Video summary
How to Get Into IAM in 2026 | The Real Career Path, Tools & AI
Main summary
Key takeaways
Main ideas / lessons conveyed
Identity & Access Management (IAM) career reality
- IAM professionals prevent major security and governance failures that happen when access is mismanaged—such as:
- Over-permissioning
- Poor deprovisioning
- Weak governance
- Identity work is not only “fixing breaches.” It also includes:
- Prevention
- Mitigation planning
- Readiness for incidents
Why poor IAM is risky
- Disgruntled insiders
- Fired employees may still retain access if deprovisioning and governance are outdated.
- This can enable leakage of sensitive personal and financial data.
- Excessive permissions
- Attackers with elevated access can take down servers and cause millions/billions in damage.
- “Whales” (CEOs/executives)
- Often targeted via phishing and social engineering.
- If governance doesn’t handle role changes correctly, attackers may gain “keys to the kingdom.”
- Everyday identity phishing/fatigue
- MFA fatigue and similar social engineering can lead to credential compromise.
- Small credential leaks (e.g., pinned passwords in Slack/Discord/Teams, Wi‑Fi passwords) can be chained into larger compromise.
- Remote work increases exposure due to more devices and network contexts.
How identity teams operate (“purple team”)
- IAM blends offense and defense:
- Research new attack patterns (often via security blogs and reports).
- Assess exposure and test controls.
- If vulnerabilities exist, build mitigations.
- Run tabletop exercises to plan breach response:
- Roles
- Communications
- Teams involved
- Emphasis: IAM practitioners should document and rehearse incident response, not just react.
Entry points into IAM
- Help desk (traditional route)
- Can be “easy” only in name—some help desk teams restrict access so people can’t learn IAM deeply.
- The better approach is to use help desk as an on-the-job inside track:
- Learn onboarding/lifecycle tools
- Build hands-on experience outside the strict job role (where possible)
- Alternative paths
- Testing roles
- Business analyst / requirements roles
- Other analyst routes that can grow into deeper IAM responsibilities
Navigating IAM roles and “niche down”
Choose a lane based on personal fit:
- People who like coding/tinkering → engineer track
- People who are analytical / prefer explaining problems → analyst track
- Project manager often grows from business analyst plus requirements/scheduling understanding
- Architect is described as someone building the “house”—integrating engineers/analysts into a cohesive identity ecosystem
Tooling approach (2026 starter plan)
- Start with Entra (Microsoft) for many people because:
- Many organizations (especially government contractors) are Microsoft shops
- Entra fundamentals generalize across industries/use cases
- Learn other platforms after foundations:
- Octa/Okta as complementary experience
- Salesforce/SailPoint
- SailPoint is described as harder to fill role-wise
- Entry can be more difficult due to competition and demand
- Key principle: learn fundamentals first, then apply to multiple platforms.
Learning SailPoint specifically (experience access options)
Ways people gain SailPoint experience:
- Join an implementation team / consulting / MSP and gain access through that work
- Pay for training or “university-style” programs and labs (hands-on)
- Avoid “hit-or-miss” training (e.g., random offshore programs)
- Notes:
- YouTube exists, but it’s more limited for SailPoint than for other tools
- SailPoint is described as more gated than cloud platforms that allow free tenants
Fundamentals are the real differentiator
Before chasing tool-specific depth, build core IAM understanding:
- Authentication vs authorization models
- SSO
- SAML and OIDC
- Joiner/mover/leaver and onboarding/offboarding processes
- Being able to explain IAM simply (e.g., “to a 6th grader”) is treated as evidence of true mastery
- AI can support learning and automation, but hiring still depends on human verification and communication.
Hiring & interview expectations
Interviewers look for:
- Proof you did the work (not “our team did it”)
- Specifics:
- “How did you do it?”
- “What problems/roadblocks did you face?”
- “How did you resolve them?”
- Scenario-based reasoning:
- Entry-level answers deepen into senior-level detail
- Resume exaggeration detection:
- If candidates can’t answer specifics, it can indicate “resume padding”
- Identity also benefits from identity verification methods to reduce hiring mismatches.
Mindset for career growth
Two non-identity skills emphasized:
- Patience
- Learning IAM takes months to a year
- “Get an IAM job in 3 months” is considered unrealistic
- Curiosity
- Actively ask questions
- Learn new attack trends
- Understand the “why” behind changes
- People who “rocket ship” are those who continuously learn beyond what the job requires.
