Video summary

How to Get Into IAM in 2026 | The Real Career Path, Tools & AI

Main summary

Key takeaways

Educational

Main ideas / lessons conveyed

Identity & Access Management (IAM) career reality

  • IAM professionals prevent major security and governance failures that happen when access is mismanaged—such as:
    • Over-permissioning
    • Poor deprovisioning
    • Weak governance
  • Identity work is not only “fixing breaches.” It also includes:
    • Prevention
    • Mitigation planning
    • Readiness for incidents

Why poor IAM is risky

  • Disgruntled insiders
    • Fired employees may still retain access if deprovisioning and governance are outdated.
    • This can enable leakage of sensitive personal and financial data.
  • Excessive permissions
    • Attackers with elevated access can take down servers and cause millions/billions in damage.
  • “Whales” (CEOs/executives)
    • Often targeted via phishing and social engineering.
    • If governance doesn’t handle role changes correctly, attackers may gain “keys to the kingdom.”
  • Everyday identity phishing/fatigue
    • MFA fatigue and similar social engineering can lead to credential compromise.
    • Small credential leaks (e.g., pinned passwords in Slack/Discord/Teams, Wi‑Fi passwords) can be chained into larger compromise.
    • Remote work increases exposure due to more devices and network contexts.

How identity teams operate (“purple team”)

  • IAM blends offense and defense:
    1. Research new attack patterns (often via security blogs and reports).
    2. Assess exposure and test controls.
    3. If vulnerabilities exist, build mitigations.
    4. Run tabletop exercises to plan breach response:
      • Roles
      • Communications
      • Teams involved
  • Emphasis: IAM practitioners should document and rehearse incident response, not just react.

Entry points into IAM

  • Help desk (traditional route)
    • Can be “easy” only in name—some help desk teams restrict access so people can’t learn IAM deeply.
    • The better approach is to use help desk as an on-the-job inside track:
      • Learn onboarding/lifecycle tools
      • Build hands-on experience outside the strict job role (where possible)
  • Alternative paths
    • Testing roles
    • Business analyst / requirements roles
    • Other analyst routes that can grow into deeper IAM responsibilities

Navigating IAM roles and “niche down”

Choose a lane based on personal fit:

  • People who like coding/tinkeringengineer track
  • People who are analytical / prefer explaining problemsanalyst track
  • Project manager often grows from business analyst plus requirements/scheduling understanding
  • Architect is described as someone building the “house”—integrating engineers/analysts into a cohesive identity ecosystem

Tooling approach (2026 starter plan)

  • Start with Entra (Microsoft) for many people because:
    • Many organizations (especially government contractors) are Microsoft shops
    • Entra fundamentals generalize across industries/use cases
  • Learn other platforms after foundations:
    • Octa/Okta as complementary experience
    • Salesforce/SailPoint
      • SailPoint is described as harder to fill role-wise
      • Entry can be more difficult due to competition and demand
  • Key principle: learn fundamentals first, then apply to multiple platforms.

Learning SailPoint specifically (experience access options)

Ways people gain SailPoint experience:

  • Join an implementation team / consulting / MSP and gain access through that work
  • Pay for training or “university-style” programs and labs (hands-on)
  • Avoid “hit-or-miss” training (e.g., random offshore programs)
  • Notes:
    • YouTube exists, but it’s more limited for SailPoint than for other tools
    • SailPoint is described as more gated than cloud platforms that allow free tenants

Fundamentals are the real differentiator

Before chasing tool-specific depth, build core IAM understanding:

  • Authentication vs authorization models
  • SSO
  • SAML and OIDC
  • Joiner/mover/leaver and onboarding/offboarding processes
  • Being able to explain IAM simply (e.g., “to a 6th grader”) is treated as evidence of true mastery
  • AI can support learning and automation, but hiring still depends on human verification and communication.

Hiring & interview expectations

Interviewers look for:

  • Proof you did the work (not “our team did it”)
  • Specifics:
    • “How did you do it?”
    • “What problems/roadblocks did you face?”
    • “How did you resolve them?”
  • Scenario-based reasoning:
    • Entry-level answers deepen into senior-level detail
  • Resume exaggeration detection:
    • If candidates can’t answer specifics, it can indicate “resume padding”
  • Identity also benefits from identity verification methods to reduce hiring mismatches.

Mindset for career growth

Two non-identity skills emphasized:

  • Patience
    • Learning IAM takes months to a year
    • “Get an IAM job in 3 months” is considered unrealistic
  • Curiosity
    • Actively ask questions
    • Learn new attack trends
    • Understand the “why” behind changes
  • People who “rocket ship” are those who continuously learn beyond what the job requires.

