Source description
About the role
Job Summary:
Our client hiring a contractor for a Security Engineer - IAM & Cloud Identity role to join our Information Security team.
This role will focus on identity and access security across our cloud and SaaS environment, with a strong emphasis on IAM automation, least-privilege design, access troubleshooting, and cloud identity risk reduction.
This is a highly technical, hands-on role for someone who can operate across AWS, Okta, GCP, and remote access platforms, and improve the security, repeatability, and auditability of how access is granted and managed across the organization.
Experience:
5+ years of experience in security engineering, IAM engineering, cloud identity, or closely related infrastructure/security roles
Strong hands-on experience with AWS IAM, AWS Organizations, and AWS IAM Identity Center in multi-account environments
Experience managing identity and access in cloud-first environments
Strong working knowledge of Okta administration and identity federation patterns
Strong hands-on experience with AWS IAM, including AWS IAM Identity Center, permission sets, and multi-account access models
Strong Okta administration experience, including groups, rules, app integrations, assignments, and SSO / federation troubleshooting
Experience building or maintaining Terraform-based IAM / access automation
Experience troubleshooting identity and access issues across cloud and SaaS platforms, including SAML, OIDC, group mapping, and permission propagation
Strong understanding of least privilege, RBAC, and IAM risk reduction, including excessive permissions and non-human identity exposure
Experience with remote access security principles and controls, including ZTNA, access policies, network-based restrictions, and VPN-related access controls.
Experience building and maintaining Terraform-based IAM and access automation, including modules, safe change management, and code review workflows
Strong Okta experience, including groups, rules, app integrations, assignments, push groups, and federation troubleshooting
Experience troubleshooting SAML, OIDC, SCIM, access propagation, group mapping, and permission validation
Working knowledge of GCP IAM, service accounts, and cloud identity security concepts
Comfortable reading and editing JSON and YAML
Proficiency with Git-based workflows and pull request review processes
More at System Soft Technologies