Remote job
Access Engineer & IAM Auditor
Job details
About this role
Role overview
This role focuses on building and operating a structured identity and access management audit program across a complex, multi-system environment. You will assess whether access is appropriate, secure, and compliant; produce evidence-ready findings; and coordinate remediation with technical and application owners.
Responsibilities
- Create the access-audit framework, including methodology, review cadence, evidence requirements, sampling, and reporting templates. - Conduct scheduled and ad-hoc reviews of standard, privileged, and administrative accounts. - Examine cloud identity permissions, directory services, and privileged-access platforms for stale accounts, excessive rights, orphaned access, and configuration issues. - Prepare clear audit reports and evidence packages suitable for internal governance and external review. - Track corrective actions through closure, escalate overdue remediation, and maintain accurate audit records. - Keep runbooks and procedures current, improving the methodology as systems, tools, and compliance expectations evolve.
Requirements
- At least two years of experience in access engineering, IAM auditing, or a comparable security role. - Demonstrated experience designing and implementing an access-audit process from the ground up. - Hands-on knowledge of GCP IAM concepts, including roles, permissions, service accounts, and organization policies, plus LDAP administration. - Experience with PAM tools and reviews of privileged or administrative accounts. - Familiarity with IGA platforms such as One Identity, Okta, Entra ID, or Keycloak. - Working knowledge of ISO 27001, SOC 2, and NIST-related control expectations, with intermediate written and spoken English.
Nice to have
- A dependable, detail-oriented, self-directed working style with strong follow-through. - Collaborative communication and a constructive approach to resolving findings. - A learning mindset, including willingness to acknowledge mistakes and implement preventive improvements.