AI’s impact on IAM

  • Biggest identity evolution: non-human accounts / AI agents
    • Governance gaps for agent permissions and credential/token exposure
    • Need to monitor, restrict, and document what agents can do
  • AI increases productivity, but humans remain necessary for:
    • Verification and checks/balances
    • Documentation of production impact
    • Preventing mistakes like agent-driven deployments causing outages/leaks
  • “You still got to teach it”:
    • Organizations must provide safe/approved knowledge
    • Avoid leaking secrets

Market gaps mentioned

  • Hard-to-fill specialization: SailPoint
  • Another gap: customer identity / IAM (CIM)
    • Example: customer access flows like those in DoorDash / Chick-fil-A / Gap.com
  • Workforce identity experience differs from workforce “sign-in” identity work
  • AI governance knowledge is still emerging:
    • Not enough practical guidance is widely available yet

Methodology / instructions (detailed bullet list)

How to start and grow in IAM (practical path)

  1. Step 1: Build identity fundamentals (first)
    • Learn core concepts and vocabulary:
      • Authorization models
      • Authentication models
      • SSO
      • SAML
      • OIDC
      • Joiner/mover/leaver and onboarding/offboarding flows
    • Practice explaining identity concepts clearly (aim for “6th grader” explanations).
  2. Step 2: Create hands-on proof (portfolio)
    • Build real projects using identity platforms:
      • Post use cases with screenshots
      • Put artifacts in a repo to show what you built
    • Be able to verbally defend what you did during interviews.
  3. Step 3: Choose a platform to learn next
    • Recommended: Entra first
    • Learn Octa/Okta after Entra if job market/tool overlap requires it
    • For SailPoint:
      • Expect it to be more gated
      • Plan how you’ll obtain real experience access
  4. Step 4: Gain experience strategically
    • If coming from help desk:
      • Learn current systems used in your company
      • Ask questions and take notes from identity team members
      • Build experience on the side (free tenants where possible)
    • If help desk access is restricted:
      • Pivot to roles that still build IAM-relevant experience (tester, business analyst, requirements roles, analyst roles).
  5. Step 5: Niche down based on personal strengths
    • Like coding/tinkering → engineer track
    • Like analysis/problem explanation → analyst track
    • Like scheduling/requirements coordination → PM track (often from BA foundations)
    • Like integrating systems/architecting ecosystems → architect track
  6. Step 6: Prepare for interviews the “real way”
    • Expect scenario questions and deep follow-ups:
      • “What if this happens?”
      • “What roadblocks occurred and how did you fix them?”
    • Be ready to clarify:
      • What you did specifically (not just your team).
  7. Step 7: Grow via habits
    • Maintain:
      • Patience (don’t expect rapid entry without fundamentals/portfolio)
      • Curiosity (keep learning beyond daily tasks)
    • Consistency suggestion: spend time learning regularly (example given: ~20 minutes/day).

How identity teams defend (IAM operational workflow)

  1. Monitor and research
    • Read security blogs/news to identify new identity attack patterns
    • Example types: MFA fatigue patterns, phishing tactics, evolving auth threats
  2. Assess exposure
    • Determine whether the organization is vulnerable
    • Test identity-related controls
  3. Mitigate
    • Build or adjust governance and technical controls based on findings
  4. Prepare for incidents
    • Run tabletop exercises:
      • Define what happens if breached
      • Identify who to call and which teams to involve
  5. Stay in a “purple team” mindset
    • Combine “offense research” with “defensive implementation and validation.”

Speakers / sources featured (and named people)

People

  • Chris (host/interviewer; name stated as “Chris” in the subtitles)
  • Andrew Chanthophone (IAM expert/guest; referenced as “Andrew” throughout)

Referenced sources / organizations (as examples)

  • BleedingComputer
  • Krebs Report
  • Black Hat (conference example; passkeys attack discussed)
  • Microsoft Entra
  • Okta
  • SailPoint
  • CyberArk (PAM solution)
  • Privileged Access Management (PAM)
  • NIS guidance on AI governance (exact acronym unclear in subtitles)
  • OPA / incident example (referred to as “this hurt OPA a couple years ago”; exact meaning unclear in subtitles)
  • Washington Post (example coverage of “forgot to turn off access”)
  • HuggingFace (example attack referenced)
  • Amazon outage example (described as an AI agent causing a server to go down)

Original video