IAM Security Engineer
Hybrid
Posted 2d ago
Remote Work Policy
On-site
Categories
Applied AI Engineer
About the job
As an Identity and Access Management (IAM) Security Engineer at Cloudflare, you will be instrumental in developing, deploying, and scaling robust identity and access management solutions for both internal employees and workloads. Your primary focus will be on securing our systems, applications, and data by ensuring the integrity of user access, authentication, and authorization processes. This role involves a hands-on approach to building and managing critical IAM components, contributing to the overall security posture of the organization.
Responsibilities
- Design, build, test, and deploy IAM solutions covering authentication, authorization, and accounting.
- Utilize Cloudflare products to enhance identity security.
- Develop SSO integrations using SAML, OIDC, OAuth, and SCIM protocols.
- Build and maintain the Identity Governance and Administration platform.
- Create automated roles based on RBAC and ABAC principles.
- Build and manage an access certification platform.
- Build and manage a Privileged Access Management (PAM) platform.
- Provide operational support for IAM systems, including on-call duties.
Requirements
- Strong understanding of identity federation standards (SAML, OAuth, OpenID Connect).
- Experience implementing Identity Governance and Administration (IGA) solutions, including lifecycle management, SCIM, birthright access (RBAC, ABAC), and access certifications.
- Proven ability to build production-grade automation scripts and tools.
- Hands-on engineering experience leveraging AI/LLMs for operational or technical challenges.
- Experience with secure configuration of containerized application platforms like Kubernetes.
- Advanced scripting skills in languages such as Python, TypeScript, or Bash.
- Experience implementing Zero Trust security controls.
- Experience integrating with various applications and SaaS solutions.
- Experience applying and enforcing Identity and Access Management policies.
- Experience with Identity Threat Detection & Response (ITDR).
- Experience with infrastructure as code and configuration management tools (e.g., Terraform, Ansible).