What You'll Be Doing
Under general supervision, the Security Platform Engineer-IAM is a front-line member of the Identity and Access Management (IAM) team that has responsibility for supporting and evolving enterprise identity, access, and workload identity platforms. The Security Platform Engineer-IAM is responsible for engineering, automation, integration and operational support across cloud permissions, identity governance, privileged access, directory services, SSO/MFA, secrets management, and non-human identity controls.
What We're Looking For
- Contribute to the strategy, design, and management of the enterprise IAM program.
- Design, build, and support identity platform capabilities across cloud, hybrid, and enterprise environments.
- Manage and automate AWS IAM permissions, roles, policies, service accounts, workload identities, and access patterns.
- Develop and maintain Terraform modules, IaC pipelines, and GitOps-based deployment workflows for identity infrastructure.
- Collaborate across teams and business lines to improve IAM solutions, enhance compliance requirements, and Firm best practices.
- Build automation using PowerShell, Python, Terraform, APIs, and CI/CD tooling.
- Support secrets management platforms and patterns, including credential rotation, vault integrations, machine identity, and secure secret consumption.
- Engineer and govern non-human identities, including service accounts, workload identities, application identities, API credentials, and cloud-native identities.
- Build and develop systems and processes to enforce least privilege in a transparent way.
- Partner with security, infrastructure, cloud, DevOps, and application teams to implement secure access patterns.
- Engineer technical configuration changes to deployed solutions.
- Develop documentation to support ongoing IAM systems operations, maintenance and specific problem resolution.
What You'll Bring
- Strong engineering experience in identity, cloud security, infrastructure automation, or access management.
- Hands-on experience with AWS IAM, including roles, policies, permission boundaries, identity federation, service control policy, service-linked roles, and least-privilege design.
- Strong experience with Terraform for infrastructure automation and identity platform configuration.
- Demonstrated understanding of directory services principles.
- Strong scripting skills for automation, administration, reporting, and operational support (PowerShell, Python, Terraform).
- Proven experience designing, deploying, and supporting Identity and Access management platforms and projects.
- Experience with GitOps, source control workflows, pull requests, CI/CD pipelines, and controlled deployment practices.
- Experience with secrets management, credential lifecycle management, vaulting patterns, and secure application authentication.
- Understanding of a broad range of IT disciplines that would impact overall security posture.
- Familiarity with non-human identity, workload identity, service account governance, machine identity, or application identity security.
- Experience with Microsoft Entra ID, including enterprise applications, app registrations, conditional access concepts, SSO, OAuth, MFA, and identity federation.
- Experience with Identity Data Management solutions.
- Knowledge of cloud security frameworks, least privilege, Zero Trust, and identity-first security principles.
- Experience building reusable Terraform modules and policy-as-code controls.
Education & Experience
- Minimum Required: Bachelor's degree in computer science, information systems, cybersecurity, or a related field, or equivalent experience.
- Minimum Required: 4+ years experience in an Information Technology or Information Security role.
Licenses & Credentials
Systems & Technology
- Proficient with Azure and/or AWS security and engineering.
- Experience with Secrets Management platforms.
- Experience integrating identity platforms with DevOps and cloud-native environments.
- Advanced knowledge of PowerShell, Python, Terraform programming language preferred.
- Knowledge of cloud security frameworks, least privilege, Zero Trust, and identity-first security principles.
- Experience with workload identity federation, OIDC, SAML, OAuth, SCIM, Kerberos, LDAP, and certificate-based authentication.
- Experience with privileged access platforms such as CyberArk, BeyondTrust, Delinea, or similar.
- Experience with IGA platforms such as SailPoint, Saviynt, Microsoft Entra ID Governance, or similar.