About the Team
The Enterprise Identity team is responsible for designing, building, and evolving the Identity and Access Management (IAM) systems that govern who has access to internal resources and what they can do with that access. Operating within a complex multi‑cloud environment, the team focuses on Zero Trust controls, conditional access policies, automated workflows for onboarding, role transitions, and offboarding, and secure access for autonomous AI agents and service‑to‑service trust models. The team works on privileged access governance, hardening system access, reducing long‑lived elevated privileges, and driving right‑sized entitlements.
About the Role
As a Senior IAM Engineer, you will modernize the design, architecture, and evolution of Workday’s enterprise identity ecosystem. You will secure digital identities across cloud, hybrid, and on‑premises environments, mentor junior engineers, and oversee administration of IAM services in the European Sovereign Cloud.
Responsibilities
- Architecture and Design: Contribute to the design, implementation, and scaling of enterprise IAM solutions, including SSO, MFA, Lifecycle Management, and Directory Services.
- Cloud Identity: Define and implement IAM strategies across multi‑cloud environments (AWS, Azure, GCP), focusing on CBAC, RBAC, PBAC, and ABAC as part of a Zero Trust and Zero Standing Privileges model.
- Automation and DevSecOps: Champion "Identity as Code" by automating provisioning, de‑provisioning, and access review workflows using CI/CD pipelines and scripting.
- Mentorship and Leadership: Provide technical mentorship to mid‑level and junior engineers, establish engineering best practices, and lead incident response for complex identity‑related issues.
- Compliance and Audit: Partner with Risk and Compliance teams to ensure identity practices align with SOC2, ISO 27001, and GDPR.
- Regional Operations Oversight: Provide SRE oversight of IAM services in the European Sovereign Cloud environment.
- AI‑Driven Development: Use AI tools and techniques to accelerate development and improve engineering workflows.
- Automation at Scale: Identify and implement automation opportunities to streamline IAM operations and reduce manual effort.
- AWS IAM Modernization: Contribute to the redesign and modernization of how the team manages IAM in AWS.
Basic Qualifications
- 7+ years of experience in cybersecurity, with at least 5+ years dedicated to IAM engineering and architecture.
- Deep, hands‑on expertise with enterprise IAM platforms (Okta, Ping Identity, ForgeRock, Microsoft Entra ID) and PAM tools (CyberArk, BeyondTrust, Boundary), and directory services (LDAP, Active Directory).
- Deep, hands‑on expertise managing AWS and GCP environments at scale, including configuring and managing EC2, EKS/GKE, AWS IAM, and GCP Cloud IAM.
- Expert‑level understanding of protocols such as SAML 2.0, OIDC, OAuth 2.0, SCIM, LDAP, and Kerberos.
- Proficient in scripting (Go, Python, PowerShell, Bash) and Infrastructure as Code (Terraform) to automate identity workflows.
- Bachelor’s degree in Computer Science or equivalent. Certifications such as CISSP, CIAM, CAMS, or provider‑specific architect certifications (Okta Certified Professional/Consultant) are highly preferred; AWS Certified Solutions Architect is preferred.
Other Qualifications
- Experience designing and implementing security systems, procedures, and protocols to protect information and data.
- Ability to integrate security measures into system design from the outset (Security by Design).
- Experience managing and optimizing cloud resources at scale and implementing cloud security measures.
- Solid foundation in protecting data from unauthorized access, disclosure, disruption, modification, or destruction.
- Experience with security platforms, incident response protocols, threat intelligence, and risk management strategies.
- Ability to manage multiple projects and priorities while maintaining operational responsibilities.
- Excellent written and verbal communication skills, and the ability to build positive relationships across partner organizations.
- A sense of ownership and motivation to move with urgency in a fast‑paced environment.
Workday Pay Transparency Statement (For EU Locations Only)
Primary Location Base Pay Range: €84,000 EUR – €126,000 EUR (Ireland)
Equal Opportunity Employer
Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans. We are committed to providing an accessible and inclusive hiring experience; if you require assistance or an accommodation, please email accommodations@workday.com.