AWS Cloud Security / IAM Lead

Purple Drive Technologies

$120K — $150K *
Finance & Insurance
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8-12 years of experience in cloud security, IAM, or infrastructure security engineering, preferably in BFSI or regulated sectors.
  • Strong hands-on expertise in AWS security services (IAM, Organizations, Identity Center, KMS, Security Hub).
  • Deep understanding of IAM design, governance, RBAC/ABAC, and least privilege model implementation.
  • Experience with identity provider integrations (e.g., Azure AD, Okta).
  • Ability to manage user access lifecycle and ensure compliance with security standards.

Responsibilities

  • Own the enterprise-wide AWS IAM strategy across multi-account environments.
  • Define and enforce least-privilege access models and IAM governance processes.
  • Lead integration of AWS IAM with enterprise identity providers for secure SSO and federation.
  • Monitor and respond to security alerts using AWS security tools and investigate IAM-related security issues.
  • Manage user access lifecycle, ensuring compliance with regulatory security standards and conducting access audits.
  • Define security guardrails using AWS automation frameworks and partner with teams for security integration.
  • Drive the adoption of policy-as-code and automated compliance checks in CI/CD pipelines.

Benefits

  • Flexible work arrangements and potential remote work options.
  • Opportunities for professional development and continuous learning.
  • Engagement in cutting-edge technologies and security practices.
  • Collaborative work environment with a focus on team-driven success.
  • Comprehensive health and wellness programs.
Full Job Description
Overview:

8
• 8-12 years of experience in cloud security, IAM, or infrastructure security engineering, preferably within BFSI or regulated enterprises.
• Strong hands-on expertise in AWS security services, including:
• AWS IAM (roles, policies, permission boundaries, SCPs)
• AWS Organizations & multi-account governance
• AWS Identity Center (SSO)
• AWS KMS, Secrets Manager
• AWS CloudTrail, Config, GuardDuty, Security Hub
• Deep understanding of IAM design and governance, including:
• Role-based and attribute-based access control (RBAC/ABAC)
• Least privilege model implementation
• Identity lifecycle management (joiner/mover/leaver)
• Experience integrating AWS IAM with enterprise identity providers such as:
• Azure AD / Entra ID
• Okta or similar IdP platforms
• Key Responsibilities
• AWS IAM & Identity Security Leadership
• Own the design and implementation of enterprise-wide AWS IAM strategy across multi-account environments.
• Define and enforce least-privilege access models, including role-based and attribute-based controls.
• Lead integration of AWS IAM with enterprise identity providers (Azure AD/Okta), ensuring secure SSO and federation.
• Establish and maintain IAM governance processes, including access reviews, certification, and audit readiness.
• Cloud Security Operations
• Monitor and respond to security alerts across AWS using tools such as GuardDuty, Security Hub, and CloudWatch.
• Investigate and remediate IAM-related security risks, misconfigurations, and access issues.
• Oversee logging and monitoring strategy using CloudTrail, Config, and centralized SIEM integrations.
• Collaborate with SecOps teams to ensure timely incident response and root cause analysis.
• Access Management & Compliance
• Manage user access lifecycle (provisioning, deprovisioning, entitlement reviews) across AWS environments.
• Ensure compliance with regulatory and enterprise security standards (NIST, CIS benchmarks, etc.).
• Conduct periodi c access audits and enforce remediation of policy violations.
• Support internal and external audits by providing IAM evidence and controls documentation.
• Security Architecture & Governance
• Define and implement security guardrails using AWS Organizations, SCPs, and automation frameworks.
• Partner with platform and application teams to embed security-by-design principles.
• Drive adoption of policy-as-code and automated compliance checks in CI/CD pipelines.
• Provide architectural guidance for secure onboarding of new workloads and services on AWS.

Similar Jobs

More Jobs at Purple Drive Technologies

  • Data Modeler
    $100K — $130K *
    Los Angeles, CA 90011 (Los Angeles County)
    Finance & Insurance
    In-Person
  • ServiceNow Architect
    $120K — $150K *
    Malvern, PA 19355 (Chester County)
    Enterprise Technology
    In-Person
  • Guidewire Lead Developer
    $100K — $130K *
    Plano, TX 75025 (Collin County)
    Finance & Insurance
    In-Person
  • Procurement Engineer
    $70K — $95K *
    Loveland, CO 80538 (Larimer County)
    Manufacturing & Automotive
    In-Person
  • Data Modeler
    $100K — $130K *
    Los Angeles, CA 90011 (Los Angeles County)
    Finance & Insurance
    In-Person

More Finance & Insurance Jobs

Find similar AWS Cloud Security / IAM Lead jobs: