Last updated: August 6, 2026
By Mike Carter, Director of Partnership Success, KORE1
IAM engineers earn $115,000 to $155,000 base at mid-level in 2026 and $150,000 to $200,000 at senior, with identity architects clearing $240,000. Those bands come from reconciling six public sources against searches our desks actually closed. The public sources, taken at face value, put the national average anywhere from $70,582 to $152,773.
Both of those numbers were published on the same website.
Not the same day, but close enough. In June 2026 ZipRecruiter listed “IAM Engineer” at $101,752 a year. On July 20 the same site listed “Identity Access Management Engineer” at $152,773. One job. One data set. Fifty-one thousand dollars of daylight between two ways of writing the same four words.
Then Salary.com does it backward. On August 1 it put “IAM Engineer” at $107,197 and “Identity and Access Management Engineer” at $70,582. Spelling it out costs you $36,615 on one site and earns you $51,021 on the other.
That is the entire problem with budgeting this role in one paragraph.
I should name my stake before you read further. KORE1 runs an identity desk inside our cybersecurity staffing practice, and when a search closes we invoice. So when you reach the section where I argue that the architect req on your desk should probably be a senior engineer req, weigh it knowing the architect search is the one that pays us more. I write it anyway, for reasons that will be obvious by then.

What IAM Engineers Actually Get Paid in 2026
An IAM engineer builds and runs the systems that decide who gets access to what, and for how long. In practice that means provisioning and deprovisioning accounts, wiring single sign-on and federation, running access certification campaigns, and vaulting the credentials that would end your quarter if they leaked.
The title covers a genuinely wide range of work. Somebody writing SailPoint workflow rules and somebody hardening a CyberArk vault both carry it. So does the person who spent last quarter migrating 40,000 users off legacy Active Directory Federation Services and onto Entra ID, and the person who owns the customer login flow for a consumer app with nine million accounts.
The bands below blend the public aggregators with what our desks have closed across the 30-plus U.S. metros we cover. Base only in the third column. Identity work sits inside security budgets, and security budgets do less with equity than product engineering does, so the fourth column matters less here than it would in a mobile or platform guide.
| Level | Typical Profile | Base Range (US, 2026) | Total Comp |
|---|---|---|---|
| IAM Analyst / Administrator | 0 to 3 years, runs access requests and certification campaigns | $78,000 – $110,000 | $85,000 – $122,000 |
| IAM Engineer (Mid) | 3 to 6 years, owns connectors, workflows, and one platform end to end | $115,000 – $155,000 | $125,000 – $175,000 |
| Senior IAM Engineer | 6 to 10 years, owns the identity stack and the audit answer | $150,000 – $200,000 | $165,000 – $235,000 |
| Identity Architect | 8+ years, sets the target state across every application in the estate | $185,000 – $245,000 | $205,000 – $290,000 |
| IAM / IGA Manager | Runs a team of 4 to 12, owns the program and the auditors | $170,000 – $225,000 | $190,000 – $265,000 |
| Director / Head of Identity | Owns identity strategy, budget, and vendor relationships | $205,000 – $290,000 | $240,000 – $360,000 |
The jump from senior engineer to architect is the one people misread. It is not thirty percent more of the same job. The engineer is measured on whether the connector runs at two in the morning. The architect is measured on whether the CFO can answer a regulator’s question about who approved access to the general ledger in March. Different skill, different failure mode, and companies routinely write a req for the second while budgeting for the first.
Every Source Disagrees, and the Reason Is Not Sampling
Salary aggregators disagree about every job. That is normal. Different panels, different self-selection, different definitions of base versus total. On most roles the spread lands inside twenty or thirty thousand dollars and you can average your way to something usable.
