Learn Computer Stuff
Home / Cybersecurity / Identity & Access Engineer
Cybersecurity

Identity & Access Engineer

You decide who can do what, and you make sure nobody quietly accumulates more than they need.

No degree needed Moderate to hard. The concepts are learnable; the legacy estate is what makes it hard.


Can I actually do this?

Open without a degree and steadier work than it sounds — identity is where most organisations are actively spending, because stolen credentials rather than clever exploits are how most intrusions start. The common route is help desk or sysadmin, where you have already administered accounts, then specialising.

Who it suits. People who are methodical about detail and comfortable saying no to a director.

Runway. A year or so, usually from a systems or support background.

Coming from another job?

Coming from support or sysadmin? You have done the entry-level version of this job for years without it being called that. Help Desk / IT Support Systems Administrator Cloud Engineer

Also advertised as

  • IAM Engineer
  • Identity Engineer
  • Access Management Specialist
  • Directory Services Engineer

The route

Four stations, in order. Each one is a thing you finish before the next matters.

  1. Station one

    Learn it free

    Only the best few, deliberately. Every one of these is free to use — the pill on each card says exactly what is and isn't free.

    AWS IAM — user guide

    Free to learn · no certificate

    The clearest free treatment of policies, roles and least privilege from a major cloud. Free; the concepts transfer to other platforms even if the syntax does not.

    OWASP Cheat Sheet Series

    Free to learn · no certificate

    The authentication, session management and authorisation sheets are the practical reference for the application side. Free.

    NIST Cybersecurity Framework

    Free to learn · no certificate

    Identity work is usually driven by an audit finding. Knowing the framework the auditor is using is half the argument. Free from NIST.

    See the full catalog in the explorer →

  2. Station two

    Attest strategically

    Nothing named. Vendor identity certifications exist and matter mainly when an employer already runs that vendor's platform, which makes buying one speculatively a poor bet. A cloud platform certificate is a more general signal if you want one; otherwise show your work on least privilege.

    Nothing here is worth paying for

    No credential needed

    Nothing named. Vendor identity certifications exist and matter mainly when an employer already runs that vendor's platform, which makes buying one speculatively a poor bet. A cloud platform certificate is a more general signal if you want one; otherwise show your work on least privilege.

  3. Station three

    Prove it

    A certificate says you passed a test. These say you can do the job.

    A permissions audit you ran

    Take a real environment, find the over-permissioned accounts, and write up what you would remove and why. The reasoning matters more than the tooling.

    Least privilege applied end to end

    Narrow a working setup until it still works and nothing more. Show what broke on the way and how you knew.

    A joiner-mover-leaver process

    Document how access is granted, changed and removed. Most breaches trace to the leaver half.

  4. Station four

    Get hired

    Search these exact titles

    • IAM engineer
    • identity engineer
    • access management
    • identity and access management

    Who hires for this. Banks, healthcare, government and any regulated employer, plus large organisations with a real directory estate.

    Interviews here lean on scenarios about revoking and scoping access, which rewards administrative experience over study. That is our reading of the field, not a verified hiring statistic.

    On salary

    We don't publish salary estimates. Numbers copied between blogs drift from reality, and a wrong number costs you real negotiating power. When we have a verified public source, it goes here with its date.


Where this route continues

· How we verify