> Markdown version of [/jobs/ext/1334085-principal-cloud-iam-engineer](https://www.wearedevelopers.com/jobs/ext/1334085-principal-cloud-iam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Cloud IAM Engineer - **Company:** Workday, Inc. - **Location:** Reston, VA, United States (Remote available) - **Experience:** Experienced - **Salary:** $184,800.0 - $277,200.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Cloud Computing Security, Software Debugging, Identity and Access Management, Key Management, OAuth, OpenID, Zero Trust Network Access, Security Assertion Markup Language (SAML), Okta, Large Language Models, Terraform - **Published:** July 18, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9039445/principal-cloud-iam-engineer ## About the Role * 10+ years of experience in cloud security or IAM, with at least 3 years in a senior or architect-level role with clear ownership of strategy and technical direction. * Proven AWS IAM foundations SCPs, IAM Identity Center, ABAC, multi-account Organizations architecture, and secrets management at scale via AWS Secrets Manager or equivalent vault solutions. GCP familiarity is advantageous but not required. * Demonstrated Okta experience at enterprise scale SSO, adaptive MFA, SCIM provisioning, lifecycle management, and AWS environment integration. * Deep familiarity with federation protocols SAML, OIDC, and OAuth2 applied and debugged across complex, heterogeneous environments. * Infrastructure-as-code fluency with Terraform, and a clear understanding of how identity controls integrate into and are enforced through CI/CD pipelines. * Hands-on engagement with AI and agentic identity is required. This means working knowledge of NHI lifecycle management, service-to-service trust models, and least-privilege design for workloads that assume IAM roles, call external APIs, and chain actions across services. Familiarity with AI security tooling such as identity-aware proxies, agent observability platforms, or LLM access governance is a strong differentiator. You don't need to have solved this at scale; you do need to be actively working in this space. * Zero Trust applied in practice identity-aware perimeters, conditional access policies, and workload-level controls implemented in production environments. * Proven ability to drive technical alignment across engineering, security, and business stakeholders without relying on positional authority. Comfortable mentoring and leveling up less senior engineers takes the time to transfer context, not just deliver outcomes. * A risk mitigation mindset: you understand threat exposure well enough to make pragmatic architectural trade-offs, engage credibly with Risk and GRC teams, and push back when a proposed control creates engineering friction without meaningfully reducing risk. * Secrets Management experience * AWS Certified Security Specialty and a signal of structured cloud depth. ## Description We're looking for a Principal Identity and Access Management Architect to own the strategy, design, and long-term direction of our IAM program. This is not an operational role. You'll set the patterns other engineers build against, make the architectural calls that shape how we scale, and work directly with engineering, security, and Risk leadership to drive alignment across the organization. The scope spans human and non-human identity, cloud authorization, federation, secrets management, and the emerging challenge of securing AI agents in production - where the patterns don't fully exist yet and you'll be helping to define them. This role sits at the intersection of deep technical ownership and cross-functional influence. You'll be expected to lead without always having direct authority, mentor engineers who are earlier in their IAM journey, and bring a risk-informed perspective that translates threat exposure into pragmatic architectural decisions - not checkbox compliance. If you're the kind of engineer who gets ahead of problems before they scale, builds with the next three years in mind, and can hold a technical vision across a complex enterprise environment - this is the role. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [30 powerful AWS hacks in just 30 minutes: Boost your developer productivity](https://www.wearedevelopers.com/videos/1624-30-powerful-aws-hacks-in-just-30-minutes-boost-your-developer-productivity) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Seriously gaming your cloud expertise: from cloud tourist to cloud native](https://www.wearedevelopers.com/videos/373-seriously-gaming-your-cloud-expertise-from-cloud-tourist-to-cloud-native) ## Related Articles - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [What Makes WeAreDevelopers World Congress Different From Every Other Tech Event?](https://www.wearedevelopers.com/magazine/701-what-makes-wearedevelopers-world-congress-different-from-every-other-tech-event) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift)