> Markdown version of [/jobs/ext/2072778-security-identity-site-reliability-engineer](https://www.wearedevelopers.com/jobs/ext/2072778-security-identity-site-reliability-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Identity Site Reliability Engineer - **Company:** CONVERGENZ - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Cloud Computing, Software Design Documents, DevOps, Identity and Access Management, Python (Programming Language), Routing, OpenID, Reliability Engineering, Runbook, Security Assertion Markup Language (SAML), Web Services, AWS Cdk, Caching, Infrastructure as Code (IaC), Backend, Cloudformation, Gitlab-ci, Cloudwatch, Terraform - **Published:** August 15, 2026 - **Apply:** https://www.careerjet.com/job/us8ef7f837c28edaa617faa3639a3566c3/eaa ## About the Role * AWS Professional or Specialty certification preferred (e.g. Security - Specialty, Solutions Architect - Professional, or DevOps Engineer - Professional, as relevant to the role). * Prior delivery experience in a large, regulated enterprise environment (financial services strongly preferred); comfortable operating under change-control and audit scrutiny. * Able to produce clear written documentation (architecture decision records, runbooks, design docs) suitable for client Tech Risk review. * Strong stakeholder communication; can work directly with client engineering, security, and SRE teams as an embedded SME. * Works to the stated engagement location / time-zone overlap and follows AWS ProServe and client onboarding, security, and vetting requirements (CV submission, AWS + client interview, tollgate onboarding). ## Description * Identity & Entitlements: Integrate the API layer with AWS IAM Identity Center (IdC) and build a policy engine to enforce data boundaries (SRE vs. App Team vs. Business Unit). This includes integrating Omni into the client's existing identity-federation model - an established custom credential-vending / SAML broker on the primary landing zone plus existing IdC adoption for console access. * Cross-Account Data Routing: Implement and automate links to aggregate logs, metrics, and traces across multiple AWS Organizations. * End-to-End Feature Delivery: Build, test, and deploy features from the AWS infrastructure layer (CloudWatch / Omni / IAM) up through the API layer that serves the UI, using CloudWatch cross-account capabilities. May include writing high-performance APIs (in Go, Python, or Java) to query CloudWatch, CloudTrail, and flow logs, and implementing efficient caching strategies. * Infrastructure as Code (IaC): Automate the deployment of all resources using Terraform or AWS CDK, leveraging AWS CloudFormation StackSets to deploy source links to 15,000 accounts. * Enablement: Produce clear architecture and integration documentation and enable the client's teams to operate and extend the Omni identity and routing model, working as an embedded SME alongside the client's SRE and observability leadership. Core Skills Identity and access management is the primary skill for this role, paired with the ability to deliver features end-to-end from infrastructure through the API layer. Skill Category Required Depth & Technologies Identity & Security (Primary) Advanced. AWS IAM Identity Center (IdC), SAML/OIDC federation, and integration with an existing enterprise federation / credential-vending model. Attribute-based access control (ABAC) and fine-grained authorization engines such as AWS Verified Permissions or Open Policy Agent (OPA). AWS Multi-Account Governance Advanced. AWS Organizations, CloudFormation StackSets, and Org-level APIs and policies. Able to automate resource provisioning at a scale of 15,000 accounts. Backend Development Proficient. Python, Java, or Go. Building high-performance REST/API services to query CloudWatch, CloudTrail, and flow logs, with efficient caching strategies and asynchronous data fetching. Cloud Observability Advanced. CloudWatch (Metrics, Logs, Alarms, Contributor Insights), CloudWatch cross-account observability / OAM (sink and source configuration), CloudTrail, and flow logs. Infrastructure as Code Advanced. Terraform or AWS CDK, with CI/CD pipelines (e.g. GitLab CI) for automated infrastructure deployment. General Requirements ## Related Videos - [SRE Methods In an Agency Environment](https://www.wearedevelopers.com/videos/348-sre-methods-in-an-agency-environment) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Makes WeAreDevelopers World Congress Different From Every Other Tech Event?](https://www.wearedevelopers.com/magazine/701-what-makes-wearedevelopers-world-congress-different-from-every-other-tech-event) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026)