Remote job
Senior Security IAM Engineer
Job details
About this role
Role overview A senior engineer is sought to design, scale, and secure the identity and access management (IAM) ecosystem across a high-scale, cloud-first environment spanning AWS, GCP, SaaS, AI tooling, and remote access platforms. The role is highly technical and hands-on, with a strong emphasis on Terraform-based IAM automation, least-privilege design, workflow orchestration, and the integration of AI-assisted workflows into identity operations. It suits someone comfortable operating across multiple cloud and identity stacks while building repeatable, code-driven IAM systems.
Responsibilities - Design and evolve federated and centralized IAM architecture across cloud, SaaS, and AI tooling using protocols such as SAML, OIDC, OAuth, and SCIM. - Build least-privilege, RBAC, and ABAC models, including secure cross-account and cross-project access, workload identity, and non-human identity controls. - Own Terraform-based IAM and access automation, including reusable modules for roles, policies, permission sets, group mappings, and onboarding/offboarding flows. - Implement provisioning and entitlement flows, access request and approval workflows, group-based assignment, and access review automation. - Drive engineering practices around state management, drift detection, rollback planning, blast-radius awareness, and code-review-based change promotion. - Partner with engineering, infrastructure, and security teams to standardize identity patterns, reduce identity sprawl, and improve auditability.
Requirements - Deep, hands-on experience with IAM across AWS and GCP, including services such as AWS IAM Identity Center and Google Cloud IAM. - Strong proficiency with Okta and modern identity governance, Zero Trust access models, and identity lifecycle operations. - Demonstrated expertise in Terraform and Infrastructure as Code for IAM, including module design, policy-as-code, and CI/CD-driven change management. - Proficiency in at least one general-purpose language (for example Python, Bash, or PowerShell) for building automation and operational tooling. - Solid understanding of least-privilege design, permission boundaries, and audit/traceability requirements for production IAM changes. - Experience integrating IAM work with ticketing systems and workflow orchestration tools.
Nice to have - Familiarity with AI-assisted engineering assistants, agent-style coding tools, or MCP-enabled development environments. - Experience building self-service identity workflows and access visibility/reporting pipelines for non-security stakeholders.