5 hours ago
London, United KingdomSenior / Staff+
Responsibilities
- Design and evolve federated IAM architecture, least-privilege models, RBAC and ABAC controls, cross-account access, workload identity governance, and Zero Trust access patterns.
- Build and maintain reusable Terraform modules and workflows for IAM roles, policies, permission sets, group mappings, Okta assignments, IAM Identity Center, onboarding, offboarding, and access changes.
- Automate access requests, approvals, provisioning, deprovisioning, access reviews, reporting, audit visibility, and day-to-day IAM operations.
- Reduce identity risk through permission boundary enforcement, credential reduction, privileged access controls, break-glass workflows, anomaly detection, and identity investigations.
- Support Twingate, PAM integrations, adaptive access, MFA, passwordless authentication, vendor access, and privileged session controls.
- Improve IAM troubleshooting, detection, monitoring, evidence collection, operational metrics, and audit readiness.
- Develop AI-assisted identity security workflows, internal copilots, intelligent triage, security chatops, and MCP-enabled automation with appropriate safeguards.
- Provide technical guidance and influence teams toward scalable, secure, and automation-first identity practices.
Requirements
- 8–12+ years of experience in IAM security engineering, cloud security, identity architecture, or related security engineering roles.
- Strong hands-on experience with AWS IAM, AWS Organizations, IAM Identity Center, SCPs, IAM roles and policies, CloudTrail, GuardDuty, IAM Access Analyzer, and SSM.
- Strong hands-on experience with GCP IAM, service accounts, workload identity, organization/folder/project models, and audit services.
- Strong Okta administration experience, including groups, rules, application integrations, assignments, lifecycle management, and troubleshooting.
- Experience with SAML, OIDC, OAuth, SCIM, federated identity, cross-account and cross-project access, and service-account governance.
- Production experience with Terraform-based IAM automation, reusable modules, state management, drift detection, rollback planning, safe deployment, and CI/CD integration.
- Experience with Git-based workflows, pull requests, code review, Python, Bash, PowerShell, APIs, and workflow automation.
- Experience with Twingate or comparable ZTNA and remote-access platforms, including connectors, resources, access policies, and troubleshooting.
- Strong understanding of policy-as-code, identity threat modeling, privileged and just-in-time access, identity lifecycle management, logging, monitoring, access reviews, and audit readiness.
- Experience or strong interest in Claude Code, Codex, MCP integrations, agent-based automation, AI-assisted detection and triage, prompt security, model safety, and human-in-the-loop controls.
- Ability to partner with engineering, infrastructure, security, compliance, IT, and leadership stakeholders and communicate IAM risks and solutions effectively.
- Bonus experience includes Britive, CyberArk, SailPoint, Okta Workflows, CIEM, identity governance tools, Wiz, Astrix, passwordless authentication, WebAuthn, FIDO2, AI security frameworks, or relevant security certifications such as CISSP or AWS Security Specialty.
Benefits
- Remote work is available, with a hybrid option for candidates located in Barcelona.
- The posting requests that the attached résumé/CV be written in English.
Tech Stack
Categories
About Scopely
Scopely develops, publishes, and live-operates free-to-play games across mobile, PC, and console, including MONOPOLY GO!, Stumble Guys, Star Trek Fleet Command, MARVEL Strike Force, WWE Champions, and Yahtzee With Buddies. Founded in 2011 and headquartered in Culver City, California, it uses its Playgami technology platform and collaborates with studios worldwide. In 2023, Scopely was acquired by Savvy Games Group and continues to operate as an independent subsidiary.