About this Cloud Identity & Access Management (IAM) Engineer role at Shyftlabs
Role Overview
We are seeking a Cloud Identity & Access Management (IAM) Engineer to own, secure, and streamline access across our enterprise systems. In this role, you will architect our identity infrastructure, enforce Single Sign-On (SSO) across all applications, automate employee access lifecycles, and strictly govern application-level permissions.
Because this role oversees core identity infrastructure across our multi-cloud and SaaS environments, we require hands-on technical experience with identity protocols, cloud access policies, and security automation.
What You'll Do
Access Administration: Serve as the technical lead for all central Identity and Access Management (IAM) operations.
SSO Architecture: Implement and enforce Single Sign-On (SSO) across all internal systems and third-party SaaS platforms.
Cloud Security: Architect cloud IAM policies, manage service accounts, and secure OAuth consent screens across multi-cloud infrastructure.
Application Governance: Audit third-party application integrations, track shadow IT, and conduct periodic access reviews with department leads to eliminate excess permissions.
Lifecycle Automation: Build automated onboarding and offboarding pipelines using SCIM, APIs, or scripts to ensure day-one access and immediate termination revocations.
Policy & Monitoring: Apply Zero Trust and Least Privilege principles to existing setups, while monitoring identity logs for anomalous activity.
What You'll Bring
Experience: 4+ years in Cybersecurity, IT Engineering, or Cloud Infrastructure, with a primary focus on IAM.
Identity Protocols: Technical proficiency in SAML 2.0, OpenID Connect (OIDC), OAuth 2.0, and SCIM.
Cloud Infrastructure: Direct experience configuring access controls, role-based policies, organizational policies, and OAuth consent pages across enterprise cloud platforms.
SaaS & Workspace: Administration experience with enterprise workspace tools and centralized Identity Providers (such as Okta, Entra ID, or Google Cloud Identity).
Automation & Code: Scripting experience in Python, Bash, Go, or PowerShell, alongside experience using REST APIs or Infrastructure as Code (Terraform) for access management.
Security Controls: Hands-on experience implementing Privileged Access Management (PAM), Just-In-Time (JIT) access, and centralized audit logging.