Senior Identity And Access Management Engineer

hace 7 días


Madrid, Madrid, España Roche A tiempo completo

Bei Roche kannst du ganz du selbst sein und wirst für deine einzigartigen Qualitäten geschätzt. Unsere Kultur fördert persönlichen Ausdruck, offenen Dialog und echte Verbindungen. Hier wirst du für das, was du bist, wertgeschätzt, akzeptiert und respektiert. Dies schafft ein Umfeld, in dem du sowohl persönlich als auch beruflich wachsen kannst. Gemeinsam wollen wir Krankheiten vorbeugen, stoppen und heilen und sicherstellen, dass jeder Zugang zur Gesundheitsversorgung hat – heute und in Zukunft. Werde Teil von Roche, wo jede Stimme zählt.

Die Position

The Identity Management Support Team manages and operates the solutions and components used to provide customers with Directory and Identity Management Services using SailPoint. We are part of a global Roche Digital Technology group (RDT).

In this role, you are mainly responsible for the multi-cloud Identity Management environment, focusing specifically on Azure and Google Cloud Platform (GCP), while maintaining consistency with AWS. This includes the design of new solutions, consultancy, maintenance, performance, tactical lifecycle management and continuous improvement of the underlying technologies.

Your main responsibilities are:

  • Strong background in IAM concepts at design level and evolution in Cloud environments, Azure and/or GCP.
  • Contributes to the design of new solutions based on SailPoint and PingFederate, AD, Privilege Access Management.
  • Design and implement Centralized Role-Based Access Control (RBAC) based on Cloud Adoption Framework (CAF) principles.
  • Access Governance and Controls: Enforce strong security controls across cloud environments, including Multi-Factor Authentication (MFA) and Identity Protection. Implement Least Privilege policies, often involving custom roles and organizational-level controls. Implement IAM Deny Policies to strictly block high-risk actions, ensuring separation of duties
  • Automation and Infrastructure-as-Code (IaC): Drive the core value of "Automate as much as possible". Design and implement IAM infrastructure using IaC, leveraging Terraform. For Azure, this mandates IaC using Terraform and Azure Verified Modules (AVM) with CI/CD pipelines in GitLab
  • Privileged Access Management (PAM): Design and support Just-in-Time (JIT) Access mechanisms, ensuring no standing privileges for administrators, using tools like Cyberark for Just-in-Time access
  • Consultancy and Collaboration: Act as a mentor and reference, working closely with stakeholders to provide the right level of consultancy. Ensure regular interactions with the Managed Service Provider
  • Operational Excellence: Act as an expert in the release management activities, providing 2nd and 3rd level support for the Identity Management Infrastructure. Proactively monitor systems for performance, availability, and capacity management
  • Actively focus on self-development in creating actionable plans to improve.

Who you are

You're someone who wants to drive your own development and is highly curious. You're looking for a company where you have the opportunity to pursue your interests across functions and geographies, where a job title is not considered the final definition of who you are, but the starting point.

For this position, you bring the following experience, skills & qualifications:

  • 5-7 years of experience working in a major global organization, preferably in a regulated industry and in providing solutions aligned with standards, security, validation, capacity and high availability.
  • Bachelor's Degree in computer science, engineering or related discipline; or recognition of prior working experience which is equivalent.
  • Strong hands-on technical skills with an IT operations background. Expert knowledge on infrastructure technologies, business processes and applications with a focus on Sailpoint IQ Identity Governance and Access Identity Management technologies and PingFederate.

  • Cloud Platform skills:

  • Expertise in GCP Identity and Access Management (IAM), including Identity Synchronization, Service Account binding/federation, and organizational policy enforcement.

  • Expertise in Azure IAM/RBAC, including implementing centralized RBAC designs, Azure Policy, and alignment with the Azure Cloud Adoption Framework (CAF).
  • Experience applying cloud governance principles (e.g., Azure Policy, IAM Deny Policies) to ensure consistent governance and security across multi-cloud workloads

  • Automation and DevOps:

  • experience with Infrastructure-as-Code (IaC) tools, particularly Terraform, for platform building and management.

  • Experience implementing governance as code and integrating automated workflows via CI/CD pipelines (e.g., GitLab).

  • Strong understanding of Computer Systems Validation and working experience in a validated environment.

  • Good understanding of IT Security systems and landscape with in-depth knowledge of Directories, Identity Management and Privileged Access Management technologies.
  • Industry accredited certification is desirable. Willingness to continually acquire and maintain the technical skills appropriate to the requirements of this position.
  • Proactive, collaborative and supportive approach when interacting with colleagues.
  • Committed to operational excellence, with willingness to cross-train and to learn additional technical expertise.
  • Strong customer focus and a highly responsive service delivery and support ethic.
  • Adaptable to change in a large organization.
  • Excellent communication, negotiation and documentation skills.
  • Proven interpersonal skills to interact effectively with individuals in multiple countries and in varying cultures.
  • Strong verbal and written English.

Wer wir sind

Eine gesündere Zukunft treibt uns zur Innovation an. Mehr als Mitarbeiter weltweit arbeiten gemeinsam daran, wissenschaftliche Fortschritte zu erzielen und sicherzustellen, dass jeder Zugang zur Gesundheitsversorgung hat – heute und für zukünftige Generationen. Durch unser Engagement werden über 26 Millionen Menschen mit unseren Medikamenten behandelt und mehr als 30 Milliarden Tests mit unseren Diagnostik-Produkten durchgeführt. Wir ermutigen uns gegenseitig, neue Möglichkeiten zu erkunden, Kreativität zu fördern und hohe Ziele zu setzen, um lebensverändernde Gesundheitslösungen zu liefern.

Gemeinsam können wir eine gesündere Zukunft gestalten.

Roche ist ein Arbeitgeber, der die Chancengleichheit fördert.



  • Madrid, Madrid, España Inetum A tiempo completo

    Descripción de la empresaDescripción de la empresaSobre InetumInetum es líder europeo en servicios digitales. El equipo de consultores y expertos de Inetum se esfuerza cada día por lograr un impacto digital en las empresas, en las entidades del sector público y en la sociedad. Las soluciones de Inetum quieren contribuir al rendimiento y la innovación...


  • Madrid, Madrid, España Liebherr Group A tiempo completo

    We are expanding our Global Corporate Information Security Team and looking forward new colleagues joining our teams:The IAM Security Engineer is responsible for implementing, managing, and securing identity and access management solutions across an organization. They ensure that users, systems, and applications have appropriate access while minimizing...


  • Madrid, Madrid, España NTT DATA Europe & Latam A tiempo completo

    About the CompanyNTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply nowAbout the Role:At NTT DATA we are looking for professionals specialized inCyberArk Privilege Cloudto join an international project of great...


  • Madrid, Madrid, España JULIUS BAER A tiempo completo

    At Julius Baer, we celebrate and value the individual qualities you bring, enabling you to be impactful, to be entrepreneurial, to be empowered, and to create value beyond wealth. Let's shape the future of wealth management together.Access and Catalogue Engineering is playing a critical role in enabling secure, efficient, and compliant access to our...


  • Madrid, Madrid, España Julius Baer A tiempo completo

    At Julius Baer, we celebrate and value the individual qualities you bring, enabling you to be impactful, to be entrepreneurial, to be empowered, and to create value beyond wealth. Let's shape the future of wealth management together. Access and Catalogue Engineering is playing a critical role in enabling secure, efficient, and compliant access to our...


  • Madrid, Madrid, España Ping Identity A tiempo completo

    About Ping Identity: At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it's not just something we provide our customers. It's something that inspires our company. People don't come here to join a culture that's built on digital freedom. They come to...


  • Madrid, Madrid, España TOPIC Embedded Systems A tiempo completo

    AtTOPIC (in the Netherlands)we work every day on high-tech innovations to make the world smarter, healthier, and better. Are you a driven and ambitious Senior DevOps Engineer with a passion for automation, CI/CD, and state-of-the-art tooling that we are looking for? As a Senior DevOps Engineer, you play a key role in enabling development teams to work...


  • Madrid, Madrid, España Allianz Technology A tiempo completo

    About The JobAre you ready to lead in a dynamic, international environment? As aCluster Product Owner (CPO), you'll drive the implementation of the ILAP strategy across a family of related products — bridging product owners, stakeholders, and leadershipYour mission: ensure reliable, scalable, and high-performing systems by enabling seamless delivery across...


  • Madrid, Madrid, España Roche A tiempo completo

    At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure...


  • Madrid, Madrid, España Colliers International EMEA A tiempo completo

    Company Description Colliers is a leading diversified professional services and investment management company. With operations in 68 countries, our 22,000 enterprising people work collaboratively to provide expert advice to maximize the potential of property and real assets to accelerate the success of our clients, our investors and our people.We are at the...