GCP IAM Lead / Manager

Globant

New York (NY)

On-site

USD 90,000 - 140,000

Full time

40 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Globant is seeking an experienced GCP IAM Lead/Manager to support a Deloitte project team delivering secure, scalable cloud identity and access management capabilities. You will own the design, governance, and delivery of GCP IAM across onboarding efforts.

The ideal candidate has deep hands-on GCP IAM expertise, strong Terraform and infrastructure-as-code governance experience, and a security-by-design mindset.

Qualifications

  • 7+ years in identity and access management or cloud security.
  • Hands-on experience designing GCP IAM in enterprise environments.
  • Terraform and infrastructure-as-code governance experience.
  • Ability to communicate technical controls to both technical and nontechnical audiences.

Responsibilities

  • Lead the design and implementation of GCP IAM solutions for onboarding and migration.
  • Define and maintain IAM reference architectures, RBAC models, and service-account strategy.
  • Establish secure-by-default IAM standards with least privilege and auditability.
  • Develop and govern Terraform standards for IAM, including module patterns and drift management.
  • Lead IAM design reviews and provide guidance to engineering teams.
  • Evaluate and approve IAM exceptions with documented risks and controls.
  • Partner with cybersecurity, risk, and compliance stakeholders to define access-control requirements.
  • Configure and manage IAM roles, policies, groups, service accounts, and privileged access controls.
  • Maintain secure service-account practices and lifecycle management.
  • Support authentication and authorization requirements across GCP projects and data platforms.

Skills

GCP IAM
Terraform
IAM governance
Security by design
Stakeholder mgmt
RBAC design
Onboarding governance

Tools

Terraform

Job description

Location

New York, NY

Compensation

$90,000–$140,000 annually

Employment Type

Full-time

Position Summary

We are seeking an experienced GCP IAM Lead / Manager to support a Deloitte project team delivering secure, scalable cloud identity and access management capabilities. This role will own the design, governance, and delivery of Google Cloud Platform (GCP) Identity and Access Management solutions across multiple onboarding efforts.

The ideal candidate has deep hands‑on GCP IAM expertise, strong Terraform and infrastructure‑as‑code governance experience, and a security‑by‑design mindset. You will establish repeatable IAM patterns, guide engineering teams through implementation, manage access‑control risks and exceptions, and partner with security and compliance stakeholders to support audit‑ready delivery.

This role is well suited for an IAM leader who can balance architecture, delivery execution, governance, and operational support in a complex enterprise environment. The work will emphasize least‑privilege access, resource‑level permissions, well‑managed service accounts, documented controls, and scalable onboarding standards. Google recommends granting roles at the smallest practical scope, avoiding broad basic roles in production, and using separate service accounts with narrowly scoped privileges for distinct application components.cloud.google+1

