> Markdown version of [/jobs/ext/1311797-principal-iam-cloud-system-engineer-technology-digital](https://www.wearedevelopers.com/jobs/ext/1311797-principal-iam-cloud-system-engineer-technology-digital). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal IAM Cloud System Engineer, Technology & Digital - **Company:** Baptist Health - **Location:** Coral Gables, FL, United States - **Experience:** Expert - **Salary:** $122,475.0 - $159,218.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Application Programming Interfaces (APIs), Amazon Web Services, Audit Trail, Microsoft Azure, Bash Shell, Cloud Computing Security, Cloud Engineering, Computer Programming, Federated Identity Management, Identity and Access Management, Information Systems Security Architecture Professional, Python (Programming Language), OAuth, OpenID, Role-Based Access Control, Openid Connect, Azure Active Directory, Cloud Services, Security Assertion Markup Language (SAML), Single Sign-On, Systems Integration, User Provisioning Software, Scripting, Enterprise Software Applications, Cloud Platform System, Multi-Cloud, Infrastructure as Code (IaC), Information Technology, Gsuite, Terraform - **Published:** July 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b1ed62234bc27ad8 ## About the Role * Master's degree in computer science or related fields * Experience: 10+ years of dedicated experience in cloud engineering, with at least 5 years focused heavily on Cloud IAM. + Identity Platform Expertise: Proven, hands-on administration experience with: + AWS IAM Identity Center (SSO configuration, Permission Sets, AWS Organizations integrations). + Azure Entra ID (Conditional Access, Directory Roles, Enterprise Apps). + Google Workspace (Directory Management, SSO integration, SAML/OIDC setup). + Architectural Experience: Experience designing and documenting an IAM delegation model for mid-to-large-size engineering organizations. + Federation Standards: Deep understanding of identity federation protocols: SAML 2.0, OAuth 2.0, and OIDC. PREFERRED & EXPANDED QUALIFICATIONS + IaC Skills: Strong experience managing IAM configurations using Terraform or an equivalent infrastructure-as-code tool. + Programming/Scripting: Proficiency in Python or Go for building custom IAM governance tools and integrations. + Compliance Knowledge: Experience implementing least-privilege frameworks in highly regulated environments (e.g., Healthcare/HIPAA, Finance/SOC 2). + Security Certifications: Certified Information Systems Security Professional (CISSP), AWS Certified Security - Specialty, or Microsoft Certified: Identity and Access Administrator Associate. Minimum Required Experience: 10 Years EOE, including disability/vets ## Description We are seeking a Principal Cloud IAM Engineer to design, implement, and govern our multi-cloud identity and access management (IAM) ecosystem. In this role, you will be the primary architect of our cloud security boundaries, ensuring that our workforce and automated systems have precise, least-privilege access across our cloud environments and productivity suites. The ideal candidate has deep hands-on expertise in federated identity systems, multi-directory synchronization, and the design of highly scalable IAM delegation models that empower engineering teams while maintaining strict security guardrails. 1. Multi-Cloud IAM Architecture & Administration * AWS IAM Identity Center: Architect and manage centralized single sign-on (SSO), permission sets, and multi-account access strategies across AWS Organizations. * Azure Entra ID: Configure and maintain Enterprise Applications, App Registrations, conditional access policies, and group management. * Google Workspace: Govern administrative controls, organizational units (OUs), third-party app permissions, and API scopes. 2. IAM Delegation Model & Policy Design * Delegation Design: Define and roll out an enterprise-wide IAM delegation model, establishing clear boundaries between central security teams, platform engineering, and product development squads. * Access Control Patterns: Implement Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) using resource tags, AWS Session Tags, or Azure directory attributes. * Guardrails at Scale: Design and enforce Service Control Policies (SCPs) in AWS, Management Group policies in Azure, and Organization Policies in GCP to limit the blast radius of delegated privileges. 3. Federation, Provisioning & Automation * SSO & Federation: Implement and troubleshoot SAML 2.0, OpenID Connect (OIDC), and OAuth 2.0 integrations between identity providers (IdPs) and cloud services. * Automated Provisioning (SCIM): Configure SCIM-based user provisioning pipelines to automate user lifecycle management (joiners, movers, leavers) from Google Workspace or Entra ID into cloud environments. * Infrastructure as Code (IaC): Treat IAM as code. Author, test, and deploy IAM roles, policies, and directory group mappings using tools like Terraform or OpenTofu. * Automation Scripting: Write utility scripts (Python, Go, or Bash) to automate access audits, discover unused credentials, and clean up over-privileged roles. 4. Governance, Compliance & Auditing * Access Reviews: Establish continuous monitoring and automated periodic access reviews (Attestation) to satisfy industry compliance frameworks (e.g., SOC 2, HIPAA, ISO 27001). * Audit Trail Analysis: Monitor and analyze identity activity logs (AWS CloudTrail, Azure Activity Logs, Google Workspace Audit logs) to detect potential credential abuse, privilege escalations, or policy violations. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)