Identity and Access Management - Cloud Identity Security Engineer
--Yoursoft Alternative--
Identity and Access Management - Cloud Identity Security Engineer
- Job Role: IAM / Cloud Identity Security Engineer
- Primary Skill: Identity & Access Management (IAM)
- Skill Level: Journeyman
- Location: Bucharest / All Romania
- Language: English
Role Overview
We are looking for an experienced IAM / Cloud Identity Security Engineer to design, implement and support enterprise-scale Identity and Access Management solutions across public cloud and hybrid environments.
The role focuses on authentication, authorization, federation, identity lifecycle management and privileged access, with a strong emphasis on least privilege, Zero Trust and defense-in-depth principles.
The successful candidate will work across AWS, Microsoft Azure, GCP, IBM Cloud and Alibaba Cloud, integrating identity services with enterprise platforms, DevOps tooling, governance solutions and non-human identities.
Key Responsibilities
- Design, implement and support enterprise-scale Identity and Access Management (IAM) solutions across public cloud and hybrid environments.
- Apply IAM best practices covering:
- Authentication
- Authorization
- Federation
- Identity lifecycle management
- Privileged access management
- Implement and maintain Joiner–Mover–Leaver (JML) processes.
- Design access models based on least privilege and role-based access control.
- Define and maintain RBAC models, entitlement models and access policies.
- Identify and mitigate privilege escalation risks.
- Apply Zero Trust and defense-in-depth principles across cloud and hybrid environments.
- Design and support federated access between enterprise Identity Providers and cloud platforms.
- Support workforce and administrative access across multiple cloud platforms.
- Design and maintain identity integrations with DevOps tooling and central governance platforms.
- Manage identities for applications, workloads, service accounts and other non-human identities.
- Implement secure approaches for managing:
- Secrets
- Credentials
- Tokens
- Short-lived access
- Machine identities
- Support enterprise identity and access security across AWS, Azure, GCP and other public cloud environments.
- Troubleshoot IAM-related incidents and access issues.
- Analyse authentication, authorization and federation failures.
- Support security investigations involving excessive privileges, inappropriate access or privilege escalation.
- Contribute to the continuous improvement of IAM architecture, security controls and operational processes.
- Collaborate with security architects, cloud engineers, DevOps teams, application teams and governance stakeholders.
- Ensure IAM implementations comply with enterprise security policies and standards.
Required Skills & Experience
- Bachelor's degree or foreign equivalent in:
- Computer Engineering
- Information Technology
- Software Engineering
- Information Systems
- or a related field.
- 6 years of progressive post-baccalaureate experience in the position offered or a related occupation.
- Strong foundation in Identity and Access Management (IAM) principles and practices.
- Deep understanding of:
- Authentication
- Authorization
- Federation
- Identity lifecycle management
- Practical understanding of Joiner–Mover–Leaver (JML) processes.
- Strong understanding of least privilege principles.
- Knowledge of Zero Trust security principles.
- Strong understanding of defense-in-depth approaches.
- Strong knowledge of:
- RBAC
- Entitlement models
- Privilege escalation risks
- Experience working with identity and access security in cloud and hybrid environments.
- Strong analytical and troubleshooting skills.
- Ability to collaborate effectively across security, cloud, infrastructure, DevOps and application teams.
- A collaborative mindset and strong focus on innovation, security and scalable solutions.
- Fluent English, written and spoken.
Preferred Skills & Experience
Multi-Cloud IAM
Experience designing and deploying enterprise IAM solutions across one or more of the following:
- AWS
- Microsoft Azure
- Google Cloud Platform (GCP)
- IBM Cloud
- Alibaba Cloud
Experience across multiple cloud providers is highly desirable.
Microsoft Entra ID
Strong experience with Microsoft Entra ID (Azure AD) as a central enterprise Identity Provider, including:
- Conditional Access
- Multi-Factor Authentication (MFA)
- Identity Protection
- Privileged Identity Management (PIM)
- Enterprise application integrations
- Identity governance
Federation & SSO
- Design and support federated authentication between enterprise Identity Providers and cloud platforms.
- Support workforce and administrative access using federated identity.
- Experience with SSO and modern federation protocols.
- Understanding of identity trust relationships and cross-platform authentication.
DevOps & Non-Human Identities
- Integrate IAM capabilities with DevOps tooling and CI/CD environments.
- Secure workload identities and service accounts.
- Manage machine identities and application identities.
- Implement appropriate access controls for automated workloads.
- Apply least-privilege principles to service accounts and workloads.
Secrets & Privileged Access
- Experience managing secrets and credentials securely.
- Knowledge of short-lived credentials and temporary access mechanisms.
- Understanding of privileged access management.
- Experience reducing long-lived credentials and excessive privileges.
Cloud Security
The consultant should have practical knowledge of IAM and security controls within public cloud environments, including:
- AWS
- Azure
- GCP
- IBM Cloud
- Alibaba Cloud
Experience supporting cloud environments from an identity and access security perspective is preferred.
Key Competencies
- Identity & Access Management
- Cloud IAM
- Enterprise Identity Management
- Authentication & Authorization
- Federation & SSO
- Identity Lifecycle Management
- Joiner–Mover–Leaver
- RBAC & Entitlement Management
- Privileged Access Management
- Microsoft Entra ID
- Conditional Access
- MFA
- Identity Protection
- Zero Trust
- Least Privilege
- Workload & Machine Identities
- Secrets & Credential Management
- Multi-Cloud Security
- Hybrid Identity
- Security Operations & Troubleshooting
Technical Environment
Identity & Access
- Microsoft Entra ID / Azure AD
- IAM
- RBAC
- Entitlement Management
- Privileged Identity Management
- Federation
- SSO
- MFA
Cloud
- AWS
- Microsoft Azure
- GCP
- IBM Cloud
- Alibaba Cloud
Security
- Zero Trust
- Least Privilege
- Defense in Depth
- Privileged Access
- Identity Protection
Workload & DevOps Identity
- Service Accounts
- Workload Identities
- Machine Identities
- CI/CD & DevOps integrations
- Secrets & Credential Management
- Short-lived Access
Education
Mandatory:
Bachelor's degree or foreign equivalent in Computer Engineering, Information Technology, Software Engineering, Information Systems, or a related field.
Experience
Mandatory:
Minimum 6 years of progressive post-baccalaureate professional experience in the offered position or a related occupation.
Seniority Expectations – Journeyman
At Journeyman level, the consultant is expected to have substantial hands-on IAM experience and be capable of independently delivering assigned IAM and cloud identity activities.
The candidate should be able to:
- Implement IAM solutions based on established enterprise architecture and security requirements.
- Configure and manage identity, access and authentication controls.
- Work with RBAC, entitlements and least-privilege models.
- Troubleshoot authentication, authorization and federation issues.
- Support Microsoft Entra ID and cloud IAM environments.
- Implement secure access for workforce, administrative and workload identities.
- Apply Zero Trust principles to assigned solutions.
- Collaborate effectively with cloud, DevOps, security and application teams.
- Contribute to the design and implementation of scalable enterprise IAM solutions.
Position Summary
Item | Details |
Recommended Role | IAM / Cloud Identity Security Engineer |
Primary Skill | Identity & Access Management (IAM) |
Skill Level | Journeyman |
Location | Bucharest / All Romania |
Language | English |
Core Focus | Enterprise IAM & Cloud Identity Security |
Cloud Platforms | AWS, Azure, GCP, IBM Cloud, Alibaba Cloud |
Key Technology | Microsoft Entra ID |
Security Principles | Zero Trust, Least Privilege, Defense in Depth |
Identity Scope | Workforce, Privileged, Application & Workload Identities |
Recruitment focus: I would prioritise candidates with titles such as IAM Engineer, Cloud IAM Engineer, Identity Security Engineer, Cloud Identity Engineer, IAM Consultant, Identity & Access Management Specialist or Cloud Security Engineer – IAM. The strongest candidates should have demonstrable enterprise IAM + multi-cloud + Entra ID/federation experience rather than a traditional application-security background.