Security Identity Site Reliability Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+10 more
Job description
- Identity & Entitlements: Integrate the API layer with AWS IAM Identity Center (IdC) and build a policy engine to enforce data boundaries (SRE vs. App Team vs. Business Unit). This includes integrating Omni into the client’s existing identity-federation model - an established custom credential-vending / SAML broker on the primary landing zone plus existing IdC adoption for console access.
- Cross-Account Data Routing: Implement and automate links to aggregate logs, metrics, and traces across multiple AWS Organizations.
- End-to-End Feature Delivery: Build, test, and deploy features from the AWS infrastructure layer (CloudWatch / Omni / IAM) up through the API layer that serves the UI, using CloudWatch cross-account capabilities. May include writing high-performance APIs (in Go, Python, or Java) to query CloudWatch, CloudTrail, and flow logs, and implementing efficient caching strategies.
- Infrastructure as Code (IaC): Automate the deployment of all resources using Terraform or AWS CDK, leveraging AWS CloudFormation StackSets to deploy source links to 15,000 accounts.
- Enablement: Produce clear architecture and integration documentation and enable the client’s teams to operate and extend the Omni identity and routing model, working as an embedded SME alongside the client’s SRE and observability leadership.
Core Skills Identity and access management is the primary skill for this role, paired with the ability to deliver features end-to-end from infrastructure through the API layer. Skill Category Required Depth & Technologies Identity & Security (Primary) Advanced. AWS IAM Identity Center (IdC), SAML/OIDC federation, and integration with an existing enterprise federation / credential-vending model. Attribute-based access control (ABAC) and fine-grained authorization engines such as AWS Verified Permissions or Open Policy Agent (OPA). AWS Multi-Account Governance Advanced. AWS Organizations, CloudFormation StackSets, and Org-level APIs and policies. Able to automate resource provisioning at a scale of 15,000 accounts. Backend Development Proficient. Python, Java, or Go. Building high-performance REST/API services to query CloudWatch, CloudTrail, and flow logs, with efficient caching strategies and asynchronous data fetching. Cloud Observability Advanced. CloudWatch (Metrics, Logs, Alarms, Contributor Insights), CloudWatch cross-account observability / OAM (sink and source configuration), CloudTrail, and flow logs. Infrastructure as Code Advanced. Terraform or AWS CDK, with CI/CD pipelines (e.g. GitLab CI) for automated infrastructure deployment. General Requirements
Requirements
- AWS Professional or Specialty certification preferred (e.g. Security - Specialty, Solutions Architect - Professional, or DevOps Engineer - Professional, as relevant to the role).
- Prior delivery experience in a large, regulated enterprise environment (financial services strongly preferred); comfortable operating under change-control and audit scrutiny.
- Able to produce clear written documentation (architecture decision records, runbooks, design docs) suitable for client Tech Risk review.
- Strong stakeholder communication; can work directly with client engineering, security, and SRE teams as an embedded SME.
- Works to the stated engagement location / time-zone overlap and follows AWS ProServe and client onboarding, security, and vetting requirements (CV submission, AWS + client interview, tollgate onboarding).
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Top Must-Visit Developer Conferences in the US in 2026
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
What Makes WeAreDevelopers World Congress Different From Every Other Tech Event?
Is Software Engineering Over-Saturated?