AstraZeneca Posted September 22, 2026

Cybersecurity – Identity & Access Management (IAM) Engineer

Zapopan, Jalisco, Mexico Full time
Notify me about similar jobs

AstraZeneca is the source of truth for this posting and owns the application process. We surface normalized context and market comparison you won't find on the original listing.

About this opportunity

Introduction to the role

Every medicine we discover, every clinical trial we run and every patient record we hold depends on our systems and science being secure. At AstraZeneca, Cyber Security protects the infrastructure behind drug discovery, clinical development, manufacturing and the delivery of medicines to patients around the world.

As a Cybersecurity – Identity & Access Management Engineer, you will help protect the digital identities that enable our researchers, clinicians and colleagues to access critical systems securely and efficiently.

You will support, maintain and improve enterprise Identity and Access Management services across on-premises and cloud environments. Working with Active Directory, Microsoft Entra ID and hybrid identity technologies, you will provide operational support for authentication, authorization, password management, multifactor authentication, Windows File Share access and identity lifecycle management.

Working across Cyber Security, infrastructure, cloud, application and support teams, you will resolve complex identity issues, support high-priority incidents and automate IAM processes. Your work will help ensure that the right people have the right access at the right time, while protecting the science behind life-changing medicines.

Accountabilities

In this role, you will:

Support, maintain and improve enterprise IAM services across on-premises and cloud environments, ensuring secure and reliable authentication, authorization and identity lifecycle management.

Administer Active Directory Domain Services, including domain controllers, organizational units, trusts and directory infrastructure.

Support and troubleshoot hybrid identity environments that integrate Active Directory and Microsoft Entra ID, including identity synchronization and provisioning processes.

Manage and troubleshoot authentication services, including multifactor authentication, Self-Service Password Reset, passwordless authentication, Conditional Access and federation services.

Manage and troubleshoot Windows File Share access, including permissions and group-based access, to ensure appropriate and secure access to enterprise resources.

Support joiner, mover and leaver processes, including user provisioning, deprovisioning, group management and access reviews.

Administer Microsoft Entra ID services, including enterprise applications, application registrations, authentication methods and identity governance capabilities.

Investigate and resolve issues involving authentication, account access, identity synchronization, group membership and authorization.

Troubleshoot and maintain Active Directory replication, DNS, DHCP, domain controller health, Kerberos authentication, LDAP connectivity and Group Policy Objects.

Implement and maintain identity security controls and privileged access management processes in line with established security, risk, compliance and architectural standards.

Support high-priority incidents, including incident triage, prioritization, stakeholder communication, escalation management and service-restoration activities.

Balance operational support, project activities, incidents, service requests and unplanned work according to business impact, urgency, risk and established service-management processes.

Identify opportunities to automate repetitive IAM activities using PowerShell and other technologies to improve efficiency, consistency and service reliability.

Collaborate with business users, Cyber Security, infrastructure, cloud, application and support teams, managing expectations and ensuring requests follow approved support channels and processes.

Essential experience, skills and knowledge

You will need:

Strong experience supporting Active Directory Domain Services (AD DS) in a complex enterprise environment.

Hands-on experience administering Microsoft Entra ID, including identity synchronization, authentication methods and enterprise applications.

Experience supporting hybrid identity environments that integrate on-premises Active Directory with cloud identity platforms.

Experience supporting and troubleshooting Windows File Share access, including permissions and group-based access management.

Experience supporting and troubleshooting multifactor authentication, Self-Service Password Reset, passwordless authentication and user credential management.

A strong understanding of authentication and federation technologies, including Kerberos, LDAP, SAML, OAuth, OpenID Connect and federation services.

Experience managing and troubleshooting Group Policy Objects and related directory-services configurations.

A good understanding of DNS, DHCP, Active Directory replication, domain controller operations and Windows Server administration.

Strong analytical and problem-solving skills, with experience diagnosing and resolving complex identity and access management issues.

Experience developing scripts and automating IAM processes using PowerShell or similar technologies.

Experience supporting and coordinating responses to high-priority incidents, including triage, prioritization, stakeholder communication, escalation management and service restoration.

The ability to manage operational support, project activities, incidents, service requests and unplanned work according to business impact, urgency and risk.

The ability to engage effectively with business users, technical teams and support organizations, manage expectations and ensure requests are routed through approved support channels.

A degree in Information Technology, Computer Science, Cybersecurity, Engineering or a related discipline, or equivalent practical experience.

Desirable experience, skills and knowledge

It would also be useful to have:

Experience with Microsoft security technologies such as Conditional Access, Identity Protection, Privileged Identity Management and Identity Governance.

Knowledge of Microsoft Azure and cloud identity architectures.

Experience with privileged access management technologies such as CyberArk, Akeyless, BeyondTrust or similar solutions.

Exposure to identity governance, access certification, role-based access control and compliance controls.

Experience working with security controls, audit requirements and compliance expectations in a regulated enterprise environment.

