Cloud IAM Engineer
About the Role
We're seeking a Cloud IAM Operations Engineer to manage day-to-day identity and access provisioning across our AWS environment. This is a hands-on, execution-focused role where you'll review incoming access requests against least-privilege principles and implement approved access using Infrastructure as Code. You'll operate in alignment with established policies, partnering closely with security architecture on escalations and edge cases.
Responsibilities
- Review AWS access requests against least-privilege and organizational access policy
- Provision and implement approved access using Infrastructure as Code (CDK preferred; or similar IaC tools considered)
- Manage and maintain the organization's Just-In-Time (JIT) access management tool, ensuring all human-use AWS access is provisioned on-demand through JIT workflows
- Maintain accurate, auditable records of access grants, changes, and revocations
- Identify and escalate access requests that fall outside standard policy or carry elevated risk
- Support periodic access reviews and recertification processes
- Contribute to runbooks and documentation to improve consistency and repeatability of the access request lifecycle
- Partner with security architecture and IAM leadership on process improvements and automation opportunities
- Conduct periodic reviews of AWS IAM permission sets using IAM Access Analyzer and other tooling to refine access controls
Qualifications
- 2–4 years of experience in cloud security, IAM, or cloud technologies in AWS
- Working experience with AWS IAM fundamentals (roles, policies, permission sets, least-privilege design)
- Strong interpersonal and communication skills
- Working experience with Infrastructure as Code (CDK preferred; Pulumi, or CloudFormation also considered)
- Understanding of access review and audit requirements in a regulated environment
- Working experience implementing or administering Just-In-Time (JIT) access management tools
- Strong attention to detail and sound judgment on access decisions
- Clear written communication for documentation and access decision records
Preferred Qualifications
- Experience in a healthcare or other regulated industry (HIPAA/HITRUST-aware)
- Familiarity with identity governance tooling and access certification workflows
- Basic scripting ability (Python, TypeScript, or similar) to support IaC workflows
Work Environment
This is a remote, full-time, permanent position based in the US. The role requires working across multiple time zones and may involve occasional travel. Physical demands include prolonged periods of sitting and/or standing in front of a computer, with specific vision abilities such as close vision, color vision, peripheral vision, depth perception, and ability to adjust focus.
Pay
The annual US base salary range for this position is $107,000 to $114,000. Final compensation will be determined during the interview process based on skills, experience, qualifications, and education.