Senior Security IAM Engineer

Hidden Jobs

United States

Hybrid

USD 125,000 - 171,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Remote-first
Hybrid in Barcelona

Job summary

Hidden Jobs is seeking a senior IAM engineer to design, scale, and secure identity and access management across cloud, SaaS, AI, and remote environments in the Barcelona area.

The role focuses on IaC-driven IAM automation, least-privilege architecture, and AI-assisted workflows, partnering with security and engineering teams to reduce identity sprawl and improve access visibility.

Qualifications

  • Deep experience designing IAM architecture across cloud and SaaS
  • Hands-on Terraform for IAM and access automation
  • Familiar with federated identity protocols (SAML, OIDC, OAuth, SCIM) and RBAC/ABAC modeling
  • Programming/scripting with Python, Bash, PowerShell; CI/CD and Git

Responsibilities

  • Design and evolve IAM architecture for cloud-first, multi-account environments.
  • Advance federated identity using SAML, OIDC, OAuth, and SCIM; drive least-privilege design across cloud and SaaS.
  • Own Terraform-based IAM automation with reusable modules for roles, policies, and access patterns.
  • Automate identity lifecycle workflows including provisioning, deprovisioning, access requests, and reviews.
  • Partner with engineering, infrastructure and security teams to standardize secure identity patterns and improve access visibility.
  • Mature Terraform practices around state management, drift detection, rollback planning, and safe promotion of access changes.

Skills

IAM architecture
Terraform
Federated identity
SAML/OIDC/OAuth
RBAC/ABAC
Python scripting
Okta Workflows

Tools

Terraform
Okta Workflows
APIs

Job description

Role overview

This senior engineering role sits on an Information Security team and focuses on designing, scaling, and securing the identity and access management ecosystem across cloud, SaaS, AI, and remote access environments. It is a highly technical, hands-on position centered on Infrastructure as Code-driven IAM automation, least-privilege architecture, and AI-assisted operational workflows. The work spans AWS, GCP, Okta, AWS IAM Identity Center, Zero Trust models, identity governance, and modern AI-enabled engineering tooling.

Responsibilities
  • Design and evolve IAM architecture to support a high-scale, cloud-first environment spanning AWS, GCP, SaaS applications, AI tooling, and remote access platforms.
  • Advance federated identity using SAML, OIDC, OAuth, and SCIM; drive least-privilege role design, RBAC and ABAC models, and Zero Trust access controls across cloud and SaaS.
  • Own Terraform-based IAM automation, building reusable modules for roles, policies, permission sets, group mappings, and standardized access patterns.
  • Automate identity lifecycle workflows including provisioning, deprovisioning, access requests, approvals, access reviews, and self-service tooling for internal teams.
  • Partner with engineering, infrastructure, and security teams to standardize secure identity patterns, reduce identity sprawl, and improve access visibility and auditability.
  • Mature Terraform engineering practices around state management, drift detection, rollback planning, blast-radius awareness, and safe promotion of access changes.
Requirements
  • Deep experience designing IAM architecture across AWS, GCP, Okta, and AWS IAM Identity Center in cloud-first, multi-account environments.
  • Strong hands-on expertise with Terraform for IAM and access automation, including reusable modules, policy-as-code, and Infrastructure as Code workflows.
  • Proficiency with federated identity protocols (SAML, OIDC, OAuth, SCIM) and RBAC/ABAC modeling for cloud and SaaS workloads.
  • Working knowledge of Python, Bash, PowerShell, APIs, CI/CD systems, and Git-based change management.
  • Experience with orchestration tooling such as Okta Workflows and ticketing or ITSM integrations such as ServiceNow.
  • Familiarity with AI-assisted engineering assistants and AI-enabled operational workflows applied to IAM.
Nice to have
  • Background in non-human identity governance, workload identity, and service account lifecycle management.
  • Experience operating within fast-moving engineering organizations with cross-account and cross-project access patterns.
Benefits and work setup
  • Remote-first arrangement, with a hybrid option available for candidates based in the Barcelona area.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior+ IAM Engineer
Senior+ IAM Engineer

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 300,000
Healthcare coverage
Vision & dental
HSA/FSA
+7
Staff Security Engineer, IAM
Staff Security Engineer, IAM

GitLab • United States

On-site
USD 180,000 - 240,000
Sr. IAM Engineer
Sr. IAM Engineer

Pho Prime, LLC • Shelton (CT)

On-site
USD 120,000 - 170,000
Mobility Allowance
Information Security Engineer
Information Security Engineer

Motion Recruitment • Charlotte (NC)

On-site
USD 110,000 - 150,000
Principle Engineer
Principle Engineer

Neutrino Advisory, an Inc 5000 Company • Dallas (TX)

On-site
USD 150,000 - 210,000
Senior Identity Security Engineer
Senior Identity Security Engineer

Talent Mappers • Illinois

Hybrid
USD 140,000 - 160,000
Senior IAM Engineer
Senior IAM Engineer

Cleartech Recruiting • Denver (CO)

On-site
USD 120,000 - 180,000
IAM Engineer
IAM Engineer

The Clearing House • North Carolina

Hybrid
USD 90,000 - 130,000
Senior IAM Engineer
Senior IAM Engineer

Cleartech Recruiting • Chicago (IL)

On-site
USD 120,000 - 180,000
Senior IAM Engineer
Senior IAM Engineer

Cleartech Recruiting • Austin (TX)

On-site
USD 120,000 - 150,000