Security Platform Engineer-IAM

STIFEL
St. Louis, MO, United States
15 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Build Automation Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Information Systems Continuous Integration DevOps Federated Identity Management Identity and Access Management
+23 more
Python (Programming Language) Kerberos (Protocol) Key Management Lightweight Directory Access Protocols (LDAP) OAuth OpenID Windows PowerShell Role-Based Access Control Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Systems Integration Policy as Code Scripting Enterprise Software Applications Cyberark Infrastructure Automation Frameworks Information Technology Data Management SailPoint Terraform Software Version Control Programming Languages

Job description

Under general supervision, the Security Platform Engineer-IAM is a front-line member of the Identity and Access Management (IAM) team that has responsibility for supporting and evolving enterprise identity, access, and workload identity platforms. The Security Platform Engineer-IAM is responsible for engineering, automation, integration and operational support across cloud permissions, identity governance, privileged access, directory services, SSO/MFA, secrets management, and non-human identity controls.

What We’re Looking For

  • Contribute to the strategy, design, and management of the enterprise IAM program.
  • Design, build, and support identity platform capabilities across cloud, hybrid, and enterprise environments.
  • Manage and automate AWS IAM permissions, roles, policies, service accounts, workload identities, and access patterns.
  • Develop and maintain Terraform modules, IaC pipelines, and GitOps-based deployment workflows for identity infrastructure.
  • Collaborate across teams and business lines to improve IAM solutions, enhance compliance requirements, and Firm best practices.
  • Build automation using PowerShell, Python, Terraform, APIs, and CI/CD tooling.
  • Support secrets management platforms and patterns, including credential rotation, vault integrations, machine identity, and secure secret consumption.
  • Engineer and govern non-human identities, including service accounts, workload identities, application identities, API credentials, and cloud-native identities.
  • Build and develop systems and processes to enforce least privilege in a transparent way.
  • Partner with security, infrastructure, cloud, DevOps, and application teams to implement secure access patterns.
  • Engineer technical configuration changes to deployed solutions.
  • Develop documentation to support ongoing IAM systems operations, maintenance and specific problem resolution.

What You’ll Bring

  • Strong engineering experience in identity, cloud security, infrastructure automation, or access management.
  • Hands-on experience with AWS IAM, including roles, policies, permission boundaries, identity federation, service control policy, service-linked roles, and least-privilege design.
  • Strong experience with Terraform for infrastructure automation and identity platform configuration.
  • Demonstrated understanding of directory services principles.
  • Strong scripting skills for automation, administration, reporting, and operational support (PowerShell, Python, Terraform).
  • Proven experience designing, deploying, and supporting Identity and Access management platforms and projects.
  • Experience with GitOps, source control workflows, pull requests, CI/CD pipelines, and controlled deployment practices.
  • Experience with secrets management, credential lifecycle management, vaulting patterns, and secure application authentication.
  • Understanding of a broad range of IT disciplines that would impact overall security posture.
  • Familiarity with non-human identity, workload identity, service account governance, machine identity, or application identity security.
  • Experience with Microsoft Entra ID, including enterprise applications, app registrations, conditional access concepts, SSO, OAuth, MFA, and identity federation.
  • Experience with Identity Data Management solutions.
  • Knowledge of cloud security frameworks, least privilege, Zero Trust, and identity-first security principles.
  • Experience building reusable Terraform modules and policy-as-code controls.

Education & Experience

  • Minimum Required: Bachelor’s degree in computer science, information systems, cybersecurity, or a related field, or equivalent experience.
  • Minimum Required: 4+ years experience in an Information Technology or Information Security role.

Licenses & Credentials

  • Minimum Required: None.

Systems & Technology

  • Proficient with Azure and/or AWS security and engineering.
  • Experience with Secrets Management platforms.
  • Experience integrating identity platforms with DevOps and cloud-native environments.
  • Advanced knowledge of PowerShell, Python, Terraform programming language preferred.
  • Knowledge of cloud security frameworks, least privilege, Zero Trust, and identity-first security principles.
  • Experience with workload identity federation, OIDC, SAML, OAuth, SCIM, Kerberos, LDAP, and certificate-based authentication.
  • Experience with privileged access platforms such as CyberArk, BeyondTrust, Delinea, or similar.
  • Experience with IGA platforms such as SailPoint, Saviynt, Microsoft Entra ID Governance, or similar.

