freehire launches on Product Hunt on 26 August.

Follow →

Chief IAM Engineer

This position is no longer accepting applications(closed Aug 17, 2026).

Summary

Designs and implements advanced workflows, scripts, and API integrations for enterprise Privileged Access (PA) secrets management, credential auto-rotation, lifecycle management, and compliance reporting, bridging IAM and Security/GRC teams to automate governance gaps.

We are building a Chief IAM Engineer role to extend an enterprise Privileged Access (PA) secrets management and privileged access program. You will architect and deliver custom scripts and Workflows for SaaS credential auto-rotation, lifecycle management, compliance reporting, and access attestations, partnering closely with IAM and Security/GRC teams to close PA gaps—apply now.

Responsibilities

  • Design and implement advanced Workflows to meet enterprise governance needs beyond PA's native capabilities
  • Develop custom scripts and API integrations to automate credential rotation for non-federated local SaaS accounts and connected apps (e.g., Salesforce ECAs, Snowflake Key Pair Auth, Workday), using vendor APIs
  • Create workflows triggered by Lifecycle Management (LCM) events to handle orphaned secrets, dynamically resolve manager routing, and send multi-interval expiration notifications (e.g., T-60, T-30) via Slack, Teams, or Email
  • Implement automated solutions to pull secrets metadata through the OPA API, produce CSV exports, and update external tracking dashboards for rotation success rates, overdue secrets, and orphaned accounts
  • Orchestrate hybrid attestation campaigns by combining PA metadata with Identity Governance (IG) and ITSM tools (e.g., Jira) for annual secret-owner reviews and rotation exception logging
  • Integrate APIs, PA REST endpoints, and third-party systems to enable consistent secrets vaulting and attribute tracking
  • Translate PA functional gaps into engineering solutions by delivering scalable, secure, well-documented workarounds instead of manual processes
  • Build attestation, reporting, and audit-logging flows that withstand SOC 2, ISO 27001, and NIST-style scrutiny
  • Collaborate as the technical bridge between IAM and Security/GRC teams, converting governance requirements into reliable automation

Requirements

  • Proven background in Identity and Access Management for 7+ years, spanning Privileged Access Management (PAM), Secrets Management, Non-Human Identity (NHI) governance, Just-in-Time (JIT) access, and Zero Standing Privileges (ZSP)
  • Deep, hands-on administrative expertise with Workforce Identity Cloud (WIC), Privileged Access (PA), and Identity Governance (IG)
  • Working knowledge of Identity Governance Administration (IGA) concepts
  • Demonstrated track record building, validating, and releasing workflows for orchestration and automation
  • High proficiency in Python, plus Node.js or Bash
  • Hands-on experience with RESTful APIs, JSON, and webhooks to deliver custom integrations and programmatic workarounds
  • Solid understanding of SOC 2, ISO 27001, and NIST, and their impact on privileged credential handling, audit logging, and access attestations
  • Strong ability to assess product constraints and engineer scalable workarounds
  • English proficiency at B2 level or higher

Nice to have

  • Familiarity with SIEM integrations for audit logging
  • Experience with workload identities and runtime secret injection
  • Prior experience in a security engineering capacity within an enterprise environment

Benefits

  • International projects with top brands
  • Work with global teams of highly skilled, diverse peers
  • Healthcare benefits
  • Employee financial programs
  • Paid time off and sick leave
  • Upskilling, reskilling and certification courses
  • Unlimited access to the LinkedIn Learning library and 22,000+ courses
  • Global career opportunities
  • Volunteer and community involvement opportunities
  • EPAM Employee Groups
  • Award-winning culture recognized by Glassdoor, Newsweek and LinkedIn

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available