Technical Report MTF-CF-RR-2026-10-06-IAM | United States | Evidence observed 6 October 2026
Executive summary
Identity and access management (IAM) work in this study sits between reliable service operations, security controls and changes to the systems that give people and services access. The 108 U.S. vacancy advertisements examined on 6 October 2026 describe practitioners who provision and remove access, maintain identity data and integrations, administer authentication, run governance and privileged-access controls, investigate failures, and leave usable records for approvers, support teams and auditors. Those activities appear in different combinations. An analyst resolving access requests is doing related work to an engineer building a lifecycle connector, but the engineer's design authority and experience requirements should not be assigned to the analyst.
This is a structured purposive sample of advertisements available at one observation point, assembled from employer career pages, authorized application systems and public recruiting marketplaces. It supports a detailed account of what these sampled employers and recruiters described. It does not estimate the share of all U.S. IAM jobs that require any one skill. A current application control shows that a public route to apply existed when observed; it cannot establish that an employer was interviewing, that a position was funded, or that the page remains open after the observation date.
The strongest practical lesson from the sample is that IAM is work on a controlled service, not simply familiarity with a product name. The service needs a trustworthy identity source, a request and approval path, a provisioned or changed entitlement, checks for excessive or failed access, and a record that someone else can understand. The precise systems, approval rules, and authority differ by employer. MUFG's analyst posting emphasizes automation and reporting; Jupiter Medical Center's analyst posting combines lifecycle work, access certification, application onboarding and audit support; Southern New Hampshire University's engineer posting joins platform operations, access workflows, documentation and third-level support.
Study question and method
The question was: What work products, actions and capabilities do current U.S. enterprise IAM practitioner vacancies describe? The sample covers dedicated IAM analysts, administrators, engineers, specialists, architects and managers whose principal work is operating, governing or implementing identity services. It includes workforce identity, identity governance and administration (IGA), authentication and federation, privileged access management (PAM), machine identities and relevant customer identity work. Student internships, identity-product software development for sale to customers, product sales, physical-access-only work, generic security roles with incidental IAM, non-U.S. positions, closed pages and postings without a verifiable individual job description were excluded from the principal sample.
Three collection segments searched employer names A–M, employers N–Z, and an additional group of public universities and health systems. Search results identified leads; the evidence was the individual vacancy description and its observed application state. The final set has 108 distinct advertisements from 69 named employers or recruiters: 50 from the first segment, 47 from the second and 11 from the sector supplement. Eighty-nine were on first-party employer, authorized application or direct staffing/consultancy pages; 19 were live public marketplace advertisements. The latter add role variety but have a weaker view of the underlying client's hiring state. One closed employer page was removed after a live closure check overrode earlier cached text. Multi-location copies and identifiable syndicated copies were counted once. Unnamed staffing clients still prevent perfect detection of the same end-client opening advertised by different agencies.
Each included description was coded for duties, work products, technical methods, observable workplace behavior, systems, education and experience, required and preferred criteria, seniority, cadence, interfaces, decision authority and escalation. Where the advertisement did not say, the field remains not stated. An unmentioned weekly review, for example, is missing information rather than evidence that the review never happens. A product listed among preferred alternatives is a tool mention, not proof of a mandatory duty or a hiring minimum. Reported numbers count advertisements, not positions filled or people hired.
Location was checked against the role description, not inferred from a website locale. Some postings have several eligible U.S. locations or remote work limited to named states. One marketplace advertisement has a U.S. city in its header that differs from the U.S. city in its body; it contributes to the U.S. sample but supports neither city-specific inference. Relative posting ages were preserved as relative labels. An updated marketplace timestamp was not treated as a newly created vacancy. Individual coding retains a link to each underlying description.
