Logo for ICONMA

Senior AWS Identity & Security Engineer – SRE / Cloud Security

Role overview

Qualifications

  • Advanced Identity Security (Primary) AWS IAM Identity Center (IdC), SAML/OIDC federation, and integration with an existing enterprise federation
  • Advanced Attribute-based access control (ABAC) and fine-grained authorization engines such as AWS Verified Permissions or Open Policy Agent (OPA)
  • Advanced AWS Organizations, CloudFormation StackSets, and Org-level APIs and policies, able to automate resource provisioning at a scale of 15,000 accounts
  • Proficient in Python, Java, or Go for building high-performance REST/API services

Responsibilities

  • Integrate the API layer with AWS IAM Identity Center (IdC) and build a policy engine to enforce data boundaries
  • Implement and automate links to aggregate logs, metrics, and traces across multiple AWS Organizations
  • Build, test, and deploy features from the AWS infrastructure layer using CloudWatch cross-account capabilities
  • Automate the deployment of all resources using Terraform or AWS CDK, leveraging AWS CloudFormation StackSets

About the company

ICONMA logo

ICONMA

Management Consulting

We provide Professional Staffing Services & Project-Based Solutions for a broad range of Fortune 500 organizations. ICONMA is a certified Woman-Owned staffing company and was founded in 2000. ICONMA’s corporate headquarters is in Troy, Michigan, and has 15+ locations worldwide. What makes ICONMA stand out in a fiercely competitive industry? *We provide integrated, full lifecycle services across a broad range of business and technical platforms. *No single company can duplicate our full range of staffing and permanent recruiting services nationwide. *Proven track record of attracting and retaining exceedingly skilled professional workers in a highly competitive market. SERVICES OFFERED Staff Augmentation (Contract, Contract to Hire, Direct Hire, Single Source) Data Analysis Project-Based Services & Solutions Hire Train Deploy Service Model Offshore Staff Augmentation Payroll Services AREAS OF EXPERTISE - Information Technology - Engineering - Business Professional - Accounting/Finance - Admin/Clerical/Call Center - Healthcare/Clinical/Scientific - Marketing/Creative mail linkedin@iconma.com Phone (888) 451-2519 Website http://www.iconma.com

Company details

Company typeLarge
IndustryManagement Consulting
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Our client, a IT Services and Consulting company, is looking for a Senior AWS Identity & Security Engineer – SRE / Cloud Security for their New York, NY/New Jersey, NJ/Dallas, TX/Remote location.
 
Responsibilities:

  • Identity & Entitlements: Integrate the API layer with AWS IAM Identity Center (IdC) and build a policy engine to enforce data boundaries (SRE vs. App Team vs. Business Unit). This includes integrating Omni into the client’s existing identityfederation model — an established custom credentialvending / SAML broker on the primary landing zone plus existing IdC adoption for console access.
  • CrossAccount Data Routing: Implement and automate links to aggregate logs, metrics, and traces across multiple AWS Organizations.
  • EndtoEnd Feature Delivery: Build, test, and deploy features from the AWS infrastructure layer (CloudWatch / Omni / IAM) up through the API layer that serves the UI, using CloudWatch crossaccount capabilities. May include writing highperformance APIs (in Go, Python, or Java) to query CloudWatch, CloudTrail, and flow logs, and implementing efficient caching strategies.
  • Infrastructure as Code (IaC): Automate the deployment of all resources using Terraform or AWS CDK, leveraging AWS CloudFormation StackSets to deploy source links to 15,000 accounts.
  • Enablement: Produce clear architecture and integration documentation and enable the client’s teams to operate and extend the Omni identity and routing model, working as an embedded SME alongside the client’s SRE and observability leadership.
 
Requirements:
  • Top skills required for this role:
  • Advanced. Identity & Security (Primary)  AWS IAM Identity Center (IdC), SAML/OIDC federation, and integration with an existing enterprise federation / credentialvending model
  • Advanced. Attributebased access control (ABAC) and finegrained authorization engines such as AWS Verified Permissions or Open Policy Agent (OPA).
  • Advanced. AWS Organizations, CloudFormation StackSets, and Orglevel APIs and policies. Able to automate resource provisioning at a scale of 15,000 accounts.
  • Proficient. Python, Java, or Go. Building highperformance REST/API services to query CloudWatch, CloudTrail, and flow logs, with efficient caching strategies and asynchronous data fetching.
  • Advanced. CloudWatch (Metrics, Logs, Alarms, Contributor Insights), CloudWatch crossaccount observability / OAM (sink and source configuration), CloudTrail, and flow logs.
  • Advanced. Terraform or AWS CDK, with CI/CD pipelines (e.g. GitLab CI) for automated infrastructure deployment.
  • Years of Experience:   
  • 12.00 Years of Experience
 
Why Should You Apply?

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Cloud Security Engineer Related jobs

Other jobs at ICONMA

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.