Job Role: IAM Engineer
Location: Dallas TX, NYC (Only Locals)
Experience: 10 years
Skills:
Identity and access management is the primary skill for this role, paired with the ability to deliver features end-to-end from infrastructure through the API layer.
Skill Category
Identity & Security (Primary): Advanced. AWS IAM Identity Center (IdC), SAML/OIDC federation, and integration with an existing enterprise federation / credential-vending model. Attribute-based access control (ABAC) and fine-grained authorization engines such as AWS Verified Permissions or Open Policy Agent (OPA).
AWS Multi-Account Governance: Advanced. AWS Organizations, CloudFormation StackSets, and Org-level APIs and policies. Able to automate resource provisioning at a scale of 15,000 accounts.
Backend Development: Proficient. Python, Java, or Go. Building high-performance REST/API services to query CloudWatch, CloudTrail, and flow logs, with efficient caching strategies and asynchronous data fetching.
Cloud Observability: Advanced. CloudWatch (Metrics, Logs, Alarms, Contributor Insights), CloudWatch cross-account observability / OAM (sink and source configuration), CloudTrail, and flow logs.
Infrastructure as Code : Advanced. Terraform or AWS CDK, with CI/CD pipelines (e.g. GitLab CI) for automated infrastructure deployment.
General Requirements
• AWS Professional or Specialty certification preferred (e.g. Security – Specialty, Solutions Architect – Professional, or DevOps Engineer – Professional, as relevant to the role).
• Prior delivery experience in a large, regulated enterprise environment (financial services strongly preferred); comfortable operating under change-control and audit scrutiny.