Summary:
We are looking for an experienced IAM Security Engineer/Sec OPS to be a part of the IT Security team. As a security engineer, you will work with a highly specialized team with the primary task of improving security and automating processes across the organization.
Responsibilities:
- IAM Architecture & Implementation:
- Design and implement identity and access management solutions across AWS, Azure, GCP, and OCI.
- Develop and maintain role-based access control (RBAC) and attribute-based access control (ABAC) frameworks.
- Establish and enforce least privilege access principles across all cloud platforms.
- Design and implement federated identity solutions using SAML, OAuth 2.0, and OIDC.
- Create and manage service accounts, IAM roles, policies, and permission boundaries.
- Implement and maintain secure authentication mechanisms including MFA/2FA.
- Automation & DevOps Integration:
- Develop Infrastructure as Code (IaC) solutions for IAM using Terraform, CloudFormation, ARM templates.
- Build CI/CD pipelines for automated IAM policy deployment and testing.
- Create automated workflows for user provisioning, de-provisioning, and access reviews.
- Develop scripts and tools for IAM auditing and reporting.
- Governance & Operations:
- Establish IAM governance frameworks and access request workflows.
- Create and maintain documentation for IAM procedures and runbooks.
- Provide IAM expertise and guidance to development and operations teams.
- Manage privileged access management (PAM) solutions.
- Coordinate with security, compliance, and engineering teams.
- Perform access certifications and periodic access reviews.
- Collaborate with cross-functional teams to identify, troubleshoot, and resolve IAM issues.
Requirements:
- 5 years of experience in Identity and Access Management.
- 3 years of hands-on experience with AWS IAM (policies, roles, SCP, permission boundaries).
- 3 years of experience with Azure AD/Entra ID, Azure RBAC, and Managed Identities.
- 2 years of experience with GCP IAM (roles, service accounts, workload identity).
- 1 year of experience with OCI IAM (compartments, policies, dynamic groups).
- 3 years of DevOps/automation experience with infrastructure as code.
- Bachelor's degree in Computer Science, Information Security, or related field or equivalent experience.
Required Skills:
- Cloud IAM Platforms:
- AWS: IAM, Organizations, SSO, Cognito, Secrets Manager, KMS, STS, IAM Identity Center.
- Azure: RBAC, Managed Identities, Key Vault, Conditional Access, PIM.
- GCP: Cloud IAM, Identity Platform, Workload Identity, Secret Manager, Cloud KMS.
- OCI: Identity and Access Management, Identity Domains, Federation, Compartments.
- Automation & DevOps:
- Strong proficiency in scripting languages (Python, Bash, PowerShell, Go).
- Expert knowledge of Infrastructure as Code tools (Terraform, CloudFormation, Pulumi, ARM templates).
- Experience with CI/CD platforms (Jenkins, GitLab, Harness).
- Version control with Git and GitOps workflows.
- Container and orchestration platforms (Docker, Kubernetes, EKS, AKS, GKE).
- Security & Identity Standards:
- Deep understanding of OAuth 2.0, OpenID Connect, SAML 2.0, LDAP.
- Knowledge of identity federation and Single Sign-On (SSO) solutions.
- Experience with identity providers (Okta).
- Understanding of zero trust architecture principles.
- Familiarity with certificate-based authentication and PKI.
- Soft Skills:
- Strong analytical and problem-solving abilities.
- Excellent written and verbal communication skills.
- Ability to work independently and in cross-functional teams.
- Strong documentation skills.
- Detail-oriented with focus on security best practices.
- Ability to mentor and guide junior team members.
Preferred Skills:
- Certifications:
- AWS Certified Security - Specialty.
- AWS Certified Solutions Architect - Professional.
- Azure Security Engineer Associate (AZ-500).
- Azure Solutions Architect Expert (AZ-305).
- Google Professional Cloud Security Engineer.
- Google Professional Cloud Architect.
- Oracle Cloud Infrastructure Architect Associate/Professional.
- Certified Information Systems Security Professional (CISSP).
- Certified Cloud Security Professional (CCSP).
- Additional Experience:
- Experience with privileged access management (PAM) tools (CyberArk, BeyondTrust, HashiCorp Vault).
- Knowledge of identity governance and administration (IGA) platforms (SailPoint, Saviynt).
#AditiConsulting
# 26-02546