Identity and Access Management (IAM) Engineer

Proton

Paris (KY)

On-site

USD 53,000 - 80,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Stock Options
Strong health coverage
Flexible Working

Job summary

Proton is seeking an experienced IAM Engineer to design and secure our core identity infrastructure. The successful candidate will manage and integrate IAM solutions, working closely with cross-functional teams while ensuring compliance and access control are optimized.

The role requires a strong background in open-source technologies such as Keycloak and midPoint, alongside proficient scripting skills. We offer a competitive compensation range between €53,000 and €80,000 annually, reflective of qualifications and experience.

Qualifications

  • Proven experience as an IAM Engineer in a production environment.
  • Strong hands-on experience with open-source IAM solutions.
  • Strong proficiency in scripting languages for automation.

Responsibilities

  • Design, implement, and maintain IAM solutions.
  • Develop secure automated processes for user lifecycle management.
  • Configure access control and authentication mechanisms.

Skills

IAM expertise
Open-source IAM solutions
Scripting languages (Python, Bash)

Education

Bachelor's degree in a related field

Tools

Keycloak
midPoint
Ansible

Job description

Role Overview

The Identity and Access Management (IAM) Engineer will play a critical role in designing, implementing, and securing Proton's core internal identity infrastructure. As we scale globally, maintaining robust access controls and seamless identity governance is paramount to safeguarding our systems and supporting our growing team across Europe and beyond.

This role bridges modern system engineering, security architecture, and identity lifecycle automation. Sitting within our technical infrastructure and security ecosystem, you will take ownership of our core IAM stack, which leverages a strong foundation of self-hosted, open-source technologies (eg Keycloak, and midPoint) alongside key enterprise solutions like Duo. You will collaborate closely with cross‑functional teams to integrate identity solutions into existing architectures, automate operational workflows, and design Proton-specific access models that strike the perfect balance between strict zero-trust security and team velocity.

What you will do
IAM Architecture & Implementation
  • Design, implement, integrate, and maintain Proton’s core IAM solutions, ensuring high availability, security, and scalability.
  • Manage and maintain systems and applications built on self-hosted, open‑source environments.
  • Collaborate closely with cross‑functional engineering teams to integrate the IAM platform seamlessly into our existing infrastructure and internal tools.
User Lifecycle & Governance
  • Develop, implement, and maintain secure automated processes for user provisioning, de‑provisioning, and overall account lifecycle management to ensure seamless onboarding and offboarding.
  • Design and manage identity governance processes to ensure proper management of user access rights, entitlements, and strict alignment with organizational compliance standards.
  • Conduct regular audits, assessments, and access re‑certification campaigns to proactively discover and remediate access anomalies.
Authentication & Access Control
  • Configure, optimize, and manage access control, authentication, and authorization mechanisms.
  • Develop and enforce granular policies for identity and access management in alignment with organizational security goals.
  • Support, maintain, and contribute to specialized infrastructure projects.
Automation & Systems Engineering
  • Leverage your scripting and automation expertise to eliminate operational toil and streamline identity workflows.
  • Write high‑quality, maintainable code for infrastructure automation and configuration management.
Job requirements
  • Proven experience as an IAM Engineer with a deep focus on identity management within a production environment.
  • Strong, hands‑on experience working with open‑source IAM solutions (e.g., FreeIPA, Keycloak, midPoint).
  • Deep technical understanding of core identity protocols and standards, specifically LDAP, SAML, OAuth, and OIDC.
  • Strong proficiency in scripting languages (e.g., Python, Bash) for automation, integration, and tooling tasks.
  • Solid background in system engineering, particularly with managing, deploying, and maintaining complex self‑hosted solutions.
  • Ability to adapt quickly in a fast‑paced environment.
  • Strong communication and interpersonal skills, with a proven track record of collaborating effectively across engineering and non‑engineering teams.
Preferred qualifications
  • Advanced proficiency in implementing, configuring, and maintaining midPoint.
  • Hands‑on experience with configuration management and infrastructure‑as‑code tools (such as Ansible, Puppet).
  • Prior experience managing identity governance frameworks, including compliance reporting and access re‑certification campaigns.
  • Relevant industry certifications in IAM‑related technologies (e.g., CIDPRO certification).
Success in This Role
  • Proton’s identity lifecycle processes (onboarding, offboarding, and transitions) become fully automated, secure, and seamless.
  • Internal open‑source IAM solutions are robustly engineered, highly available, and perfectly integrated across our infrastructure.
  • Identity governance and re‑certification campaigns are managed effectively with minimal manual overhead and clear auditability.
  • Authentication mechanisms and access controls are optimized to enforce strict security baselines without breaking organizational agility.
What We Offer
  • Work that Matters – millions of people trust Proton with their privacy. Your work here is real and impacts users worldwide.
  • Stock Options – you become an owner from day one.
  • Technology – you receive the right hardware and software to do your best work.
  • Learning & Development – we invest in your growth and give you real challenges and ownership from day one.
  • Employee Benefits – strong health coverage, solid retirement options, generous leave, and wellness support.
  • In‑Person Collaboration – collaboration in offices across Geneva, Zürich, Barcelona, London and more.
  • Food – lunch and snacks in our offices.
  • Transport – coverage for public transport, bike allowance, or parking.
  • Flexible Working – you own your schedule and focus on outcomes.
Our Commitment to Diversity and Inclusion

