Sr. Identity and Access Management Engineer
Hace 1 día
Madrid, Community of Madrid, España
OneTrust
Jornada completa
Gratis con email o Google
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Gratis con email o Google
Sr. Identity and Access Management Engineer
Madrid, Spain Strength in Trust
OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™ unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society. The Challenge
As a Senior IAM Engineer, you will design, build, and operate core identity security capabilities across the enterprise. This includes
Identity Governance & Administration (IGA) architecture ,
Privileged Access Management (PAM) , and
secrets management , as well as the automation and integrations that enable secure access at scale. This role is responsible for multiple areas of IAM
(not just a single platform), and will contribute at a strategy, design, and execution level—partnering with Security, IT, and Engineering teams to deliver secure, reliable identity services. Your Mission
IAM / IGA Architecture & Engineering Architect and implement
IGA capabilities
including identity lifecycle (joiner/mover/leaver), access request workflows, approvals, provisioning/deprovisioning automation, certifications, and role/entitlement governance. Design and maintain the
identity lifecycle management (ILM) framework and controls
across the environment. Build and enhance IAM integrations (e.g., HR source, directories, SaaS apps) using industry standards (SCIM, SAML/OIDC, APIs) and automation patterns. Privileged Access Management (PAM) & Secrets Management Engineer and mature
PAM controls
and operating processes for privileged identities and activities, including access request/approval patterns, time-bound elevation, auditing, and least privilege enforcement. Implement and manage
secrets management
capabilities (vaulting, rotation, access control, auditability) for human and non-human identities, including service principals and automation identities. Scripting, Automation, and Development Develop automation using
scripting and software engineering practices
(e.g., PowerShell/Python/Bash), including CI/CD-friendly workflows and infrastructure-as-code patterns (e.g., Terraform). Create repeatable solutions for access governance, role engineering, connector onboarding, reporting/analytics, and operational runbooks. Operations, Incident Support, and Continuous Improvement Respond to IAM operational work (tickets/requests) requiring engineering changes and enhancements. Assist in investigation and remediation of IAM incidents and issues, improving controls and automation to prevent recurrence. Conduct proofs-of-concept (POCs), partner with vendors, and recommend solutions aligned to security and business requirements. Collaboration, Advisory, and Documentation Serve as a trusted advisor to stakeholders—translating complex IAM topics into clear recommendations and implementation plans. Produce and maintain technical documentation, standards, and procedures supporting audits and operational readiness. Mentor peers and positively influence the team’s technical direction. Required Technical Skills (Must Have) IGA architecture & engineering expertise
(identity lifecycle, RBAC/ABAC concepts, access reviews/certifications, entitlement modeling, SoD/least privilege). Privileged Access Management (PAM)
concepts and hands-on implementation (JIT/JEA, session controls, privileged identity separation, auditing). Secrets management
(vaulting, rotation, access policies, non-human identity security). Experience designing and operating IAM controls in modern enterprise environments (cloud + SaaS) - especially Azure, including authentication/authorization and identity governance patterns. Preferred Skills (Nice to Have) Experience with IGA platforms (e.g., Saviynt, SailPoint, Omada) and IAM directories/IDPs (e.g., Entra ID/Azure AD). Experience with PAM and secrets tooling (e.g., CyberArk, Delinea, BeyondTrust, Akeyless, HashiCorp Vault, Azure Key Vault, AWS Secrets Manager). Familiarity with compliance frameworks and evidence collection for audits (SOX/SOC2/ISO27001-style controls). Experience integrating IAM with ticketing/workflow systems and operational processes. You Are
Typically requires a minimum of: BA/BS in Computer Science, Engineeri
Madrid, Spain Strength in Trust
OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™ unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society. The Challenge
As a Senior IAM Engineer, you will design, build, and operate core identity security capabilities across the enterprise. This includes
Identity Governance & Administration (IGA) architecture ,
Privileged Access Management (PAM) , and
secrets management , as well as the automation and integrations that enable secure access at scale. This role is responsible for multiple areas of IAM
(not just a single platform), and will contribute at a strategy, design, and execution level—partnering with Security, IT, and Engineering teams to deliver secure, reliable identity services. Your Mission
IAM / IGA Architecture & Engineering Architect and implement
IGA capabilities
including identity lifecycle (joiner/mover/leaver), access request workflows, approvals, provisioning/deprovisioning automation, certifications, and role/entitlement governance. Design and maintain the
identity lifecycle management (ILM) framework and controls
across the environment. Build and enhance IAM integrations (e.g., HR source, directories, SaaS apps) using industry standards (SCIM, SAML/OIDC, APIs) and automation patterns. Privileged Access Management (PAM) & Secrets Management Engineer and mature
PAM controls
and operating processes for privileged identities and activities, including access request/approval patterns, time-bound elevation, auditing, and least privilege enforcement. Implement and manage
secrets management
capabilities (vaulting, rotation, access control, auditability) for human and non-human identities, including service principals and automation identities. Scripting, Automation, and Development Develop automation using
scripting and software engineering practices
(e.g., PowerShell/Python/Bash), including CI/CD-friendly workflows and infrastructure-as-code patterns (e.g., Terraform). Create repeatable solutions for access governance, role engineering, connector onboarding, reporting/analytics, and operational runbooks. Operations, Incident Support, and Continuous Improvement Respond to IAM operational work (tickets/requests) requiring engineering changes and enhancements. Assist in investigation and remediation of IAM incidents and issues, improving controls and automation to prevent recurrence. Conduct proofs-of-concept (POCs), partner with vendors, and recommend solutions aligned to security and business requirements. Collaboration, Advisory, and Documentation Serve as a trusted advisor to stakeholders—translating complex IAM topics into clear recommendations and implementation plans. Produce and maintain technical documentation, standards, and procedures supporting audits and operational readiness. Mentor peers and positively influence the team’s technical direction. Required Technical Skills (Must Have) IGA architecture & engineering expertise
(identity lifecycle, RBAC/ABAC concepts, access reviews/certifications, entitlement modeling, SoD/least privilege). Privileged Access Management (PAM)
concepts and hands-on implementation (JIT/JEA, session controls, privileged identity separation, auditing). Secrets management
(vaulting, rotation, access policies, non-human identity security). Experience designing and operating IAM controls in modern enterprise environments (cloud + SaaS) - especially Azure, including authentication/authorization and identity governance patterns. Preferred Skills (Nice to Have) Experience with IGA platforms (e.g., Saviynt, SailPoint, Omada) and IAM directories/IDPs (e.g., Entra ID/Azure AD). Experience with PAM and secrets tooling (e.g., CyberArk, Delinea, BeyondTrust, Akeyless, HashiCorp Vault, Azure Key Vault, AWS Secrets Manager). Familiarity with compliance frameworks and evidence collection for audits (SOX/SOC2/ISO27001-style controls). Experience integrating IAM with ticketing/workflow systems and operational processes. You Are
Typically requires a minimum of: BA/BS in Computer Science, Engineeri