Identity is worse than that. Considerably worse.
| Source | Title as Published | 2026 Figure | Why It Reads That Way |
|---|---|---|---|
| ZipRecruiter (July 20, 2026) | Identity Access Management Engineer | $152,773 average | Scraped from job postings. Long titles skew enterprise and federal |
| Glassdoor (2026) | Identity and Access Management Engineer | $135,259 total pay | 205 self-reported salaries, total pay not base, 90th percentile $210,769 |
| ERI SalaryExpert (2026) | IAM Engineer | $131,938 average | Modeled from survey panels, weighted toward large employers |
| PayScale (June 1, 2026) | Identity and Access Management (IAM) Engineer | $120,323 base | 82 profiles, range $79,000 to $170,000, bonus $4,000 to $17,000 |
| Salary.com employer data (Aug 1, 2026) | IAM Engineer | $107,197 base | Employer-reported, tight band, 90th percentile only $124,244 |
| ZipRecruiter (June 2026) | IAM Engineer | $101,752 average | Same scrape, abbreviated title, pulls in analyst and help-desk-adjacent posts |
| Salary.com posting data (Aug 1, 2026) | Identity and Access Management Engineer | $70,582 base | Derived from posted ranges, and posted ranges lowball identity badly |
First row against last row. $82,191 apart. For a title that differs by nothing except whether somebody typed out the acronym.
Sampling explains part of it. It does not explain the direction flipping between two sites, which is the part that should make you stop using any single one of these pages as a budget input.
The real cause is duller than sampling error. Identity work has no stable job architecture across employers. A bank calls the person an IAM Engineer II inside a 14-level ladder with a published band. A 300-person SaaS company calls the same person a Security Engineer and pays whatever their platform engineers make. A federal integrator calls them an ICAM Engineer and prices in a clearance. The aggregators bucket all three by string match on the title field, and the title field is the least reliable column in the entire data set.
We hit this on a search in Charlotte last spring. Client had approved $118,000 for a mid-level IAM engineer, anchored on a national average they had pulled in about ninety seconds. Every candidate we brought was already at $140,000 or above. The req sat open eleven weeks before they moved the band to $145,000, and the person they eventually hired had been available and interested in week two at $142,000. Eleven weeks of unmanaged joiner-mover-leaver backlog to save a number they ended up not saving.
Four Jobs Sharing One Job Title
Our identity desk fills four distinct tracks. Candidates cross between them, but not casually, and not inside a two-week ramp. If you write one req and expect the whole market to answer it, you will get volume and no fit.
Identity governance and administration
SailPoint IdentityIQ, SailPoint Identity Security Cloud, Saviynt. This is the joiner-mover-leaver machine, the access certification campaigns, the role mining, the segregation-of-duties rules that keep the auditors calm. It is the largest of the four tracks by open headcount and the one where a specific platform on the résumé changes the offer most. Job postings for SailPoint IdentityNow engineers run roughly $83,000 to $151,500 on ZipRecruiter, which tells you how wide the “IGA engineer” label stretches in practice.
Deep SailPoint people are scarce. Deep Saviynt people are scarcer still, and they know it, which is why a Saviynt-heavy req in a secondary market routinely sits open about twice as long as the equivalent SailPoint search at the same band.
Privileged access management
CyberArk, Delinea, BeyondTrust. Vaults, session brokering, credential rotation, and the uncomfortable conversation about why 60 engineers all know the production database password. PAM engineers get paid a premium over general IAM, typically $10,000 to $25,000 at the same level, because the blast radius of getting it wrong is the entire environment and because the candidate pool is genuinely small.
Single sign-on and federation
Okta, Microsoft Entra ID, Ping Identity, and whatever SAML integration somebody set up in 2016 and never documented. This is application onboarding at scale. The work is less glamorous than the other three and the market has more supply, so bands sit at the lower end of the mid range unless the estate is genuinely large.
Large means something specific. Two thousand applications rather than two hundred, with a mix of modern OIDC, ancient SAML, and at least a dozen things that still authenticate against LDAP because nobody has been willing to touch them since 2014.
CIAM and zero trust
Customer identity, which is a different animal entirely because the users are not employees and the failure mode is revenue rather than compliance. Okta Customer Identity, Auth0, ForgeRock, or a homegrown stack on top of OAuth 2.0 and OIDC. These engineers behave more like product engineers than security engineers and their comp reflects that. Senior CIAM people command the top of the senior band, and at consumer-scale companies they clear it.
| Track | Core Platforms | Senior Base Range | Supply |
|---|---|---|---|
| Identity governance (IGA) | SailPoint, Saviynt | $155,000 – $195,000 | Tight, worse for Saviynt |
| Privileged access (PAM) | CyberArk, Delinea, BeyondTrust | $165,000 – $210,000 | Very tight |
| SSO and federation | Okta, Entra ID, Ping | $145,000 – $180,000 | Reasonable |
| CIAM and zero trust | Auth0, Okta CIC, ForgeRock, custom OIDC | $160,000 – $215,000 | Tight at consumer scale |
One caution on that table. A résumé listing all four is usually a systems integrator background, which means broad exposure and shallow ownership. Sometimes that is exactly right for a greenfield build. It is usually wrong for a team inheriting a decade of accumulated entitlements.

IAM Pay by Experience, and Where the Ladder Actually Bends
The first three years
Entry into identity almost never happens through a computer science degree. It happens sideways. Help desk into account administration into an IGA tool, or systems administration into Active Directory into Entra ID. The floor sits around $78,000 and the ceiling on the analyst title is roughly $110,000.
What moves somebody off that floor fastest is not a certification. It is getting hands on a governance platform in production and being able to describe a certification campaign they ran without reading from notes.
Three to six years, where most of our reqs live
$115,000 to $155,000. This is the deepest part of the market and the band where a specific platform matters most, because at this level the company is buying somebody who can be productive in a named tool inside thirty days. PayScale puts the broad average at $120,323 with a 10th-to-90th range of $79,000 to $170,000, which is roughly consistent with this band once you account for the analyst-level profiles sitting in their sample.
Mid-level is also where we fill fastest. Across our IT desks generally, KORE1 averages 17 days to placement, and mid-level identity roles land close to that when the band is right.
Six to ten years, senior
$150,000 to $200,000, and the spread inside that range is mostly about audit exposure. A senior engineer who has personally sat in front of external auditors and defended an access model is worth measurably more than one who has only built to a spec somebody handed them. Glassdoor puts senior identity engineers at $189,338, which sits near the top of our band and reflects total pay rather than base.
The other thing that moves the number here is scale. Ten thousand identities and two hundred applications is a different job from a hundred thousand identities and two thousand applications, and it is not linearly different, because past a certain estate size the constraint stops being the tooling and starts being how many humans will actually review a certification campaign before the deadline.
Architect, and the title inflation problem
$185,000 to $245,000 base. Real identity architects design a target state, sequence a multi-year migration, and defend that sequence to people who control budget. There are not many of them.
There are, however, a great many people with “Architect” in their current title who are senior engineers with good slide decks. I am not being unkind about it. Title inflation in identity has been running hot since about 2021 and a lot of it was retention-driven rather than scope-driven. Screen for it by asking what the candidate personally decided rather than what their team delivered, then ask who disagreed with that decision and how the disagreement got resolved, because architecture is mostly the second conversation. The answers separate quickly.
NIST Finalized 800-63-4 in July 2025 and Most Reqs Have Not Caught Up
NIST published the final revision of its Digital Identity Guidelines, SP 800-63-4, in July 2025, after a four-year process and roughly 6,000 public comments. The short version for a hiring manager is that phishing-resistant authentication moved from best practice to expected baseline, any AAL2 implementation now has to offer a phishing-resistant option, and syncable passkeys qualify as AAL2 authenticators.
That last clause did more to reshape identity roadmaps than anything else published in the last three years.
The practical effect on hiring is that a candidate whose deepest authentication experience is deploying push-based MFA in 2022 is now behind. Not unemployable. Behind. Most teams are somewhere inside a passkey rollout right now. FIDO2 enrollment flows, recovery paths that do not quietly reopen the phishing hole you just closed, and then the part nobody enjoys, which is deciding what happens to the 8 percent of your workforce carrying devices that cannot hold a passkey at all.