Explicit workstream mentions in the sample
The table counts an advertisement only when its coded duty or output text explicitly mentions the workstream. Hiring criteria, tool lists, titles and preferred alternatives do not trigger these counts. Governance includes access review, role design and audit-support work; documentation includes reports, records, metrics, procedures and policy outputs. The labels are deliberately broad, so a count describes this coding scheme and this sample, not a share of all U.S. jobs. A record may appear in several rows.
| Workstream in duties or outputs | Full sample, n=108 | Without IdentityLogic Consulting, n=97 | Source examples |
|---|---|---|---|
| Identity lifecycle and access fulfillment | 45 | 43 | Cognizant, UC San Diego Health |
| Governance, reviews, roles and audit support | 55 | 50 | State Street, Jupiter Medical Center |
| Authentication and federation | 27 | 23 | Walmart, Cloudflare |
| Privileged or machine identity | 21 | 20 | State Street, IdentityLogic Consulting |
| Integration or automation | 78 | 70 | Sharp HealthCare, MUFG |
| Incident response, support or recovery | 47 | 44 | Southern New Hampshire University, Gordon Food Service |
| Documentation, reporting or evidence | 79 | 71 | MUFG, University of Alaska Fairbanks |
| Stakeholder coordination or handoff | 19 | 17 | IdentityLogic Consulting, Sharp HealthCare |
Three pairings are useful for understanding the job's shape. Lifecycle and governance appear together in 30 advertisements; lifecycle and integration or automation in 38; governance and documentation or reporting in 46. After removing IdentityLogic Consulting, the respective counts are 29, 36 and 41. These are co-mentions within an advertisement, not proof that the same employee performs the actions at the same time. The counts also do not measure the quality or urgency of a duty. For example, a rare privileged-access incident can be important even when fewer descriptions name it.
The operating core: lifecycle and requests
A recurring workstream is the identity lifecycle: a person joins, changes role or leaves; an account, group membership or application entitlement must follow the approved change. Cognizant's operations analyst posting describes joiner, mover and leaver execution alongside requests, incidents, certifications and audit remediation. Gordon Food Service's application administrator works closer to the daily queue: resolving errors, monitoring imports, checking rehires and removing stale roles. Peraton's associate access specialist also illustrates account, token, entitlement and inspection tasks in a specific government-contract context.
These examples point to a chain of operational decisions. The practitioner identifies the person or service, checks the authoritative input and requested entitlement, verifies the approval route, performs or coordinates the change, tests the result, and records what occurred. When a request is incomplete or inconsistent, requesting clarification is part of the work. When a connector or source feed fails, the problem may move from routine fulfillment into incident handling. The employer's access policy determines who may approve access; a job title alone does not grant that authority. The postings often describe platform ownership or technical execution more clearly than final business approval rights, so the matrix leaves unsupported authority claims open.
The outputs are concrete. They include updated identity and entitlement records, completed request tickets, role models, lifecycle workflows, connector configurations, exception records, support documentation and evidence for a review or audit. Freeman Health System's IAM engineer describes lifecycle and policy workflows; UC San Diego Health's access analyst places complex requests and inappropriate-access investigation inside a healthcare system. These are related jobs with different local rules and applications, so neither posting is a universal operating procedure.
Governance, evidence and privileged access
Access governance is a recurring workstream in the descriptions: roles and entitlements are defined, applications are brought into an identity platform, access is reviewed, and exceptions are corrected. State Street's access certification and onboarding analyst describes certifications, entitlement rationalization, application onboarding and user acceptance testing. Its “VP” label is an employer rank for an experienced analyst position; it is not evidence of executive authority. IdentityLogic Consulting's access-review analyst focuses on campaign execution, remediation tracking, reporting and supervised configuration. Black & Veatch's senior analyst asks for broader IGA maturation and role design, with substantial experience requirements. These distinctions matter when interpreting the same words, such as “certification” or “role.”
The work product in a certification is more than a clicked approval. It can include a review population, entitlement context, assigned reviewers, decisions, follow-up on removals, exceptions and an audit trail. The vacancy evidence supports the importance of those elements as job outputs, while local retention and approval rules remain employer-specific. Jupiter Medical Center links periodic certifications to lifecycle administration and application onboarding. UC San Diego Health's senior access analyst adds role-model improvement, excessive-access remediation and mentoring to the analyst's remit.
