> Markdown version of [/jobs/ext/1218976-iam-security-engineer](https://www.wearedevelopers.com/jobs/ext/1218976-iam-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Security Engineer - **Company:** Spectraforce - **Location:** Seattle, WA, United States - **Experience:** Experienced - **Contract:** Temporary to permanent - **Skills:** Microsoft Access, Microsoft Windows, Active Directory, Amazon Web Services, Automation of Tests, Microsoft Azure, Bash Shell, Cloud Computing, Cyber Security, Linux, Identity and Access Management, JSON, Python (Programming Language), Kerberos (Protocol), Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Oracle (Applications), Public Key Infrastructure, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), YAML, SSL Certificate Management, Scripting, Google Cloud, Okta, Multi-Cloud, Infrastructure as Code (IaC), Git, HR Software, Build Management, Kubernetes, Infrastructure Automation Frameworks, Information Technology, Hashicorp, Low-code, SailPoint, Restful APIs, Terraform, Docker, Legacy Systems, Programming Languages - **Published:** July 9, 2026 - **Apply:** http://leoforce.us/Careers/Spectraforce/JobDetails.html?jobid=99c1e9f8-f0d4-4079-9033-a2237c3d1103&OrgId=1&UserId=2788 ## About the Role * 2+ years of direct experience in an Identity and Access Management role. * Demonstrated experience with at least one major cloud identity platform (Okta, Microsoft Entra ID). * Proficiency in scripting with PowerShell or Python for automation. * Hands-on experience with Infrastructure as Code tools, particularly Terraform. * Strong understanding of modern authentication and federation protocols (SAML, OIDC, OAuth 2.0, SCIM). * Experience with hybrid identity models connecting cloud IdPs to on-premise Active Directory. * *For development-focused roles: Proficiency in a scripting or programming language (Python, Go) and hands-on experience consuming REST APIs. * Bachelor's Degree in Information Technology, Computer Science, Cybersecurity or related experience required., * AWS Certified Security - Specialty or Azure Security Engineer Associate * Microsoft SC-300: Identity and Access Administrator Associate * Okta Certified Administrator * SailPoint Certified IdentityIQ Associate or SailPoint Certified IdentityNow Professional * For development-focused roles: Experience with full-stack development is a plus. * Technical Skills Tools: * Okta, Microsoft Entra ID, Active Directory, AWS IAM, SailPoint IdentityNow, Terraform, BeyondTrust, HashiCorp Vault, PKI / Certificate Management, Git. * Languages: PowerShell, Python*, Bash*, Go*, JSON, YAML, REST APIs*. * Platforms: AWS, Azure, GCP, Windows/Linux, Docker, Kubernetes. * Protocols: SAML 2.0, OAuth 2.0, OIDC, SCIM, LDAP, Kerberos, FIDO2. Soft Skills * Customer Focus * Drives Results * Builds Trust * Self-Development * Communicates Effectively * Has Courage * Decision Quality * Strategic Mindset * Manages Complexity ## Description A solid individual contributor responsible for designing, implementing, and supporting IAM solutions across multiple environments with minimal supervision. This role actively develops automation to streamline operational tasks, implements subsystem-level security designs, and serves as an escalation point for complex technical issues., * Design and implement secure IAM configurations across multi-cloud and hybrid identity environments, applying Zero Trust principles to develop and tune conditional access policies and cloud IAM roles. * Develop, test, and maintain automation scripts (Python, PowerShell) and low-code workflows (e.g., Okta Workflows) to streamline user lifecycle management (LCM), reduce manual effort, and improve accuracy. * Independently manage the end-to-end integration of new applications into the IAM ecosystem, including SSO, MFA, IGA, and PAM solutions, applying Role-Based Access Control (RBAC) models. * Implement and configure IAM controls for non-human identities, such as service principals in Azure or Cloud Infrastructure platform (AWS, GCP, Oracle), ensuring they adhere to the principle of least privilege. * Create and maintain modular and reusable Infrastructure as Code (IaC) modules (e.g., Terraform) for the repeatable and consistent deployment of IAM resources. * Manage secrets and credentials for applications and services using a vaulting solution and enterprise Public Key Infrastructure (PKI). * Troubleshoot and resolve complex technical identity and access issues across both cloud and legacy systems, performing root cause analysis and implementing preventative measures. * For development-focused roles: Develop, test, and maintain custom automation scripts and simple applications that interact with REST APIs to extend IAM platform capabilities. Example Projects or Deliverables * Design and build an automated workflow in Okta Workflows to deprovision access from a set of high-risk applications within one hour of receiving a termination event from the HR system. * Develop a reusable Terraform module to standardize the creation of IAM roles in AWS, incorporating permissions boundaries and mandatory tagging policies. * Implement Just-in-Time (JIT) access for a defined set of privileged roles using a PAM solution, reducing standing privileged access by 75% for that group. * Create a comprehensive dashboard to monitor for anomalous login patterns, correlating data from the IdP, cloud platforms, and legacy directory services. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)