Access Engineer & IAM Auditor
Growe
WorldwideremotePosted 8 days ago
Skill Required
Accessibility-EngineerIAM-AuditsIAMCybersecurityCompliance-AuditingAccess-Management-EngineerIdentity-And-Access-Management-EngineerIAM-Security-EngineerAccess-Control-EngineerIAM-Solutions-EngineerIAM-Audit-and-Compliance-AnalystCloud-IAM-EngineerIdentity-And-Access-Management-EngineeringIdentity-And-Access-Management-ArchitectISO 27001designingbuildingwrittendesignGCPandFulltime
Key highlights
- Auditing GCP IAM, LDAP, and PAM tools
- Tracking remediation through closure with system owners
- Building audit process from scratch
- Experience with IGA tools (One Identity, Okta, Entra ID, Keycloak)
- Familiarity with ISO 27001, SOC 2, NIST
- 2+ years as Access Engineer/IAM Auditor or similar
Role overview
Responsibilities
- Design and establish a standardized access audit framework, including methodology, cadence, evidence collection, and reporting templates
- Define risk-based audit scope and sampling methodology appropriate for a large, complex, multi-system landscape
- Run regular (scheduled/periodic) and ad-hoc access audits across the environment, including privileged and administrative accounts
- Audit GCP IAM, LDAP, and PAM tools for stale accounts, excessive permissions, orphaned access, and misconfigurations
- Prepare clear, audit-ready reports and evidence packages suitable for internal review and external auditors
- Track remediation actions with system and application owners through to closure, escalating overdue items as needed
- Maintain audit documentation and process runbooks to ensure repeatability and continuity
- Continuously refine the audit methodology based on findings, tooling changes, and evolving compliance requirements
Requirements
- 2+ years in the position of Access Engineer/IAM Auditor or similar
- Experience designing and building an access audit process from scratch
- Hands-on experience with GCP/LDAP (roles, permissions, service accounts, org policies)
- Hands-on experience with Privileged Access Management (PAM) tools and privileged/admin account audits
- Experience working across IGA tools (e.g., One Identity, Okta, Entra ID, Keycloak)
- Familiarity with compliance frameworks such as ISO 27001, SOC 2, and NIST
- At least Intermediate level of English (written and spoken)
Nice to have
- Strong team-player orientation with the ability to maintain a positive and constructive atmosphere within the team
- High reliability and consistency in delivering work to a high standard of accuracy and attention to detail
- Self-dependent, result-oriented mindset
- A growth mindset - comfortable acknowledging mistakes, learning from them, and implementing corrective measures to prevent recurrence
Additional details
- We align with core values: GROWE TOGETHER (team is main asset, work together and support each other), DRIVE RESULT OVER PROCESS (set ambitious, clear, measurable goals), BE READY FOR CHANGE (see challenges as opportunities, adapt today to win tomorrow)