Role Overview
We are seeking a Senior Platform Engineer with a deep specialization in Identity and Access Management (IAM). In this role, you will not just manage cloud resources; you will architect the "Identity-First" foundation for our multi-cloud environment. You will be responsible for building automated governance frameworks, Zero Trust architectures, and self-service IAM platforms that empower our developers while maintaining rigorous compliance standards (FedRAMP, NIST, or SOC 2).
Key Responsibilities
Platform Engineering: Build and maintain an internal developer platform across AWS and Azure, focusing on automated provisioning using Terraform and ArgoCD.
IAM Automation: Architect and implement automated IAM guardrails and "Policy-as-Code" (using OPA or Sentinel) to enforce least-privilege access across 100+ cloud accounts.
Kubernetes Governance: Secure enterprise EKS/AKS clusters by implementing IRSA (IAM Roles for Service Accounts) and Workload Identity to eliminate static credentials.
Identity Integration: Manage cross-cloud identity synchronization between AWS IAM Identity Center and Microsoft Entra ID (Azure AD).
Security & Compliance: Ensure all platform infrastructure meets FedRAMP/NIST baselines through automated remediation and continuous monitoring.
Secrets Management: Own the lifecycle of credentials and certificates using HashiCorp Vault or cloud-native Secrets Managers.
Technical Requirements
Experience: 10+ years in Cloud/DevOps, with at least 3 years focused on Platform Engineering and IAM.
Multi-Cloud Mastery: Proven experience managing production workloads in both AWS and Azure.
Infrastructure as Code: Expert-level proficiency in Terraform (modular design) and GitOps workflows.
Containers: Deep knowledge of Kubernetes (EKS/AKS), Helm, and service mesh technologies.
Identity Protocols: Strong understanding of OIDC, SAML, OAuth 2.0, and RBAC/ABAC models.
Compliance: Experience working within highly regulated frameworks (FedRAMP, HIPAA, or PCI DSS).