Key Responsibilities
  • Lead the design and implementation of GCP IAM solutions supporting enterprise cloud onboarding and migration initiatives.
  • Define and maintain IAM reference architectures, including role‑based access control (RBAC) models, group‑based access patterns, service account strategy, privileged‑access patterns, and authentication and authorization controls.
  • Establish secure‑by‑default IAM standards for Google Cloud environments, with a focus on least privilege, segregation of duties, role scoping, temporary access, and auditability.
  • Develop and govern Terraform standards for IAM, including reusable module patterns, safe role‑binding strategies, code‑review requirements, change controls, and drift‑management practices.
  • Lead IAM design reviews and provide technical guidance to engineering teams implementing cloud access controls.
  • Evaluate and approve IAM exceptions; document risks, compensating controls, remediation plans, and approval decisions.
  • Partner with cybersecurity, risk, compliance, platform engineering, application teams, and project stakeholders to define and implement access‑control requirements.
  • Configure and manage IAM roles, policies, groups, service accounts, permissions, conditional access, and privileged‑access controls.
  • Design and maintain secure service‑account practices, including dedicated application identities, minimal permissions, lifecycle management, access reviews, and reduction of unnecessary service‑account keys.
  • Support user authentication and authorization requirements across GCP projects, applications, APIs, services, and data platforms.
  • Troubleshoot and resolve IAM‑related access, authentication, authorization, provisioning, policy, and service‑account issues.
  • Manage delivery across multiple onboarding efforts, including priorities, timelines, dependencies, risks, and stakeholder communications.
  • Define the IAM operating model, including runbooks, incident‑response procedures, access‑request processes, access recertification inputs, monitoring, and support escalation paths.
  • Conduct regular IAM audits, access reviews, policy assessments, and compliance checks against established security standards and project requirements.
  • Develop and maintain technical documentation for IAM architectures, configurations, policies, implementation procedures, operational processes, and audit evidence.
  • Track and report IAM delivery metrics, onboarding progress, exceptions, remediation activities, operational incidents, and control effectiveness.
Required Qualifications
  • 7+ years of experience in identity and access management, cloud security, cybersecurity engineering, or related technical roles.
  • Strong hands‑on experience designing and implementing GCP IAM solutions in enterprise environments.
  • Demonstrated experience developing IAM architecture patterns for complex cloud environments, including RBAC, service accounts, privileged access, authorization models, and least‑privilege controls.
  • Experience leading multiple technical workstreams, engineering teams, or cloud onboarding efforts.
  • Strong experience with Terraform and infrastructure as code, including IAM modules, policy management, code review, change control, and deployment governance.
  • Experience implementing and managing IAM policies, roles, permissions, groups, service accounts, authentication, authorization, and access reviews.
  • Knowledge of cloud‑security concepts, including least privilege, segregation of duties, privileged access, access lifecycle management, logging, auditing, and incident response.
  • Experience troubleshooting identity, authentication, authorization, and access‑control issues in a cloud environment.
  • Strong stakeholder‑management skills and the ability to communicate technical controls, risks, design decisions, and implementation requirements to technical and nontechnical audiences.
  • Ability to create clear technical documentation, runbooks, process flows, standards, and audit‑support materials.
Preferred Qualifications
  • Experience in financial services, consulting, banking, wealth management, insurance, or another highly regulated industry.
  • Experience working on large‑scale cloud migration, cloud transformation, application onboarding, or enterprise platform modernization initiatives.
  • Familiarity with Google Cloud security services, organization policies, Cloud Identity, Google Workspace, Cloud Logging, Security Command Center, or IAM Recommender.
  • Experience with access recertification, identity governance and administration (IGA), privileged access management (PAM), or entitlement‑management processes.
  • Experience with CI/CD pipelines and automated Terraform deployment practices.
  • Knowledge of compliance and control frameworks, such as NIST, SOC 2, ISO 27001, PCI DSS, SOX, or internal risk‑management standards.
  • Relevant certifications, such as Google Professional Cloud Security Engineer, Google Professional Cloud Architect, CISSP, CISM, CCSP, or Terraform Associate.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Google Cloud Platform IAM Lead
Google Cloud Platform IAM Lead

CORE Occupational Medicine • Plano (TX)

On-site
USD 140,000 - 190,000
Cloud IAM Governance Lead (GCP)
Cloud IAM Governance Lead (GCP)

Heitmeyer Consulting • Brooklyn (OH)

On-site
USD 140,000 - 180,000
Cloud IAM Technician
Cloud IAM Technician

SPECTRAFORCE • United States

On-site
USD 100,000 - 130,000
Senior GCP IAM Lead | Terraform & Security Architect
Senior GCP IAM Lead | Terraform & Security Architect

Globant • New York (NY)

On-site
USD 90,000 - 140,000
Senior GCP Security Engineer
Senior GCP Security Engineer

Madison-Davis, LLC • New York (NY)

On-site
USD 180,000 - 240,000
Security Engineer
Security Engineer

KPG99 INC • New York (NY)

On-site
USD 150,000 - 230,000
GCP Architect
GCP Architect

Compunnel, Inc. • Mount Laurel Township (NJ)

On-site
USD 120,000 - 150,000
GCP Cloud Security Architect
GCP Cloud Security Architect

Donyati • United States

On-site
USD 140,000 - 180,000
GCP IAM Lead - Secure-by-Default Identity at Scale
GCP IAM Lead - Secure-by-Default Identity at Scale

CORE Occupational Medicine • Plano (TX)

On-site
USD 140,000 - 190,000
GCP Platform Engineering SME
GCP Platform Engineering SME

VDart Inc • United States

Remote
USD 138,000 - 248,000
Remote work