Skip to Content

Identity and Access Management - Cloud Identity Security Engineer

--Yoursoft Alternative--

Identity and Access Management - Cloud Identity Security Engineer

  • Job Role: IAM / Cloud Identity Security Engineer
  • Primary Skill: Identity & Access Management (IAM)
  • Skill Level: Journeyman
  • Location: Bucharest / All Romania
  • Language: English

Role Overview

We are looking for an experienced IAM / Cloud Identity Security Engineer to design, implement and support enterprise-scale Identity and Access Management solutions across public cloud and hybrid environments.

The role focuses on authentication, authorization, federation, identity lifecycle management and privileged access, with a strong emphasis on least privilege, Zero Trust and defense-in-depth principles.

The successful candidate will work across AWS, Microsoft Azure, GCP, IBM Cloud and Alibaba Cloud, integrating identity services with enterprise platforms, DevOps tooling, governance solutions and non-human identities.

Key Responsibilities

  • Design, implement and support enterprise-scale Identity and Access Management (IAM) solutions across public cloud and hybrid environments.
  • Apply IAM best practices covering:
    • Authentication
    • Authorization
    • Federation
    • Identity lifecycle management
    • Privileged access management
  • Implement and maintain Joiner–Mover–Leaver (JML) processes.
  • Design access models based on least privilege and role-based access control.
  • Define and maintain RBAC models, entitlement models and access policies.
  • Identify and mitigate privilege escalation risks.
  • Apply Zero Trust and defense-in-depth principles across cloud and hybrid environments.
  • Design and support federated access between enterprise Identity Providers and cloud platforms.
  • Support workforce and administrative access across multiple cloud platforms.
  • Design and maintain identity integrations with DevOps tooling and central governance platforms.
  • Manage identities for applications, workloads, service accounts and other non-human identities.
  • Implement secure approaches for managing:
    • Secrets
    • Credentials
    • Tokens
    • Short-lived access
    • Machine identities
  • Support enterprise identity and access security across AWS, Azure, GCP and other public cloud environments.
  • Troubleshoot IAM-related incidents and access issues.
  • Analyse authentication, authorization and federation failures.
  • Support security investigations involving excessive privileges, inappropriate access or privilege escalation.
  • Contribute to the continuous improvement of IAM architecture, security controls and operational processes.
  • Collaborate with security architects, cloud engineers, DevOps teams, application teams and governance stakeholders.
  • Ensure IAM implementations comply with enterprise security policies and standards.

Required Skills & Experience

  • Bachelor's degree or foreign equivalent in:
    • Computer Engineering
    • Information Technology
    • Software Engineering
    • Information Systems
    • or a related field.
  • 6 years of progressive post-baccalaureate experience in the position offered or a related occupation.
  • Strong foundation in Identity and Access Management (IAM) principles and practices.
  • Deep understanding of:
    • Authentication
    • Authorization
    • Federation
    • Identity lifecycle management
  • Practical understanding of Joiner–Mover–Leaver (JML) processes.
  • Strong understanding of least privilege principles.
  • Knowledge of Zero Trust security principles.
  • Strong understanding of defense-in-depth approaches.
  • Strong knowledge of:
    • RBAC
    • Entitlement models
    • Privilege escalation risks
  • Experience working with identity and access security in cloud and hybrid environments.
  • Strong analytical and troubleshooting skills.
  • Ability to collaborate effectively across security, cloud, infrastructure, DevOps and application teams.
  • A collaborative mindset and strong focus on innovation, security and scalable solutions.
  • Fluent English, written and spoken.

Preferred Skills & Experience

Multi-Cloud IAM

Experience designing and deploying enterprise IAM solutions across one or more of the following:

  • AWS
  • Microsoft Azure
  • Google Cloud Platform (GCP)
  • IBM Cloud
  • Alibaba Cloud

Experience across multiple cloud providers is highly desirable.

Microsoft Entra ID

Strong experience with Microsoft Entra ID (Azure AD) as a central enterprise Identity Provider, including:

  • Conditional Access
  • Multi-Factor Authentication (MFA)
  • Identity Protection
  • Privileged Identity Management (PIM)
  • Enterprise application integrations
  • Identity governance

Federation & SSO

  • Design and support federated authentication between enterprise Identity Providers and cloud platforms.
  • Support workforce and administrative access using federated identity.
  • Experience with SSO and modern federation protocols.
  • Understanding of identity trust relationships and cross-platform authentication.

DevOps & Non-Human Identities

  • Integrate IAM capabilities with DevOps tooling and CI/CD environments.
  • Secure workload identities and service accounts.
  • Manage machine identities and application identities.
  • Implement appropriate access controls for automated workloads.
  • Apply least-privilege principles to service accounts and workloads.

Secrets & Privileged Access

  • Experience managing secrets and credentials securely.
  • Knowledge of short-lived credentials and temporary access mechanisms.
  • Understanding of privileged access management.
  • Experience reducing long-lived credentials and excessive privileges.

Cloud Security

The consultant should have practical knowledge of IAM and security controls within public cloud environments, including:

  • AWS
  • Azure
  • GCP
  • IBM Cloud
  • Alibaba Cloud

Experience supporting cloud environments from an identity and access security perspective is preferred.

Key Competencies

  • Identity & Access Management
  • Cloud IAM
  • Enterprise Identity Management
  • Authentication & Authorization
  • Federation & SSO
  • Identity Lifecycle Management
  • Joiner–Mover–Leaver
  • RBAC & Entitlement Management
  • Privileged Access Management
  • Microsoft Entra ID
  • Conditional Access
  • MFA
  • Identity Protection
  • Zero Trust
  • Least Privilege
  • Workload & Machine Identities
  • Secrets & Credential Management
  • Multi-Cloud Security
  • Hybrid Identity
  • Security Operations & Troubleshooting

Technical Environment

Identity & Access

  • Microsoft Entra ID / Azure AD
  • IAM
  • RBAC
  • Entitlement Management
  • Privileged Identity Management
  • Federation
  • SSO
  • MFA

Cloud

  • AWS
  • Microsoft Azure
  • GCP
  • IBM Cloud
  • Alibaba Cloud

Security

  • Zero Trust
  • Least Privilege
  • Defense in Depth
  • Privileged Access
  • Identity Protection

Workload & DevOps Identity

  • Service Accounts
  • Workload Identities
  • Machine Identities
  • CI/CD & DevOps integrations
  • Secrets & Credential Management
  • Short-lived Access

Education

Mandatory:

Bachelor's degree or foreign equivalent in Computer Engineering, Information Technology, Software Engineering, Information Systems, or a related field.

Experience

Mandatory:

Minimum 6 years of progressive post-baccalaureate professional experience in the offered position or a related occupation.

Seniority Expectations – Journeyman

At Journeyman level, the consultant is expected to have substantial hands-on IAM experience and be capable of independently delivering assigned IAM and cloud identity activities.

The candidate should be able to:

  • Implement IAM solutions based on established enterprise architecture and security requirements.
  • Configure and manage identity, access and authentication controls.
  • Work with RBAC, entitlements and least-privilege models.
  • Troubleshoot authentication, authorization and federation issues.
  • Support Microsoft Entra ID and cloud IAM environments.
  • Implement secure access for workforce, administrative and workload identities.
  • Apply Zero Trust principles to assigned solutions.
  • Collaborate effectively with cloud, DevOps, security and application teams.
  • Contribute to the design and implementation of scalable enterprise IAM solutions.

Position Summary

Item

Details

Recommended Role

IAM / Cloud Identity Security Engineer

Primary Skill

Identity & Access Management (IAM)

Skill Level

Journeyman

Location

Bucharest / All Romania

Language

English

Core Focus

Enterprise IAM & Cloud Identity Security

Cloud Platforms

AWS, Azure, GCP, IBM Cloud, Alibaba Cloud

Key Technology

Microsoft Entra ID

Security Principles

Zero Trust, Least Privilege, Defense in Depth

Identity Scope

Workforce, Privileged, Application & Workload Identities

Recruitment focus: I would prioritise candidates with titles such as IAM Engineer, Cloud IAM Engineer, Identity Security Engineer, Cloud Identity Engineer, IAM Consultant, Identity & Access Management Specialist or Cloud Security Engineer – IAM. The strongest candidates should have demonstrable enterprise IAM + multi-cloud + Entra ID/federation experience rather than a traditional application-security background.