Chief IAM Engineer
Remote in Argentina, & 2 others
Identity and Access Management& 6 others
Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobChoose an option
We are building a Chief IAM Engineer role to extend an enterprise Privileged Access (PA) secrets management and privileged access program. You will architect and deliver custom scripts and Workflows for SaaS credential auto-rotation, lifecycle management, compliance reporting, and access attestations, partnering closely with IAM and Security/GRC teams to close PA gaps—apply now.
Responsibilities
- Design and implement advanced Workflows to meet enterprise governance needs beyond PA's native capabilities
- Develop custom scripts and API integrations to automate credential rotation for non-federated local SaaS accounts and connected apps (e.g., Salesforce ECAs, Snowflake Key Pair Auth, Workday), using vendor APIs
- Create workflows triggered by Lifecycle Management (LCM) events to handle orphaned secrets, dynamically resolve manager routing, and send multi-interval expiration notifications (e.g., T-60, T-30) via Slack, Teams, or Email
- Implement automated solutions to pull secrets metadata through the OPA API, produce CSV exports, and update external tracking dashboards for rotation success rates, overdue secrets, and orphaned accounts
- Orchestrate hybrid attestation campaigns by combining PA metadata with Identity Governance (IG) and ITSM tools (e.g., Jira) for annual secret-owner reviews and rotation exception logging
- Integrate APIs, PA REST endpoints, and third-party systems to enable consistent secrets vaulting and attribute tracking
- Translate PA functional gaps into engineering solutions by delivering scalable, secure, well-documented workarounds instead of manual processes
- Build attestation, reporting, and audit-logging flows that withstand SOC 2, ISO 27001, and NIST-style scrutiny
- Collaborate as the technical bridge between IAM and Security/GRC teams, converting governance requirements into reliable automation
Requirements
- Proven background in Identity and Access Management for 7+ years, spanning Privileged Access Management (PAM), Secrets Management, Non-Human Identity (NHI) governance, Just-in-Time (JIT) access, and Zero Standing Privileges (ZSP)
- Deep, hands-on administrative expertise with Workforce Identity Cloud (WIC), Privileged Access (PA), and Identity Governance (IG)
- Working knowledge of Identity Governance Administration (IGA) concepts
- Demonstrated track record building, validating, and releasing workflows for orchestration and automation
- High proficiency in Python, plus Node.js or Bash
- Hands-on experience with RESTful APIs, JSON, and webhooks to deliver custom integrations and programmatic workarounds
- Solid understanding of SOC 2, ISO 27001, and NIST, and their impact on privileged credential handling, audit logging, and access attestations
- Strong ability to assess product constraints and engineer scalable workarounds
- English proficiency at B2 level or higher
Nice to have
- Familiarity with SIEM integrations for audit logging
- Experience with workload identities and runtime secret injection
- Prior experience in a security engineering capacity within an enterprise environment
