Staff Identity & Access Management Engineer
Rivianvw Tech · Belgrade · 2026-10-02
About this role
ABOUT US
Rivian and Volkswagen Group Technologies is a joint venture between two industry leaders with a clear vision for automotive’s next chapter. From operating systems to zonal controllers to cloud and connectivity solutions, we’re addressing the challenges of electric vehicles through technology that will set the standards for software-defined vehicles around the world.
The road to the future is uncharted. By combining our expertise across connectivity, AI, security and more, we’ll map a new way forward. Working together, we’ll create a future that’s more connected, more intelligent, more sustainable for everyone.
ROLE SUMMARY
RV Tech is building its enterprise identity program from the ground up, and the Staff IAM Engineer runs it. You are the directly responsible individual for the full identity program: the workforce identity platform, identity governance, privileged access, non-human identities, secrets management, and the Helpdesk operations that sit on top of all of it. You own the outcomes, the roadmap, the team, and the vendors.
This is a player-coach role. You will design and build, lead a small agile team of engineers and contractors, direct external implementation partners, and personally represent identity controls to auditors across multiple certification regimes. You will also be the person who finds a creative way through resource constraints, most often by applying AI engineering and automation where headcount is not available.
RESPONSIBILITIES
PROGRAM LEADERSHIP
- Serve as the directly responsible individual for the enterprise identity program across all of its pillars: workforce identity platform (IdP), identity governance and administration (IGA), privileged access management (PAM), non-human identity (NHI) governance, secrets management, and device trust.
- Own the identity roadmap end to end: define priorities, sequence delivery, manage dependencies across IT, Product, and partner teams, and report status, risks, and decisions to leadership and steering committees.
- Juggle multiple concurrent high-priority projects with shifting priorities; keep each one operationally successful and make explicit, defensible trade-offs when resources conflict.
- Build and lead a small, agile, effective identity team: hire, develop, and set standards for full-time engineers and a contractor workforce.
- Manage external implementation partners and vendors: scope statements of work, hold partners to delivery and quality commitments, control spend, and run vendor evaluations and RFPs for new identity capabilities.
IDENTITY PLATFORM OPERATIONS
- Own operation of the enterprise workforce identity platform: tenant configuration, access policies, MFA and adaptive access, lifecycle automation, and application integrations (SSO and SCIM).
- Lead identity-related Helpdesk operations: own the L2/L3 support model, SLAs, and runbooks; resolve escalations personally when needed; and eliminate recurring ticket classes through automation and self-service.
- Lead the identity workstream in operational and cybersecurity incidents: direct containment (session revocation, credential resets, access suspension), produce post-incident evidence, and own identity-related corrective actions.
- Define platform observability and operational KPIs: alerting on authentication anomalies, policy drift, integration failures, and lifecycle errors.
- Drive stabilization and optimization of the identity platform, including retirement of legacy identity dependencies.
ACCESS GOVERNANCE & AUDIT
- Own quarterly user access reviews (UARs) end to end: scope, reviewer coordination, completion tracking, revocation remediation, and audit-ready records.
- Own identity control design and evidence for the TISAX, ISO 27001, SOC 2, and SOX control environments; serve as the primary identity point of contact for internal and external auditors across all four regimes.
- Own governance of non-human identities (service accounts, service principals, API credentials, machine identities): discovery, ownership attestation, rotation, and decommissioning.
- Detect and remediate excessive privileges and risky entitlements; design preventive controls so they do not recur.
SCALING & GROWTH
- Lead the privileged access management capability: strategy, tool selection, rollout, and operating model.
- Lead the enterprise secrets management program: adoption, developer workflows, and integration with the identity lifecycle.
- Apply AI engineering and automation to scale the identity function: agentic investigation and remediation of access anomalies, automated evidence collection, lifecycle automation, and self-service.
- Build identity data pipelines and governance tooling on the enterprise data platform, feeding identity signals into detection and response.
REQUIRED QUALIFICATIONS
- Bachelor's degree in Computer Science, Information Security, Information Systems, or a related technical field (required).
- 8+ years in identity and access management, with 3+ years as the accountable lead for a production workforce identity program or platform.
- Experience building and leading a small, agile, effective team, including managing a contractor workforce and directing external implementation partners and vendors.
- Deep hands-on experience with major identity platforms, including Okta, Microsoft Entra ID, Ping Identity, or comparable workforce IdPs, including tenant design, policy architecture, and lifecycle automation.
- Expert knowledge of SAML, OIDC, OAuth 2.0, SCIM, and directory services (Entra ID/Active Directory) in hybrid enterprise environments.
- Exemplary written and verbal communication skills, with demonstrated experience presenting identity controls and evidence directly to auditors for TISAX, ISO 27001, SOC 2, and/or SOX.
- Experience leading identity-related Helpdesk or service operations (L2/L3 support model, SLAs, runbooks) and leading identity response…
Skills asked for
- agile
- cybersecurity
- python
- terraform
- databricks
- aws
- gcp
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.