We started seeing “passkey” as a hard requirement on reqs around the middle of 2026. Very few résumés carry production passkey experience yet, which means the requirement functions as a filter that removes most of your qualified pool over a skill most of them could pick up in a quarter. That line is sitting on a lot of job descriptions right now. Worth asking what yours is buying you.
Federal and federal-adjacent teams are further along, because the zero-trust mandates gave them a deadline. If you are hiring in the Washington, DC corridor you are competing against integrators who have been doing phishing-resistant work at scale since 2022, and you should expect to pay for it.
Where the Money Is by Metro
Identity pays a location premium, but a narrower one than most engineering disciplines, because a meaningful share of these roles stayed remote. The compliance work does not require a badge reader.
| Metro | ZipRecruiter Average, IAM Engineer | What Drives It |
|---|---|---|
| Washington, DC | $115,244 | Federal ICAM work, clearance premium on top of the posted number |
| New York | $111,320 | Banking and insurance, heaviest IGA concentration in the country |
| Los Angeles | $109,639 | Media, healthcare systems, aerospace supply chain |
| Houston | $97,171 | Energy sector OT and IT convergence work |
| North Carolina | $92,473 | Charlotte banking, Research Triangle pharma, lower cost base |
Read those as floors, not targets. They are averages across a scraped posting pool that includes analyst-level roles, and every one of them sits below where we actually close mid-level searches in the same city. Orange County and the broader Southern California market run roughly seven to twelve percent above the Los Angeles figure for governance work, mostly because the healthcare and medical device employers in Irvine and Costa Mesa are competing for the same twenty people.
Remote changes the calculus more here than elsewhere. A Charlotte-based senior IGA engineer working remotely for a New York bank is a common shape, and that person is priced against New York, not Charlotte. If you are a mid-market employer in a secondary metro, that is your actual competition.
Credential Attacks Went Down in 2026. Identity Hiring Went Up.
The 2026 Verizon Data Breach Investigations Report found that credential abuse dropped to 13 percent of breaches as an initial access vector, losing the top spot it had held to vulnerability exploitation. Read that headline alone and you would conclude identity spending should be flattening.
It is not. Ours is one of the desks that grew this year.
The rest of the report explains why. Credential abuse still shows up somewhere in 39 percent of breaches, just not as the front door. Ransomware appeared in 48 percent of breaches investigated, and 73 percent of ransomware victims had an associated infostealer or credential leak in the prior year. Credentials made up 52 percent of the data compromised in basic web application attacks.
Attackers did not stop using identity. They moved it later in the chain, where it does more damage and where perimeter tooling cannot see it. The defensive answer to that is not a better login page. It is entitlement hygiene, session monitoring, privileged access controls, and knowing within an hour rather than a quarter that a service account has been doing something it never did before.
Which is engineering work. Sustained, unglamorous, headcount-shaped engineering work.
Meanwhile the Bureau of Labor Statistics projects employment of information security analysts, the occupational bucket that contains most identity roles, to grow 29 percent between 2024 and 2034, with about 16,000 openings a year and a median wage of $124,910 as of May 2024. And the 2025 ISC2 Cybersecurity Workforce Study found 95 percent of security professionals reporting at least one skill gap on their team, up five points year over year, while only 34 percent said their staffing level was actually adequate.
Supply is not catching demand. It has not for a while.

Certifications, and Which Ones Move the Number
Vendor certifications matter more in identity than in most engineering disciplines, and less than candidates think. Somehow both are true.
They matter because the platforms are genuinely proprietary. Nobody learns SailPoint workflow rules from a general security background. They matter less than candidates think because a certification without production hours reads as exactly what it is, and any competent technical screen exposes it in about eight minutes.
- SC-300, Microsoft Identity and Access Administrator. The most common cert we see on IAM résumés in 2026, largely because so many estates run on Entra ID. Useful floor signal. Adds little to an offer on its own.
- Okta certifications, Professional through Consultant, are the most requested vendor credential in workforce identity postings this year. A Consultant-level Okta cert with matching production experience is worth real money in an SSO or federation search.
