Remote job
Senior Security IAM Engineer
Job details
About this role
Role overview
This senior engineering role sits on an Information Security team and focuses on designing, scaling, and securing the identity and access management ecosystem across cloud, SaaS, AI, and remote access environments. It is a highly technical, hands-on position centered on Infrastructure as Code-driven IAM automation, least-privilege architecture, and AI-assisted operational workflows. The work spans AWS, GCP, Okta, AWS IAM Identity Center, Zero Trust models, identity governance, and modern AI-enabled engineering tooling.
Responsibilities
- Design and evolve IAM architecture to support a high-scale, cloud-first environment spanning AWS, GCP, SaaS applications, AI tooling, and remote access platforms. - Advance federated identity using SAML, OIDC, OAuth, and SCIM; drive least-privilege role design, RBAC and ABAC models, and Zero Trust access controls across cloud and SaaS. - Own Terraform-based IAM automation, building reusable modules for roles, policies, permission sets, group mappings, and standardized access patterns. - Automate identity lifecycle workflows including provisioning, deprovisioning, access requests, approvals, access reviews, and self-service tooling for internal teams. - Partner with engineering, infrastructure, and security teams to standardize secure identity patterns, reduce identity sprawl, and improve access visibility and auditability. - Mature Terraform engineering practices around state management, drift detection, rollback planning, blast-radius awareness, and safe promotion of access changes.
Requirements
- Deep experience designing IAM architecture across AWS, GCP, Okta, and AWS IAM Identity Center in cloud-first, multi-account environments. - Strong hands-on expertise with Terraform for IAM and access automation, including reusable modules, policy-as-code, and Infrastructure as Code workflows. - Proficiency with federated identity protocols (SAML, OIDC, OAuth, SCIM) and RBAC/ABAC modeling for cloud and SaaS workloads. - Working knowledge of Python, Bash, PowerShell, APIs, CI/CD systems, and Git-based change management. - Experience with orchestration tooling such as Okta Workflows and ticketing or ITSM integrations such as ServiceNow. - Familiarity with AI-assisted engineering assistants and AI-enabled operational workflows applied to IAM.
Nice to have
- Background in non-human identity governance, workload identity, and service account lifecycle management. - Experience operating within fast-moving engineering organizations with cross-account and cross-project access patterns.
Benefits and work setup
- Remote-first arrangement, with a hybrid option available for candidates based in the Barcelona area.