S
Senior Security IAM Engineer
Scopely
Contract type
Ongoing
Work mode
100% remote
Experience
Lead / principal · 10+ years
Job description
Key details
- Design and operate IAM solutions for global organizations with complex access needs
- Drive identity modernization, least privilege, and access automation
- Build automation and reusable engineering patterns for IAM
- Partner directly with engineering, infrastructure, and security teams
- Convert manual IAM processes into reusable code-driven workflows
- Build transferable, scalable access patterns across teams and environments
- Implement safe production change practices for identity and access automation
- Support AI-assisted detection, triage, remediation, and documentation
- Evaluate and safely operationalize AI tooling in security environments
- Company mission
- Information not specified
Primary stack
Core technologies
Python (Programming Language)AWSGoogle Cloud Platform (GCP)Terraform
Benefits
- Information not specified
Requirements & details
- 8–12+ years in IAM security engineering, cloud security, identity architecture, or related security engineering roles
- Strong experience operating in cloud-first, high-scale environments
- Hands-on experience with AWS IAM, AWS Organizations, IAM Identity Center, SCPs, IAM roles and policies, CloudTrail, GuardDuty, IAM Access Analyzer, SSM
- Hands-on experience with GCP IAM, service accounts, workload identity patterns, organization/folder/project models, and audit services
- Okta administration including groups, rules, app integrations, assignments, lifecycle management, and troubleshooting
- SAML, OIDC, OAuth, SCIM, and federated identity design
- Cross-account and cross-project access controls
- Service account and workload identity governance
- Twingate administration or comparable ZTNA and remote access platforms
- Terraform-based IAM and access automation in production
- Designing reusable Terraform modules for IAM roles, policies, permission sets, group mappings, and access patterns
- Terraform state management, drift detection, rollback planning, and safe deployment of IAM changes
- Git-based workflows, pull requests, and code review for infrastructure and identity changes
- Python, Bash, PowerShell, or similar scripting languages
- API integrations and workflow automation
- Provisioning and deprovisioning automation
- Access reporting and policy standardization
- CI/CD integration for identity-related workflows
- Policy-as-code and automation-first IAM
- Least privilege and role engineering
- RBAC and ABAC design
- Identity threat modeling
- Privileged access and JIT access models
- Identity lifecycle management
- Non-human identity risk reduction
- Identity logging and monitoring
- Access reviews and audit readiness
- Security controls for SaaS and cloud identity systems
- Experience or strong interest in Claude Code, Codex, and similar AI-assisted engineering tools
- MCP integrations and agent-based automation workflows
- Prompt security, model safety, and human-in-the-loop operational controls
- AWS, GCP, Okta, Terraform, Python, Bash, PowerShell, Git, CI/CD, SAML, OIDC, OAuth, SCIM, Twingate, Claude Code, Codex, MCP
- Python (Programming Language)
- AWS
- Google Cloud Platform (GCP)
- Terraform