Why join AstraZeneca’s Cyber Security team?

Join a global Cyber Security function where your IAM expertise will help protect the systems behind scientific discovery and the delivery of medicines to patients. You will work at enterprise scale, collaborate with experienced security specialists, and help build secure and resilient identity services as AI and data reshape the threat landscape.

Working at AstraZeneca

When we put unexpected teams in the same room, we unleash bold thinking with the power to inspire life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions.

That is why we work, on average, a minimum of three days per week from the office. However, that does not mean we are not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.

Ready to make an impact?

If you are ready to secure digital identities at global scale and help protect the science behind life-changing medicines, apply today.#Cyber

Date Posted

22-sept-2026

Closing Date

15-oct-2026

AstraZeneca embraces diversity and equality of opportunity.  We are committed to building an inclusive and diverse team representing all backgrounds, with as wide a range of perspectives as possible, and harnessing industry-leading skills.  We believe that the more inclusive we are, the better our work will be.  We welcome and consider applications to join our team from all qualified candidates, regardless of their characteristics.  We comply with all applicable laws and regulations on non-discrimination in employment (and recruitment), as well as work authorization and employment eligibility verification requirements.

Job details

Seniority
Not listed
Function
Information Technology
Therapeutic area
Not listed
Location
Zapopan, Jalisco, Mexico
Employment type
Full time

How this role compares

Computed from every other active Information Technology role in our database, not just this employer's listings.

We currently track 1167 comparable Information Technology roles across 74 biopharma companies.

1167Comparable roles tracked
1083Currently active
74Companies hiring similar roles
35Countries represented

Salary context

162 of 1167 peers report a salary range (USD, annualized)

Peers share this role's job function. This posting doesn't list a seniority level, so peers aren't narrowed by seniority either -- the range below may span more levels than usual.

This roleSubject Not listed on this posting
Lowest disclosed · 2027 Business Technology Solutions Intern - Cybersecurity (Undergraduate) · AbbVie $21/hr – $37/hr (≈ $43,680–$76,960/yr)
Peer group range $60,320 – $400,000 (median $185,000)

Where these roles are based

Top locations among the 1167 comparable roles

India488
United States310
Spain90
Poland71
Portugal22
China17

+ 29 more countries

Seniority mix

667 of 1167 peers have a known seniority level

Senior272
Manager143
Principal67
Associate Director55
Associate49
Director41
Intern/Fellow/Postdoc21
Senior Director13
Executive/VP6

Therapeutic area mix

2 of 1167 peers have a known therapeutic area; the rest are genuinely unlabeled, not hidden

Oncology1
Vaccines & Infectious Disease1

Similar opportunities

The closest matches from our peer group, ranked by how similar they are, not how well you'd qualify for them -- treat this as market context, not a guaranteed shortlist; a weak match is labeled as one below.

40%similar
Novartis Insurgentes, Mexico Senior
Same function Same country
40%similar
Teva Pharmaceuticals Ciudad De Mexico, Mexico
Same function Same country
40%similar
Novartis Insurgentes, Mexico Manager
Same function Same country
40%similar
Novartis Insurgentes, Mexico Manager
Same function Same country
40%similar
Merck KGaA Naucalpan de Juarez, Estado de Mexico, Mexico
Same function Same country
40%similar
AstraZeneca Zapopan, Jalisco, Mexico
Same function Same country

Notify me about similar jobs

Get an email when we spot other openings like this one – same job function, comparable seniority, roles you'd actually want to see.

How we calculate "similar"

No black box, no LLM guesswork: a deterministic score built from four normalized attributes. Here's this role's own peer group at different match levels, so you can see the mechanism, not just the result.

Every comparison starts from the same 100-point budget: 25 for working in the same function, 40 for the same therapeutic area, 20 for the same or adjacent seniority, 15 for the same country. A dimension we can't confirm on both sides contributes nothing, never a guess, never a free pass.

40%
IT Sr. Business Analyst - CDMO
Novartis · Insurgentes, Mexico · Senior
Function Therapeutic area Seniority Country
40%
Manager, Enablement Architect - Playbook
Novartis · Insurgentes, Mexico · Manager
Function Therapeutic area Seniority Country
40%
Senior Technical Service Representative
Teva Pharmaceuticals · Ciudad De Mexico, Mexico · Senior
Function Therapeutic area Seniority Country
25%
Lead Software Engineer (Rust)
Roche · Sant Cugat del Vallès, Barcelona, Spain · Seniority not listed
Function Therapeutic area Seniority Country
Unmatched or unknown dimensions score exactly the same: 0 points, never a partial guess. A role we know almost nothing about beyond its function bottoms out at 25%; it never inflates to 100% just because there's little to compare against. Seniority uses a defined ladder (Associate → Manager → Associate Director → Senior → Principal → Director → Senior Director → Executive/VP) so "Director" and "Senior Director" count as adjacent, but "Director" and "Executive/VP" do not.