IAM Security Engineer
In this role, you will:
* Design and implement security controls across the IDAM 2.0 platform.
* Embed Secure by Design principles throughout solution delivery.
* Implement and maintain Zero Trust security controls.
* Configure and maintain authentication and authorisation security mechanisms.
* Implement secure service-to-service communication using mutual TLS (mTLS).
* Implement and maintain Policy-as-Code solutions using OPA and related technologies.
* Integrate secrets management, PKI and certificate lifecycle services.
* Support cryptographic key management and certificate rotation processes.
* Perform security reviews of solution designs, infrastructure and application code.
* Conduct threat modelling and security risk assessments.
* Develop and maintain security baselines, standards and hardening guides.
* Implement cloud security controls for GCP resources and Kubernetes platforms.
* Support identity governance, privileged access and least privilege implementation.
* Collaborate with Security Operations and Incident Response teams during security events.
* Support security assurance for third-party integrations and supplier solutions.
Essential Skills:
* Information Security Engineering
* Identity and Access Management (IAM)
* Zero Trust Architecture
* Authentication and Authorisation
* Workload Identity
* Agent Identity
* PKI and Certificate Management
* Cryptography
* Cloud Security (GCP)
* Kubernetes Security
* API Security
* Policy-as-Code (OPA)
* DevSecOps