> Markdown version of [/jobs/ext/2724692-identity-and-access-management-engineer](https://www.wearedevelopers.com/jobs/ext/2724692-identity-and-access-management-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity and Access Management Engineer - **Company:** OneTrust, LLC. - **Location:** Spain - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Bash Shell, Software as a Service, Cloud Computing, Continuous Integration, Java Platform Enterprise Edition (J2EE), Identity and Access Management, Python (Programming Language), Key Management, OpenID, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Security Assertion Markup Language (SAML), SoapUI, Software Engineering, SQL Databases, Scripting, Postman, Cyberark, Git Flow, Hashicorp, Gsuite, SailPoint, Terraform - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/sr-identity-and-access-management-engineer-onetrust-9925137 ## About the Role * IGA architecture & engineering expertise (identity lifecycle, RBAC/ABAC concepts, access reviews/certifications, entitlement modeling, SoD/least privilege). * Privileged Access Management (PAM) concepts and hands-on implementation (JIT/JEA, session controls, privileged identity separation, auditing). * Secrets management (vaulting, rotation, access policies, non-human identity security). * Scripting and development skills (e.g., SQL, JavaScript, PowerShell, Python, Velocity, SOAPUI, ARC, Postman, Java/J2EE, Bash; API integration; Git-based workflows). * Experience designing and operating IAM controls in modern enterprise environments (cloud + SaaS) - especially Azure, including authentication/authorization and identity governance patterns. Preferred Skills (Nice to Have) * Experience with IGA platforms (e.g., Saviynt, SailPoint, Omada) and IAM directories/IDPs (e.g., Entra ID/Azure AD). * Experience with PAM and secrets tooling (e.g., CyberArk, Delinea, BeyondTrust, Akeyless, HashiCorp Vault, Azure Key Vault, AWS Secrets Manager). * Familiarity with compliance frameworks and evidence collection for audits (SOX/SOC2/ISO27001-style controls). * Experience integrating IAM with ticketing/workflow systems and operational processes., * BA/BS in Computer Science, Engineering, Math, or a related subject * 5+ years of IAM experience * 3+ years of PAM and/or Secrets Management experience * 3+ years of cloud experience (e.g., Azure, AWS, G-Suite) * Equivalent work experience. ## Description As a Senior IAM Engineer, you will design, build, and operate core identity security capabilities across the enterprise. This includes Identity Governance & Administration (IGA) architecture, Privileged Access Management (PAM), and secrets management, as well as the automation and integrations that enable secure access at scale. This role is responsible for multiple areas of IAM (not just a single platform), and will contribute at a strategy, design, and execution level-partnering with Security, IT, and Engineering teams to deliver secure, reliable identity services., * Architect and implement IGA capabilities including identity lifecycle (joiner/mover/leaver), access request workflows, approvals, provisioning/deprovisioning automation, certifications, and role/entitlement governance. * Design and maintain the identity lifecycle management (ILM) framework and controls across the environment. * Build and enhance IAM integrations (e.g., HR source, directories, SaaS apps) using industry standards (SCIM, SAML/OIDC, APIs) and automation patterns. Privileged Access Management (PAM) & Secrets Management * Engineer and mature PAM controls and operating processes for privileged identities and activities, including access request/approval patterns, time-bound elevation, auditing, and least privilege enforcement. * Implement and manage secrets management capabilities (vaulting, rotation, access control, auditability) for human and non-human identities, including service principals and automation identities. Scripting, Automation, and Development * Develop automation using scripting and software engineering practices (e.g., PowerShell/Python/Bash), including CI/CD-friendly workflows and infrastructure-as-code patterns (e.g., Terraform). * Create repeatable solutions for access governance, role engineering, connector onboarding, reporting/analytics, and operational runbooks. Operations, Incident Support, and Continuous Improvement * Respond to IAM operational work (tickets/requests) requiring engineering changes and enhancements. * Assist in investigation and remediation of IAM incidents and issues, improving controls and automation to prevent recurrence. * Conduct proofs-of-concept (POCs), partner with vendors, and recommend solutions aligned to security and business requirements. Collaboration, Advisory, and Documentation * Serve as a trusted advisor to stakeholders-translating complex IAM topics into clear recommendations and implementation plans. * Produce and maintain technical documentation, standards, and procedures supporting audits and operational readiness. * Mentor peers and positively influence the team's technical direction., When you join OneTrust you are stepping onto a launching pad - the countdown has begun. The destination? A career without boundaries working alongside a diverse and inclusive crew who is passionate about doing meaningful work. As a pioneer, your voice and expertise will help chart the direction of an entirely new category. Our commitment to putting people first starts with you. Your growth is part of the mission. Our goal is to give you the power to embark on the next phase of your uniquely, unique career. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)