- SailPoint credentials are the ones that most reliably change an offer, because the supply gap is real and the platform is hard to fake. We have seen $12,000 to $20,000 swings on a single search tied to demonstrable IdentityIQ depth.
- CyberArk Defender and Sentry. Table stakes in PAM, not a differentiator by themselves.
- CISSP is a management-track signal, not an engineering one. It gets a résumé through an HR filter at a bank. It does not make somebody better at writing a provisioning connector, and I would not pay a premium for it on an individual contributor req.
Ask what the candidate built with the platform, not which badge they hold. A person who migrated 40,000 accounts from ADFS to Entra ID and can describe what broke during the cutover is worth more than a person with four certifications and a lab environment.
Contract and Consulting Rates
Identity runs on projects more than most security disciplines, because the work arrives in waves. A platform migration, a merger integration, an audit finding with a remediation deadline. Those are 6-to-18-month problems that do not justify permanent headcount, which is why our contract staffing volume on this desk runs higher than on comparable engineering desks.
| Engagement Type | W-2 Hourly Range | Typical Duration |
|---|---|---|
| Mid-level IAM engineer, general | $65 – $90 | 6 to 12 months |
| Senior IGA engineer, SailPoint or Saviynt | $95 – $145 | 9 to 18 months |
| PAM engineer, CyberArk implementation | $105 – $160 | 6 to 12 months |
| Identity architect, advisory | $140 – $220 | 3 to 9 months |
Rates on the top two rows moved up noticeably in the first half of 2026, tracking the passkey and phishing-resistance work that arrived all at once after the NIST revision landed.
One practical note on contract identity work. Give the contractor real access on day one or do not bother hiring them. We have watched more than one engagement burn its first three weeks waiting for the vault credentials that the engagement was hired to reorganize. Ironic, expensive, and completely avoidable.
The Section That Costs Us Money
A real share of the companies reading this should not hire an identity architect.
You should hire a senior IGA engineer for $60,000 less and buy the architecture from your platform vendor’s professional services team, who will do it as part of an implementation you are already paying for. The architect req makes sense when you have multiple platforms, a multi-year migration, and genuine internal disagreement about the target state. It makes very little sense when you have one governance tool, one directory, and a backlog of applications to onboard.
We lose the bigger fee when a client takes that advice. I keep giving it because the alternative outcome is worse for everybody. An architect with nothing to architect leaves inside a year, and then you are running the same search again with a worse story to tell candidates about why the last person left.
Second one, same spirit. If your identity problem is that nobody has run an access review in eighteen months, that is not an engineering hire. That is an analyst and a project manager, and between them they will cost about half of what you were about to spend on an engineer who would have found the same backlog and then been bored by it inside a quarter.
What Our Identity Searches Look Like Right Now
KORE1 has been placing technology talent since 2005, across eight verticals and 30-plus U.S. metros, with recruiters who average 15-plus years in their specialty. Our 12-month retention rate on placements sits at 92 percent, and identity tracks slightly above that, which we attribute mostly to how specific these searches are on both sides. Nobody accidentally takes an IGA job.
What the last several months have looked like on this desk, concretely.
Governance roles dominate the req mix and take the longest. A senior SailPoint search runs six to nine weeks in most markets, longer if the client insists on hybrid attendance in a metro without a natural pool. PAM searches are shorter but narrower, and the candidate usually has two other offers by week three, so a slow interview loop simply loses. Federation and SSO roles fill fastest, generally inside four weeks. CIAM is the one where compensation is most likely to be the blocker, because we are competing against product engineering bands rather than security bands and clients frequently have not budgeted for that.
The pattern underneath all four is the same. Reqs that fail almost never fail on sourcing. They fail on a band set from a national average, or a job description asking for five years of a platform capability that has existed for two.
What Hiring Managers Ask Us First
What number should actually go in the budget line?
Plan on $115,000 to $155,000 base for a mid-level IAM engineer and $150,000 to $200,000 for senior, then add 20 to 30 percent for benefits and payroll burden. Privileged access roles run $10,000 to $25,000 above those bands.