At Proton, we believe diversity drives innovation and strengthens our mission to provide privacy as a default for all. We are committed to fostering an inclusive environment where all individuals, regardless of race, ethnicity, gender, age, sexual orientation, physical ability, or socio‑economic background, feel valued and empowered. We strive to create equal opportunities, promote open dialogue, and support continuous learning to ensure every voice is heard and respected.

If you need any extra support or reasonable adjustments during the hiring process, please let your talent partner know.

Candidate Privacy Notice

When you apply for a position, refer a candidate, or are considered for a role at Proton Technologies AG (Proton, "we", "us", or "our"), your information is stored in Greenhouse, in accordance with their Service Privacy Policy. This information is used to evaluate your suitability for the posted position. We also retain this information for consideration for future roles that you may apply for or that we believe may align with your background and skills.

If we no longer have a legitimate business need to process your information, we will either delete or anonymize it. Should you have any inquiries about how we use or manage your information, or if you wish to access, correct, or delete your data, please contact our privacy team at careers@proton.ch.

Compensation range

Paris: 53.000 - 80.000 gross annually*
Other locations: Compensation will be discussed during the interview process
*Final compensation will be determined based on the candidate's qualifications, skills, and previous experience

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Reliability Engineer
Network Reliability Engineer

Proton • City of Geneva (NY)

On-site
USD 57,000 - 88,000
Stock options
Benefits package
Learning & development
+4
Senior Machine Learning Engineer (SOC)
Senior Machine Learning Engineer (SOC)

Proton • Paris (TX)

On-site
USD 53,000 - 85,000
Stock Options
In-Person Collaboration
Learning & Development
+2
Staff QA Automation Engineer (Android & iOS)
Staff QA Automation Engineer (Android & iOS)

Proton • Paris (TX)

On-site
USD 74,000 - 113,000
Health coverage
Stock options
Office on-site
+2
Engineering Manager (Apple) - Geneva
Engineering Manager (Apple) - Geneva

Proton • City of Geneva (NY)

Hybrid
USD 120,000 - 150,000
Office First policy
Daily lunch and snacks
Transport cost support
+5
Senior Product Manager (Inbox)
Senior Product Manager (Inbox)

Proton • Germany (OH)

Hybrid
USD 120,000 - 180,000
Stock options
In-person collaboration
Flexible working
Senior Database Platform Engineer
Senior Database Platform Engineer

Proton • Paris (KY)

Hybrid
USD 57,090 - 86,777
Stock options
Health coverage
Flexible working
+2
PR - Communication Manager, US
PR - Communication Manager, US

proton tehnologies • New York (NY)

Hybrid
USD 70,000 - 90,000
Health coverage
Stock options
Flexible working hours
+1
Spam and Abuse Analyst (MSA)
Spam and Abuse Analyst (MSA)

Proton • United States

On-site
USD 90,000 - 130,000
Stock options
Flexible hours
Medical coverage
Software Engineer
Software Engineer

Proton • City of Geneva (NY)

On-site
USD 148,000 - 222,000
Stock options
Technology equipment
Learning & development
+4
Head of Product (Mail)
Head of Product (Mail)

Proton • United States

On-site
USD 180,000 - 260,000
Impactful work
Strong team
Stock options
+4