Principal Identity Engineer

Hard Rock Digital

Deutschland

Hybrid

EUR 140.000 - 190.000

Vollzeit

Vor 6 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Eine komplette Bewerbung in einer Minute — maßgeschneiderter Lebenslauf und Anschreiben, versandbereit.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Competitive compensation
Flexible vacation
Hybrid or remote environment
Inclusive hiring

Zusammenfassung

Hard Rock Digital seeks a principal Identity Architect to drive the control plane for security access across a global platform. You will set identity governance, automation, and architecture for employees, admins, and machines.

Reporting to security leadership within a 16-person team, you will own Entra ID, CA policies, and federation, while advancing passwordless methods and just-in-time access in a large SaaS/multi-cloud estate.

Qualifikationen

  • 10+ years in identity and access management, security engineering, or similar field.
  • Hands-on with modern enterprise identity platforms, including CA, PIM/PAM, authentication methods, and governance.
  • Strong knowledge of SAML, OIDC, OAuth 2.0, SCIM, and modern MFA.
  • Experience automating identity lifecycle across large SaaS and multi-cloud estates.
  • Scripting/automation: PowerShell, Microsoft Graph API, or Python; IaC comfort.
  • Track record of least-privilege, just-in-time access in production.

Aufgaben

  • Own the security architecture, standards, authentication methods, and roadmap for Entra ID as primary IDP.
  • Design and refine Conditional Access policies balancing protection with user experience.
  • Rollout phishing-resistant, passwordless authentication methods (passkeys, certificates, FIDO2).
  • Own federation and SSO across SaaS using SAML, OIDC, OAuth 2.0, SCIM provisioning.
  • Oversee privileged access with Entra PIM, including just-in-time elevation and break-glass safeguards.
  • Automate joiner-mover-leaver lifecycle for accurate access provisioning.
  • Build access reviews and entitlement governance with GRC for ISO 27001, SOC 2, PCI DSS.
  • Govern non-human identities across AWS, Azure, GCP.
  • Support Zero Trust program aligned to NIST SP 800-207 and CISA model.
  • Partner with security operations to feed identity signals into detection/response.
  • Advise on customer identity architecture with product security/engineering.

Kenntnisse

IAM
Security architecture
PIM/PAM
Identity protocols
Automation
IaC
Least-privilege access
Communication
AI familiarity

Tools

Microsoft Entra ID
Azure AD
AWS IAM
GCP IAM

Jobbeschreibung

Role overview

This is a principal-level role establishing identity as the control plane for security across a large online gaming and entertainment platform. You will be the technical authority on how access is granted, governed, and revoked for every employee, administrator, and machine across the organization. Reporting into security leadership, the position sits inside a 16-person security organization and serves as the first dedicated identity hire, focused on architecture, automation, and governance rather than day-to-day provisioning.

Responsibilities
  • Own the security architecture, standards, authentication methods, and roadmap for Microsoft Entra ID as the primary identity provider.
  • Design and continuously refine Conditional Access policies that balance strong protection with smooth user experience for a globally distributed workforce.
  • Advance the rollout of phishing-resistant, passwordless authentication such as passkeys, certificate-based, and FIDO2 methods.
  • Own federation and single sign-on across the SaaS estate using SAML, OIDC, OAuth 2.0, and SCIM provisioning.
  • Own the privileged access model with Microsoft Entra PIM, including separate admin identities, just-in-time elevation, and approval workflows, plus break-glass safeguards.
  • Automate the joiner-mover-leaver lifecycle so access is granted, changed, and revoked accurately and promptly.
  • Build and run access reviews and entitlement governance, partnering with GRC on audit evidence for ISO 27001, SOC 2, PCI DSS, and gaming standards.
  • Govern non-human identities including service principals, managed identities, and workload/federated credentials across AWS, Azure, and GCP.
  • Serve as the identity authority for the Zero Trust program, aligned to NIST SP 800-207 and the CISA Zero Trust Maturity Model.
  • Partner with security operations to make identity signals first-class inputs to detection and response.
  • Advise on customer identity and account-security architecture in collaboration with product security and product engineering.
Requirements
  • 10+ years in identity and access management, security engineering, or a closely related field, or equivalent practical experience.
  • Deep, hands-on expertise with a modern enterprise identity platform, including Conditional Access, PIM/PAM, authentication methods, and identity governance.
  • Strong command of identity protocols and patterns such as SAML, OIDC, OAuth 2.0, SCIM, and modern MFA.
  • Experience automating the identity lifecycle and integrating identity across a large SaaS and multi-cloud estate.
  • Scripting and automation skills with PowerShell, Microsoft Graph API, or Python, plus comfort with Infrastructure as Code.
  • A track record of designing least-privilege, just-in-time access in a real production environment.
  • Excellent written and verbal communication, able to explain an access decision to an engineer and a risk to an executive.
  • Fluency with AI tooling and hands-on experience applying AI to security or engineering work.
Nice to have
  • Experience in a regulated industry such as gaming, financial services, or healthcare.
  • Exposure to customer identity and access management at scale.
Benefits and work setup
  • Competitive compensation package with benefits.
  • Flexible vacation allowance.
  • Hybrid or remote working environment.
  • Equal opportunity employer with a stated commitment to inclusive hiring.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

AI/M365 Security and Identity Governance Engineer
AI/M365 Security and Identity Governance Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 130.000
Manager, Platform – Identity Administration
Manager, Platform – Identity Administration

Jobtailor • Deutschland

Vor Ort
EUR 90.000 - 140.000
Identity Engineer – Tier 2
Identity Engineer – Tier 2

Jobtailor • Deutschland

Hybrid
EUR 55.000 - 75.000
Identity and Access Management Engineer I
Identity and Access Management Engineer I

Jobtailor • Deutschland

Remote
EUR 70.000 - 100.000
Senior Microsoft 365 Engineer
Senior Microsoft 365 Engineer

Jobtailor • Deutschland

Hybrid
EUR 90.000 - 120.000
Senior IT – Corporate Engineering
Senior IT – Corporate Engineering

Jobtailor • Deutschland

Hybrid
EUR 110.000 - 150.000
security engineer in identity and access management
security engineer in identity and access management

Enfint • Deutschland

Hybrid
EUR 90.000 - 140.000
Здоровье, стоматология и зрение
Гибкий график
Двухнедельные паузы ч/г
+2
Senior Cyber Security, Microsoft Ecosystem Engineer
Senior Cyber Security, Microsoft Ecosystem Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 120.000
Senior Cloud Identity Engineer (m/f/d)
Senior Cloud Identity Engineer (m/f/d)

Redcare Pharmacy • München

Hybrid
EUR 90.000 - 130.000
Remote work stipend
On-site collaboration when needed
Anchor days travel reimbursement
+2
Senior Cloud Identity Engineer (m/f/d)
Senior Cloud Identity Engineer (m/f/d)

Redcare Pharmacy • Hamburg

Vor Ort
EUR 90.000 - 130.000
Welcome days
Remote working stipend 500€ setup
Anchor days travel reimbursement
+2