Senior Security IAM Engineer
Scopely · ES - Spain · 2026-09-21
Sobre el puesto
Scopely is looking for a Senior IAM Security Engineer to join our Information Security team on a remote basis in Spain. This role will focus on building, scaling, and securing Scopely’s identity and access management ecosystem across our cloud, SaaS, AI, and remote access environments, with a strong emphasis on Terraform-based IAM automation, access workflow engineering, least-privilege design, identity risk reduction, and AI-assisted operational workflows.
This is a highly technical, hands-on role for someone who can operate across AWS, GCP, Okta, AWS IAM Identity Center, Zero Trust access models, identity governance workflows, and modern AI-enabled engineering environments, while building scalable identity systems through Infrastructure as Code, workflow orchestration, and automation-first security engineering.
What You Will Do
Build and Evolve Modern IAM Architecture
• Design and evolve Scopely’s IAM architecture to support a high-scale, cloud-first environment across AWS, GCP, SaaS applications, AI tooling, and remote access platforms.
Lead initiatives around:
• Federated identity architecture using SAML, OIDC, OAuth, and SCIM
• Workforce identity and access patterns across internal platforms
• Least-privilege role design and access segmentation
• RBAC and ABAC models for cloud and SaaS environments
• Centralized access models using Okta, AWS IAM Identity Center, Google Cloud IAM, and cloud-native IAM services
• Secure cross-account and cross-project access patterns
• Service account, workload identity, and non-human identity governance
• Zero Trust identity and access control design
Partner with engineering, infrastructure, and security teams to:
• Standardize secure identity and access patterns
• Reduce identity sprawl and excessive permissions
• Improve access visibility and auditability
• Build scalable identity controls for a fast-moving engineering environment
Own Terraform-Based IAM and Access Automation
• Own and improve Terraform-based IAM and access automation across Scopely’s cloud and identity environment.
Design, build, and maintain:
• Reusable Terraform modules for IAM roles, policies, permission sets, group mappings, and access patterns
• Terraform workflows for Okta app assignments, group-based access, and IAM Identity Center automation
• Standardized access modules that can be reused safely across teams and environments
• Policy-as-code patterns for least privilege and permission boundary enforcement
• Terraform-driven onboarding and offboarding flows for identity-related systems
• Automation for service account and workload identity provisioning
• Access reporting and audit visibility pipelines connected to code-based IAM workflows
Drive improvements in:
• Standardization of IAM modules, variables, role definitions, and policy structures
• Repeatability and consistency of access changes
• Reduction of manual IAM operations
• Auditability and change traceability
• Safe rollout of identity changes through code review and pull request workflows
Ensure mature Terraform engineering practices around:
• State management
• Drift detection and remediation
• Rollback planning
• Blast-radius awareness for IAM changes
• Safe promotion of access changes into production
Automate Identity and Access Workflows
• Build scalable automation for identity lifecycle management, access requests, entitlement changes, access reviews, and day-to-day IAM operations.
Design and implement:
• Provisioning and deprovisioning automation
• Access request and approval workflows
• Group-based access assignment and role mapping
• Okta app integration and assignment automation
• IAM Identity Center permission set automation
• Self-service identity workflows for internal teams
• Identity reporting and access visibility pipelines
• Operational tooling that reduces repetitive IAM work
Work with:
• Terraform and Infrastructure as Code workflows
• Python, Bash, PowerShell, and APIs
• CI/CD systems and Git-based change management
• Okta Workflows and similar orchestration tooling
• ServiceNow, ticketing, and operational workflow integrations
• AI tools such as Claude Code, Codex, and similar engineering assistants
• MCP-enabled integrations, agentic workflows, and internal automation platforms
Drive improvements in:
• Repeatability
• Auditability
• Operational safety
• Reduction of manual IAM work
• Secure-by-default access onboarding
Strengthen Identity Security and Risk Reduction
• Lead initiatives to reduce identity-related risk across human and non-human identities.
Design and implement controls for:
• Excessive permissions and privilege escalation reduction
• Service account and workload identity hardening
• Long-lived credential reduction
• Cross-account trust policy review and hardening
• Permission boundary enforcement
• Role lifecycle management
• Just-in-time and time-bound privileged access
• Break-glass access workflows
• Identity anomaly detection and misuse investigation
Use native and third-party tooling to identify and remediate risk, including:
• AWS IAM Access Analyzer
• CloudTrail
• GuardDuty
• GCP-native IAM and audit services
• Okta System Log and access reporting
• CIEM, CSPM, and related cloud security platforms
Improve Zero Trust and Privileged Access Security
• Partner with IAM, platform, and security teams to strengthen Zero Trust and privileged access controls across Scopely’s environment.
Support and enhance:
• Twingate connectors, resources, and access policy design
• Identity-aware remote access controls
• Zero Trust segmentation for internal applications and privileged systems
• Privileged access workflows
• PAM platform integrations such as Britive
• Adaptive access controls
• MFA and passwordless adoption
• Federated access into AWS, GCP, SaaS platforms, and internal tools
• Secure vendor and contractor access patterns
Drive improvements in:
• Human identity security
•…
Competencias solicitadas
- terraform
- aws
- gcp
- google cloud
- python
- bash
- ci/cd
- r
Tu próximo puesto ya está aquí.
Busca ofertas en directo de miles de empresas, guarda las que merecen una segunda mirada y deja que JobBob vigile el resto.