All jobs
Save

Senior Security IAM Engineer

Scopely
Contract type
Ongoing
Work mode
100% remote
Experience
Lead / principal · 10+ years

Job description

Key details

  • Design and operate IAM solutions for global organizations with complex access needs
  • Drive identity modernization, least privilege, and access automation
  • Build automation and reusable engineering patterns for IAM
  • Partner directly with engineering, infrastructure, and security teams
  • Convert manual IAM processes into reusable code-driven workflows
  • Build transferable, scalable access patterns across teams and environments
  • Implement safe production change practices for identity and access automation
  • Support AI-assisted detection, triage, remediation, and documentation
  • Evaluate and safely operationalize AI tooling in security environments
  • Company mission
  • Information not specified

Primary stack

Core technologies

Python (Programming Language)AWSGoogle Cloud Platform (GCP)Terraform

Benefits

  • Information not specified

Requirements & details

  • 8–12+ years in IAM security engineering, cloud security, identity architecture, or related security engineering roles
  • Strong experience operating in cloud-first, high-scale environments
  • Hands-on experience with AWS IAM, AWS Organizations, IAM Identity Center, SCPs, IAM roles and policies, CloudTrail, GuardDuty, IAM Access Analyzer, SSM
  • Hands-on experience with GCP IAM, service accounts, workload identity patterns, organization/folder/project models, and audit services
  • Okta administration including groups, rules, app integrations, assignments, lifecycle management, and troubleshooting
  • SAML, OIDC, OAuth, SCIM, and federated identity design
  • Cross-account and cross-project access controls
  • Service account and workload identity governance
  • Twingate administration or comparable ZTNA and remote access platforms
  • Terraform-based IAM and access automation in production
  • Designing reusable Terraform modules for IAM roles, policies, permission sets, group mappings, and access patterns
  • Terraform state management, drift detection, rollback planning, and safe deployment of IAM changes
  • Git-based workflows, pull requests, and code review for infrastructure and identity changes
  • Python, Bash, PowerShell, or similar scripting languages
  • API integrations and workflow automation
  • Provisioning and deprovisioning automation
  • Access reporting and policy standardization
  • CI/CD integration for identity-related workflows
  • Policy-as-code and automation-first IAM
  • Least privilege and role engineering
  • RBAC and ABAC design
  • Identity threat modeling
  • Privileged access and JIT access models
  • Identity lifecycle management
  • Non-human identity risk reduction
  • Identity logging and monitoring
  • Access reviews and audit readiness
  • Security controls for SaaS and cloud identity systems
  • Experience or strong interest in Claude Code, Codex, and similar AI-assisted engineering tools
  • MCP integrations and agent-based automation workflows
  • Prompt security, model safety, and human-in-the-loop operational controls
  • AWS, GCP, Okta, Terraform, Python, Bash, PowerShell, Git, CI/CD, SAML, OIDC, OAuth, SCIM, Twingate, Claude Code, Codex, MCP
  • Python (Programming Language)
  • AWS
  • Google Cloud Platform (GCP)
  • Terraform

Apply