About Stifel

Stifel is more than 130 years old and still thinking like a start-up. We are a global wealth management and investment banking firm serious about innovation and fresh ideas. Built on a simple premise of safeguarding our clients’ money as if it were our own, coined by our namesake, Herman Stifel, our success is intimately tied to our commitment to helping families, companies, and municipalities find their own success.

While our headquarters is in St. Louis, we have offices in New York, San Francisco, Baltimore, London, Frankfurt, Toronto, and more than 400 other locations. Stifel is home to approximately 9,000 individuals who are currently building their careers as financial advisors, research analysts, project managers, marketing specialists, developers, bankers, operations associates, among hundreds more. Let’s talk about how you can find your place here at Stifel, where success meets success.

At Stifel we offer an entrepreneurial environment, comprehensive benefits package to include health, dental and vision care, 401k, wellness initiatives, life insurance, and paid time off.

Stifel is an Equal Opportunity Employer.

Requirements

  • Strong engineering experience in identity, cloud security, infrastructure automation, or access management.
  • Hands-on experience with AWS IAM, including roles, policies, permission boundaries, identity federation, service control policy, service-linked roles, and least-privilege design.
  • Strong experience with Terraform for infrastructure automation and identity platform configuration.
  • Demonstrated understanding of directory services principles.
  • Strong scripting skills for automation, administration, reporting, and operational support (PowerShell, Python, Terraform).
  • Proven experience designing, deploying, and supporting Identity and Access management platforms and projects.
  • Experience with GitOps, source control workflows, pull requests, CI/CD pipelines, and controlled deployment practices.
  • Experience with secrets management, credential lifecycle management, vaulting patterns, and secure application authentication.
  • Understanding of a broad range of IT disciplines that would impact overall security posture.
  • Familiarity with non-human identity, workload identity, service account governance, machine identity, or application identity security.
  • Experience with Microsoft Entra ID, including enterprise applications, app registrations, conditional access concepts, SSO, OAuth, MFA, and identity federation.
  • Experience with Identity Data Management solutions.
  • Knowledge of cloud security frameworks, least privilege, Zero Trust, and identity-first security principles.
  • Experience building reusable Terraform modules and policy-as-code controls., * Minimum Required: Bachelor’s degree in computer science, information systems, cybersecurity, or a related field, or equivalent experience.
  • Minimum Required: 4+ years experience in an Information Technology or Information Security role.

Licenses & Credentials

  • Minimum Required: None.

Systems & Technology

  • Proficient with Azure and/or AWS security and engineering.
  • Experience with Secrets Management platforms.
  • Experience integrating identity platforms with DevOps and cloud-native environments.
  • Advanced knowledge of PowerShell, Python, Terraform programming language preferred.
  • Knowledge of cloud security frameworks, least privilege, Zero Trust, and identity-first security principles.
  • Experience with workload identity federation, OIDC, SAML, OAuth, SCIM, Kerberos, LDAP, and certificate-based authentication.
  • Experience with privileged access platforms such as CyberArk, BeyondTrust, Delinea, or similar.
  • Experience with IGA platforms such as SailPoint, Saviynt, Microsoft Entra ID Governance, or similar.

Benefits & conditions

At Stifel we offer an entrepreneurial environment, comprehensive benefits package to include health, dental and vision care, 401k, wellness initiatives, life insurance, and paid time off.

Stifel is an Equal Opportunity Employer.

About the company

Stifel is more than 130 years old and still thinking like a start-up. We are a global wealth management and investment banking firm serious about innovation and fresh ideas. Built on a simple premise of safeguarding our clients’ money as if it were our own, coined by our namesake, Herman Stifel, our success is intimately tied to our commitment to helping families, companies, and municipalities find their own success.

While our headquarters is in St. Louis, we have offices in New York, San Francisco, Baltimore, London, Frankfurt, Toronto, and more than 400 other locations. Stifel is home to approximately 9,000 individuals who are currently building their careers as financial advisors, research analysts, project managers, marketing specialists, developers, bankers, operations associates, among hundreds more. Let’s talk about how you can find your place here at Stifel, where success meets success.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerarc.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all