Privileged-access work carries a different kind of risk. It concerns elevated accounts, secrets, remote privileged sessions and the people or services that use them. IdentityLogic Consulting's CyberArk consultant lists account onboarding, credential rotation, platform health checks and threat analytics; its BeyondTrust engineer posting describes time-bound vendor access and session recording. State Street's SSH and machine-identity engineer focuses on ownership discovery and key governance. These are specialist or engineering roles. A beginner should understand the control objective and the handoff, while a production change to an elevated account follows the employer's assigned approval and technical authority.
Authentication, integration and engineering
The engineering side of the sample describes how identities reach applications and how authentication policies are applied. Federation, single sign-on, multifactor authentication, directories, provisioning APIs and application connectors appear across Cloudflare's workforce and workload IAM role, Walmart's authentication engineering role, and Southern New Hampshire University's platform role. Intel's PKI engineer shows a deeper certificate-lifecycle specialty. Naming SAML, OpenID Connect, SCIM or a PKI system in an advert identifies a technical area; it does not mean every IAM analyst must implement every protocol.
Integration work has its own deliverables: mapped source attributes, a connector or workflow design, tested provisioning and deprovisioning, error handling, operating documentation and a controlled release. IdentityLogic Consulting's SailPoint engineer describes workflows, connectors and refresh tasks; Sharp HealthCare's IAM system developer combines IGA connectors and role workflows with HR, directory and cloud-application integration. Engineers may also be responsible for on-call support, incident diagnosis and recovery after a change. A design that works in a test account is not yet an operational service if failure, reconciliation and evidence paths are unspecified.
Vendor names are useful for understanding the sample's technical vocabulary: SailPoint, Saviynt, Okta, Microsoft Entra, Active Directory, CyberArk, BeyondTrust and other platforms occur in the records. The names are examples of systems that employers use or consider. The sample design and the way alternatives are worded do not support a market-share ranking or a claim that a specific brand is mandatory for U.S. IAM work. A role may name one platform as required, another as preferred, and several as substitutes. The coded source record preserves that distinction.
Working with people, decisions and time
IAM roles repeatedly require observable communication: asking an application owner to clarify an entitlement, explaining a control to a user, documenting a change for a support colleague, coordinating a vendor fix, or presenting an architecture choice. MUFG's analyst posting explicitly combines technical and nontechnical presentation with guides and reporting. IdentityLogic Consulting's business systems analyst translates access needs into requirements, process models and testable stories. University of Alaska Fairbanks' policy architect must reconcile technical and institutional needs across academic and administrative groups. These are workplace behaviors, not personality labels.
Interfaces commonly include the service desk, HR or another authoritative identity-data owner, application administrators, business approvers, security and audit teams, vendors and end users. The mix changes by setting. Sharp HealthCare's Epic security analyst works with clinical-system access; SAIC's ICAM architect describes federal architecture and compliance work. Sector references describe those employers' settings. They should not be read as universal U.S. practice.
The advertisements support an event-driven rhythm more consistently than a fixed calendar. Joiners, transfers, leavers, access requests, incidents, application onboarding and releases prompt work. Some sources also name daily administration or periodic certifications. Southern New Hampshire University explicitly says day-to-day platform work and third-level incidents; Jupiter Medical Center names periodic certifications. Many descriptions do not give a weekly or monthly cadence. The broader U.S. O*NET information-security analyst profile supports access-status work, information gathering, documentation and user discussions as occupational context, but it covers a wider occupation and cannot supply IAM-specific vacancy counts or fill missing cadence in an individual advert.
Authority and escalation also vary. A coordinator may process approved access while an application owner makes the entitlement decision. An engineer can own a platform or resolve a technical fault without becoming the business approver. Southern New Hampshire University explicitly calls for third-level support; Braze's lead engineer combines roadmap ownership with escalation support. Where a posting does not state who approves or when to escalate, this study records the gap instead of inventing a chain of command.
Seniority, concentration and sensitivity
The sample spans analyst and administrator roles, experienced engineers, implementation consultants, architects and managers. A title alone is an unreliable entry-level filter. MUFG allows early-career entry but still asks for automation, scripting and API familiarity. Black & Veatch expects extensive experience. State Street's analyst at VP rank is an experienced specialist. SAIC's architect belongs in a senior federal-contract setting. The coded records keep those levels alongside the work, so an advanced qualification does not become an assumed minimum for the whole field.
Education and certification language needs the same care. A posting may accept a degree or equivalent experience, may express a certification as a preference, or may set a clearance or citizenship condition tied to a particular contract. Those are different signals. Southern New Hampshire University presents technical skills under an undifferentiated hiring heading, so its bullets should not be silently separated into required and preferred lists. University of Alaska Fairbanks states a graduate-degree and experience route with substitution language for a senior policy role. SAIC describes federal-contract experience and access conditions. These examples explain why a universal IAM degree, certification or years-of-experience threshold cannot be read from this sample.
The largest named source, IdentityLogic Consulting, supplied 11 of the 108 included advertisements. Removing it leaves 97. This sensitivity check changes the mix of named product and consulting examples, especially the prominence of several specialized PAM, federation and migration roles. It does not remove the main qualitative pattern: lifecycle and request work, access governance, authentication integration, platform operations, documentation and support are still visible in independent employers such as Cognizant, Jupiter Medical Center, Cloudflare, State Street and Sharp HealthCare. This is a robustness check on the interpretation, not a correction that makes the sample representative.
Interpretation and limits
U.S. technical guidance offers context for why these workstreams fit together. CISA and NSA's IAM guidance announcement identifies governance, federation and single sign-on, multifactor authentication, auditing and monitoring as related areas. NIST's identity and access management program provides digital-identity context. These are contextual sources. They were not added to the 108 advertisements or used to infer how often a U.S. employer requires a product or practice.
The separate 2026 current-changes study examines dated developments from an independent evidence base. It helps interpret what may be changing in tools and workflows, but product releases and policy announcements do not establish employer adoption or alter the vacancy denominator here.
The findings are bounded in four ways. First, searching for accessible, current descriptions favors employers and recruiters with discoverable public pages; it misses unadvertised jobs and pages blocked or closed before review. Second, the sample has substantial senior engineering and consulting content, so it cannot stand in for entry-level hiring alone. Third, a marketplace Apply control and a direct employer page provide different levels of currentness assurance, and an unnamed recruiting client may also advertise through another agency. Fourth, vacancies are statements of intended work and applicant criteria; they do not show how an employee actually spends each week or whether the employer fills the position. No national prevalence, wage, hiring probability or forecast follows from these observations.
The public-sector, university and hospital supplement widens the kinds of organizations represented, yet it remains targeted rather than statistically balanced. A campus identity population, a clinical record system, and a federal contract can each bring distinctive users, evidence needs and approval paths. Their inclusion shows that the common IAM service pattern can operate in several settings; it does not establish that a particular regulatory reference or platform belongs in every setting. Similarly, several advertisements from one large employer may reflect separate teams or requisitions while still giving that employer more influence over an unweighted list. The largest-source sensitivity result is therefore reported alongside the full-sample reading.
Within those limits, the sample gives a coherent picture of the role. Effective IAM practitioners connect identity data, approved access decisions, reliable technical changes and reviewable evidence. They also know when a request lacks authority, when a failed integration needs specialist support, and how to explain the result to the next person in the process. Those boundaries and outputs are as central to the work as the named platforms.
Research archive
This report is archived with the version DOI 10.5281/zenodo.23187675. The Zenodo record includes the searchable PDF and complete source register, the Role Requirements Matrix and workstream counts with source-record support.