Security Identity Site Reliability Engineer

CONVERGENZ
Washington, DC, United States
22 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Java (Programming Language) Application Programming Interfaces (APIs) Amazon Web Services Cloud Computing Software Design Documents DevOps Identity and Access Management Python (Programming Language) Routing OpenID Reliability Engineering Runbook
+10 more
Security Assertion Markup Language (SAML) Web Services AWS Cdk Caching Infrastructure as Code (IaC) Backend Cloudformation Gitlab-ci Cloudwatch Terraform

Job description

  • Identity & Entitlements: Integrate the API layer with AWS IAM Identity Center (IdC) and build a policy engine to enforce data boundaries (SRE vs. App Team vs. Business Unit). This includes integrating Omni into the client’s existing identity-federation model - an established custom credential-vending / SAML broker on the primary landing zone plus existing IdC adoption for console access.
  • Cross-Account Data Routing: Implement and automate links to aggregate logs, metrics, and traces across multiple AWS Organizations.
  • End-to-End Feature Delivery: Build, test, and deploy features from the AWS infrastructure layer (CloudWatch / Omni / IAM) up through the API layer that serves the UI, using CloudWatch cross-account capabilities. May include writing high-performance APIs (in Go, Python, or Java) to query CloudWatch, CloudTrail, and flow logs, and implementing efficient caching strategies.
  • Infrastructure as Code (IaC): Automate the deployment of all resources using Terraform or AWS CDK, leveraging AWS CloudFormation StackSets to deploy source links to 15,000 accounts.
  • Enablement: Produce clear architecture and integration documentation and enable the client’s teams to operate and extend the Omni identity and routing model, working as an embedded SME alongside the client’s SRE and observability leadership.

Core Skills Identity and access management is the primary skill for this role, paired with the ability to deliver features end-to-end from infrastructure through the API layer. Skill Category Required Depth & Technologies Identity & Security (Primary) Advanced. AWS IAM Identity Center (IdC), SAML/OIDC federation, and integration with an existing enterprise federation / credential-vending model. Attribute-based access control (ABAC) and fine-grained authorization engines such as AWS Verified Permissions or Open Policy Agent (OPA). AWS Multi-Account Governance Advanced. AWS Organizations, CloudFormation StackSets, and Org-level APIs and policies. Able to automate resource provisioning at a scale of 15,000 accounts. Backend Development Proficient. Python, Java, or Go. Building high-performance REST/API services to query CloudWatch, CloudTrail, and flow logs, with efficient caching strategies and asynchronous data fetching. Cloud Observability Advanced. CloudWatch (Metrics, Logs, Alarms, Contributor Insights), CloudWatch cross-account observability / OAM (sink and source configuration), CloudTrail, and flow logs. Infrastructure as Code Advanced. Terraform or AWS CDK, with CI/CD pipelines (e.g. GitLab CI) for automated infrastructure deployment. General Requirements

Requirements

  • AWS Professional or Specialty certification preferred (e.g. Security - Specialty, Solutions Architect - Professional, or DevOps Engineer - Professional, as relevant to the role).
  • Prior delivery experience in a large, regulated enterprise environment (financial services strongly preferred); comfortable operating under change-control and audit scrutiny.
  • Able to produce clear written documentation (architecture decision records, runbooks, design docs) suitable for client Tech Risk review.
  • Strong stakeholder communication; can work directly with client engineering, security, and SRE teams as an embedded SME.
  • Works to the stated engagement location / time-zone overlap and follows AWS ProServe and client onboarding, security, and vetting requirements (CV submission, AWS + client interview, tollgate onboarding).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:52 min

Structuring and scaling the backend engineering team

Stefan Lingler Stefan Lingler +1 · Coffee With Developers

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

Videos

See all

Related articles

See all