Chief IAM Engineer

Summary

Architect and deliver Privileged Access Management (PAM) workflows, API integrations, and custom automation for SaaS credential auto-rotation, secrets lifecycle management, compliance reporting, and access attestations. Core stack: Python/Node.js/Bash, REST APIs/webhooks, Okta Workforce Identity Cloud, Privileged Access and Identity Governance, integrated with Slack, Teams, Jira, Salesforce, Snowf

We are building a Chief IAM Engineer role to extend an enterprise Privileged Access (PA) secrets management and privileged access program. You will architect and deliver custom scripts and Workflows for SaaS credential auto-rotation, lifecycle management, compliance reporting, and access attestations, partnering closely with IAM and Security/GRC teams to close PA gaps—apply now.

Responsibilities

  • Design and implement advanced Workflows to meet enterprise governance needs beyond PA's native capabilities
  • Develop custom scripts and API integrations to automate credential rotation for non-federated local SaaS accounts and connected apps (e.g., Salesforce ECAs, Snowflake Key Pair Auth, Workday), using vendor APIs
  • Create workflows triggered by Lifecycle Management (LCM) events to handle orphaned secrets, dynamically resolve manager routing, and send multi-interval expiration notifications (e.g., T-60, T-30) via Slack, Teams, or Email
  • Implement automated solutions to pull secrets metadata through the OPA API, produce CSV exports, and update external tracking dashboards for rotation success rates, overdue secrets, and orphaned accounts
  • Orchestrate hybrid attestation campaigns by combining PA metadata with Identity Governance (IG) and ITSM tools (e.g., Jira) for annual secret-owner reviews and rotation exception logging
  • Integrate APIs, PA REST endpoints, and third-party systems to enable consistent secrets vaulting and attribute tracking
  • Translate PA functional gaps into engineering solutions by delivering scalable, secure, well-documented workarounds instead of manual processes
  • Build attestation, reporting, and audit-logging flows that withstand SOC 2, ISO 27001, and NIST-style scrutiny
  • Collaborate as the technical bridge between IAM and Security/GRC teams, converting governance requirements into reliable automation

Requirements

  • Proven background in Identity and Access Management for 7+ years, spanning Privileged Access Management (PAM), Secrets Management, Non-Human Identity (NHI) governance, Just-in-Time (JIT) access, and Zero Standing Privileges (ZSP)
  • Deep, hands-on administrative expertise with Workforce Identity Cloud (WIC), Privileged Access (PA), and Identity Governance (IG)
  • Working knowledge of Identity Governance Administration (IGA) concepts
  • Demonstrated track record building, validating, and releasing workflows for orchestration and automation
  • High proficiency in Python, plus Node.js or Bash
  • Hands-on experience with RESTful APIs, JSON, and webhooks to deliver custom integrations and programmatic workarounds
  • Solid understanding of SOC 2, ISO 27001, and NIST, and their impact on privileged credential handling, audit logging, and access attestations
  • Strong ability to assess product constraints and engineer scalable workarounds
  • English proficiency at B2 level or higher

Nice to have

  • Familiarity with SIEM integrations for audit logging
  • Experience with workload identities and runtime secret injection
  • Prior experience in a security engineering capacity within an enterprise environment

Benefits

  • International projects with top brands
  • Work with global teams of highly skilled, diverse peers
  • Healthcare benefits
  • Employee financial programs
  • Paid time off and sick leave
  • Upskilling, reskilling and certification courses
  • Unlimited access to the LinkedIn Learning library and 22,000+ courses
  • Global career opportunities
  • Volunteer and community involvement opportunities
  • EPAM Employee Groups
  • Award-winning culture recognized by Glassdoor, Newsweek and LinkedIn

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available