Talent Apply
Log in
All jobs
R

Senior Identity And Access Management Engineer - Cloud Environment

Roche
Madrid, Spain
On-site

About this role

Job title: Senior Identity And Access Management Engineer - Cloud Environment

About the Role The Security and Cybersecurity Analyst serves as a trusted advisor and independent leader who drives the analysis of moderately complex cybersecurity incidents and technical problems. By bridging deep business and technical understanding, you will manage end-to-end security analysis tasks across multiple products within a domain and shape stakeholder perspectives, taking on security incident lead or project owner roles to foster continuous improvement in security operations and practices.

What You'll Do

  • Manage the multi-cloud Identity Management environment focusing on Azure and Google Cloud Platform (GCP), while maintaining alignment with AWS, including design of new solutions and ongoing maintenance and lifecycle management.
  • Contribute to the design of new solutions based on SailPoint and PingFederate, AD, and Privileged Access Management; design and implement centralized RBAC based on Cloud Adoption Framework (CAF).
  • Enforce Access Governance and Controls: MFA, Identity Protection, and least privilege policies with custom roles and separation of duties; implement IAM Deny Policies to strictly block high-risk actions.
  • Drive Automation and Infrastructure-as-Code: design and implement IAM infrastructure using Terraform; for Azure, use Terraform and Azure Verified Modules (AVM) with CI/CD pipelines in GitLab.
  • Privileged Access Management (PAM): design and support Just-in-Time (JIT) access mechanisms, eliminating standing privileges (e.g., using CyberArk).
  • Operational Excellence: provide 2nd/3rd level support for Identity Management infrastructure; monitor performance, availability, and capacity; support release management activities.
  • Stakeholder Management: act as a mentor and consultant; engage with stakeholders and managed service providers; facilitate workshops and align initiatives with project goals.
  • Strategy and Complexity: translate requirements into implementation plans; shape team processes and contribute to Communities of Practice; navigate ambiguous requirements and complex stakeholder environments.

What We're Looking For

  • 5-7 years of experience in a major global organization, preferably in a regulated industry; degree in computer science, engineering, or related field; equivalent experience accepted; industry certification desirable.
  • Proven ability to manage relationships with diverse cross-functional stakeholders; trusted advisor.
  • Track record of championing accountability, including security incident leads and/or security project ownership.
  • Strong hands-on IT operations background with expert knowledge of SailPoint IQ Identity Governance and Access Identity Management; experience with Azure and GCP (and AWS) preferred; familiarity with SailPoint, PingFederate, Active Directory and PAM.
  • Technical skills to apply tools, concepts, and techniques across requirements, data, usability, and process analysis; ability to work independently on complex projects.

Nice to Have

  • Additional cloud experience across Azure, GCP, and AWS; Terraform with AVM; CI/CD pipelines in GitLab.
  • Experience with Privileged Access Management (PAM) solutions such as CyberArk; familiarity with Cloud Adoption Framework (CAF) principles.
  • Industry accreditation or relevant security certifications.

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →