Identity certifications
Our Offer
Joining Sygnum means being part of a dynamic, global team that is building a trusted gateway between the traditional and digital asset economies. Working at Sygnum, you will experience our fast-paced, exciting work environment that embraces meritocracy and collaboration and open communication. Alongside our ambitious long-term mission, we also come together for reaching important milestones and annual crypto-industry anniversaries like Bitcoin Pizza Day, and regularly celebrate together at themed company events as part of our journey to shape Future Finance.
Sygnum offers a comprehensive package of benefits for all team members. They include:
- Attractive combination of market salaries and entrepreneurial incentive scheme
- Flexible/Work at home policies
- Professional development via Mentoring and Buddy programs
- One-month fully paid sabbatical after five years of continuous employment
If you are passionate about the potential of blockchain to shape Future Finance and your profile is a good fit for this position, please send us your CV today!
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search