Budget by track before you budget by level. A PAM req and an SSO req at the same nominal seniority are $30,000 apart, and averaging them produces a number that is wrong for both.
Why does one site say $70,582 and another say $152,773?
Because the aggregators bucket by job title string, and identity has no consistent job architecture across employers. Posting-derived data lowballs identity badly, while long-form titles skew toward enterprise and federal roles that pay above market.
Use three sources minimum, throw out the high and the low, and sanity-check the middle against what candidates in your market are actually declining. That last input is the only one that reflects the current clearing price. Everything else is a lagging indicator with a marketing department attached.
IAM engineer or cybersecurity engineer, which is the better hire?
Different jobs, not different levels. A cybersecurity engineer defends the environment broadly. An IAM engineer owns who can get into it, which is a narrower and deeper specialty that a generalist cannot cover part-time.
Companies try the part-time version constantly. It works until the first access certification campaign, at which point the generalist discovers that governance is a full calendar quarter of work and everything else on their plate stops. Our cybersecurity engineer salary guide covers the broader role if you are weighing both.
Is a clearance worth what it costs us in time to hire?
For federal and federal-adjacent work, yes, and expect to pay 10 to 20 percent above commercial bands for an active clearance. For commercial work in the DC corridor it is usually a filter you did not need and it doubles your time to fill.
The mistake is inheriting a cleared req template from a federal program and applying it to a commercial one because the hiring manager is used to it. We have seen that cost a client seven weeks on a role where clearance was genuinely irrelevant.
How long should an identity search take?
Four weeks for federation and SSO roles, six to nine for senior governance work, and three to five for privileged access if your interview loop moves quickly. KORE1 averages 17 days to placement across IT generally, and identity runs longer than that average.
Past nine weeks on a governance search, the job description is usually the problem rather than the market. Send it to somebody who fills these weekly and ask which single line is eliminating the most people. There is almost always one.
Can we grow one internally instead?
Often yes, and identity is one of the better disciplines for it. Sysadmins and Active Directory specialists convert well because they already understand directories, groups, and the political reality of taking access away from people.
Budget nine to twelve months and a vendor training investment. The conversion fails when nobody senior is there to review the work, because early governance mistakes do not surface until an audit, and by then they are structural rather than fixable.
Does a SailPoint or Okta certification justify a higher offer?
SailPoint depth does, reliably, and we have seen $12,000 to $20,000 swings tied to it on a single search. Okta certifications matter most in federation-heavy environments. SC-300 is a floor signal rather than a premium.
The certification is not what you are paying for. You are paying for somebody who will not spend their first two months learning your platform on your time, and the credential is only a proxy for that.
Remote, hybrid, or onsite for this role?
Remote works better for identity than for almost any other security specialty, because the work is configuration, workflow, and documentation rather than incident response. Insisting on hybrid in a thin market is the single most expensive constraint you can put on one of these searches.
If hybrid is genuinely non-negotiable, say so in the first line of the job description and price it accordingly. Burying it in the benefits section wastes three weeks of everyone’s calendar, and it does not change the outcome.
Setting a Band You Can Defend
Pick the track first. Governance, privileged access, federation, or customer identity, because those are four markets and the tables above only mean something once you have chosen one. Level comes second. Metro and remote posture come third, and they matter less here than your instincts probably suggest.
Then stop averaging aggregator pages. Nothing in this guide will save you more money than that one habit.
Two things worth ten minutes when you get to the number. Our salary benchmark assistant returns a live band for a specific level and market, and the salary benchmarking methodology we use for tech leaders explains how we weight conflicting sources against each other, which on this role is a nightly occurrence. Already past budgeting and into the search? Our identity and access management staffing desk covers all four tracks, and cloud security recruiters handles the adjacent work when the identity problem turns out to be an entitlements problem in AWS.
Or skip the reading entirely. Talk to a recruiter who runs these searches every week, and you will know inside one call whether your band clears the market. Sometimes that call ends with us telling you the hire you described is not the hire you need. We still make it.

