Skip To Main Content
backBack to Search

Lead IAM Engineer

Remote in Argentina, & 2 others
Identity and Access Management& 6 others
Looking for something else?

Find a vacancy that works for you. Send us your CV to receive a personalized offer.

Find me a job

We are seeking a highly skilled Lead IAM Engineer to support an enterprise secrets management and privileged access program built on Privileged Access (PA). PA covers most of the ground, but several business requirements sit outside its native capabilities: you'll design, build, and deploy custom scripts and Workflows to close those gaps: SaaS credential auto-rotation, lifecycle management, compliance reporting, and access attestations, working closely with the IAM and Security/GRC teams.

Responsibilities
  • Design and build complex Workflows to fulfill enterprise governance requirements that fall outside PA's native capabilities
  • Develop custom scripts and API integrations to automate credential rotation for non-federated local SaaS accounts and connected apps (e.g., Salesforce ECAs, Snowflake Key Pair Auth, Workday), using vendor APIs
  • Build workflows triggered by Lifecycle Management (LCM) events to manage orphaned secrets, dynamically resolve manager routing, and trigger multi-interval expiration notifications (e.g., T-60, T-30) via Slack, Teams, or Email
  • Develop automated solutions to extract secrets metadata via the OPA API, generate CSV exports, and populate external tracking dashboards for rotation success rates, overdue secrets, and orphaned accounts
  • Orchestrate hybrid attestation campaigns by integrating PA metadata with Identity Governance (IG) and ITSM tools (e.g., Jira) for annual secret-owner reviews and rotation exception logging
  • Interact with APIs, PA REST endpoints, and third-party systems to ensure seamless secrets vaulting and attribute tracking
  • Treat PA's functional gaps as engineering problems rather than blockers, and design scalable, secure, well-documented workarounds in place of manual processes
  • Build attestation, reporting, and audit-logging flows that hold up under SOC 2, ISO 27001, and NIST-style scrutiny
  • Operate as the technical bridge between IAM and Security/GRC teams, and translate governance requirements into working automation
Requirements
  • 5+ years of experience in Identity and Access Management, with strong background across Privileged Access Management (PAM), Secrets Management, Non-Human Identity (NHI) governance, Just-in-Time (JIT) access, and Zero Standing Privileges (ZSP)
  • Deep, hands-on administrative expertise with Workforce Identity Cloud (WIC), Privileged Access (PA), and Identity Governance (IG)
  • Working knowledge of Identity Governance Administration (IGA) concepts
  • Proven track record building, testing, and deploying workflows for orchestration and automation
  • High proficiency in Python, plus Node.js or Bash
  • Hands-on experience with RESTful APIs, JSON, and webhooks to build custom integrations and programmatic workarounds
  • Solid understanding of SOC 2, ISO 27001, and NIST, and how they apply to privileged credential handling, audit logging, and access attestations
  • Ability to analyze product limitations and engineer scalable workarounds
  • English proficiency at B2 level or higher
Nice to have
  • Familiarity with SIEM integrations for audit logging
  • Experience with workload identities and runtime secret injection
  • Prior experience in a security engineering capacity within an enterprise environment