AI’s impact on IAM
- Biggest identity evolution: non-human accounts / AI agents
- Governance gaps for agent permissions and credential/token exposure
- Need to monitor, restrict, and document what agents can do
- AI increases productivity, but humans remain necessary for:
- Verification and checks/balances
- Documentation of production impact
- Preventing mistakes like agent-driven deployments causing outages/leaks
- “You still got to teach it”:
- Organizations must provide safe/approved knowledge
- Avoid leaking secrets
Market gaps mentioned
- Hard-to-fill specialization: SailPoint
- Another gap: customer identity / IAM (CIM)
- Example: customer access flows like those in DoorDash / Chick-fil-A / Gap.com
- Workforce identity experience differs from workforce “sign-in” identity work
- AI governance knowledge is still emerging:
- Not enough practical guidance is widely available yet
Methodology / instructions (detailed bullet list)
How to start and grow in IAM (practical path)
- Step 1: Build identity fundamentals (first)
- Learn core concepts and vocabulary:
- Authorization models
- Authentication models
- SSO
- SAML
- OIDC
- Joiner/mover/leaver and onboarding/offboarding flows
- Practice explaining identity concepts clearly (aim for “6th grader” explanations).
- Learn core concepts and vocabulary:
- Step 2: Create hands-on proof (portfolio)
- Build real projects using identity platforms:
- Post use cases with screenshots
- Put artifacts in a repo to show what you built
- Be able to verbally defend what you did during interviews.
- Build real projects using identity platforms:
- Step 3: Choose a platform to learn next
- Recommended: Entra first
- Learn Octa/Okta after Entra if job market/tool overlap requires it
- For SailPoint:
- Expect it to be more gated
- Plan how you’ll obtain real experience access
- Step 4: Gain experience strategically
- If coming from help desk:
- Learn current systems used in your company
- Ask questions and take notes from identity team members
- Build experience on the side (free tenants where possible)
- If help desk access is restricted:
- Pivot to roles that still build IAM-relevant experience (tester, business analyst, requirements roles, analyst roles).
- If coming from help desk:
- Step 5: Niche down based on personal strengths
- Like coding/tinkering → engineer track
- Like analysis/problem explanation → analyst track
- Like scheduling/requirements coordination → PM track (often from BA foundations)
- Like integrating systems/architecting ecosystems → architect track
- Step 6: Prepare for interviews the “real way”
- Expect scenario questions and deep follow-ups:
- “What if this happens?”
- “What roadblocks occurred and how did you fix them?”
- Be ready to clarify:
- What you did specifically (not just your team).
- Expect scenario questions and deep follow-ups:
- Step 7: Grow via habits
- Maintain:
- Patience (don’t expect rapid entry without fundamentals/portfolio)
- Curiosity (keep learning beyond daily tasks)
- Consistency suggestion: spend time learning regularly (example given: ~20 minutes/day).
- Maintain:
How identity teams defend (IAM operational workflow)
- Monitor and research
- Read security blogs/news to identify new identity attack patterns
- Example types: MFA fatigue patterns, phishing tactics, evolving auth threats
- Assess exposure
- Determine whether the organization is vulnerable
- Test identity-related controls
- Mitigate
- Build or adjust governance and technical controls based on findings
- Prepare for incidents
- Run tabletop exercises:
- Define what happens if breached
- Identify who to call and which teams to involve
- Run tabletop exercises:
- Stay in a “purple team” mindset
- Combine “offense research” with “defensive implementation and validation.”
Speakers / sources featured (and named people)
People
- Chris (host/interviewer; name stated as “Chris” in the subtitles)
- Andrew Chanthophone (IAM expert/guest; referenced as “Andrew” throughout)
Referenced sources / organizations (as examples)
- BleedingComputer
- Krebs Report
- Black Hat (conference example; passkeys attack discussed)
- Microsoft Entra
- Okta
- SailPoint
- CyberArk (PAM solution)
- Privileged Access Management (PAM)
- NIS guidance on AI governance (exact acronym unclear in subtitles)
- OPA / incident example (referred to as “this hurt OPA a couple years ago”; exact meaning unclear in subtitles)
- Washington Post (example coverage of “forgot to turn off access”)
- HuggingFace (example attack referenced)
- Amazon outage example (described as an AI agent causing a server to go down)