IAM Security Engineer
Designs and operates identity and access management systems covering federation, governance, privileged access, automation, and Zero Trust controls. Requires hands-on scripting and IAM engineering experience, including production automation and AI/LLM usage.
About the job
Responsibilities
- Design, build, test, and deploy IAM solutions for authentication, authorization, and accounting.
- Use Cloudflare products to secure identities.
- Build SSO integrations using SAML, OIDC, OAuth, and SCIM.
- Build and manage Identity Governance and Administration (IGA), access certification, and Privileged Access Management (PAM) platforms.
- Develop automated roles using RBAC and ABAC.
- Provide operational support for IAM systems, including an on-call rotation that may involve after-hours calls.
Requirements and Preferred Qualifications
- Strong understanding of identity federation, including SAML, OAuth, and OpenID Connect.
- Experience implementing IGA solutions, including lifecycle management, SCIM, birthright access, RBAC, ABAC, and access certifications.
- Production-grade automation scripting and tool development experience.
- Hands-on engineering experience using AI and large language models to solve operational or technical challenges.
- Experience securely configuring containerized application platforms such as Kubernetes.
- Advanced scripting experience with Python, TypeScript, or Bash.
- Experience implementing Zero Trust controls.
- Experience integrating with applications and SaaS solutions.
- Experience applying and enforcing IAM policies.
- Experience with Identity Threat Detection and Response (ITDR).
- Experience with infrastructure as code and configuration management tools such as Terraform and Ansible.
Skills
IAM, SAML, OIDC, OAuth, SCIM, RBAC, Abac, Python, TypeScript, Bash, Kubernetes, Terraform, Ansible, Zero Trust, Pam
Similar jobs
Security Engineering jobsProtects a cloud-native fintech environment by building detections, investigating threats, operating vulnerability management, and automating security workflows. Requires 5+ years in security operations or related fields, strong Python skills, cloud experience, and expertise in telemetry-driven threat detection.
Build and operate automated corporate security controls across endpoint devices, identity, network access, and enterprise AI tooling. The role requires 3–5 years of endpoint, identity, or corporate security experience, strong macOS and Okta expertise, and scripting skills.
Owns hands-on GRC operations for the public-sector business, including FedRAMP/GovRAMP continuous monitoring, POA&M management, vulnerability remediation, audit readiness, and customer-facing compliance content. Requires 4+ years of cybersecurity or compliance experience and direct FedRAMP, GovRAMP, or comparable experience.
Build and improve security analytics, detection, and incident response capabilities by analyzing telemetry, investigating threats, and developing scalable behavioral models and pipelines. Requires 3+ years of security analytics experience, strong Python and SQL skills, and expertise in incident response and forensics.
Reviews and validates real-time physical security alerts, analyzes incident data, documents findings, and escalates potential threats. The role requires strong communication, analytical ability, computer proficiency, attention to detail, and flexibility for overnight or weekend shifts.