Sr. Identity and Access Management Engineer

Posted 2 Days Ago
Be an Early Applicant
Madrid, Comunidad de Madrid, ESP
Hybrid
Senior level
Artificial Intelligence • Cloud • Information Technology • Security • Social Impact • Software • Cybersecurity
The Role
Designs, implements, and operates enterprise IAM capabilities across IGA, PAM, and secrets management. Builds identity lifecycle controls, access workflows, integrations, automation, and governance processes using scripting, APIs, and infrastructure-as-code. Supports IAM operations, incident remediation, audits, proofs of concept, documentation, and stakeholder advisory activities while mentoring peers and shaping technical strategy.
Summary Generated by Built In
Strength in Trust 

OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society. 

The Challenge

As a Senior IAM Engineer, you will design, build, and operate core identity security capabilities across the enterprise. This includes Identity Governance & Administration (IGA) architecture, Privileged Access Management (PAM), and secrets management, as well as the automation and integrations that enable secure access at scale.

This role is responsible for multiple areas of IAM (not just a single platform), and will contribute at a strategy, design, and execution level—partnering with Security, IT, and Engineering teams to deliver secure, reliable identity services.

Your Mission

IAM / IGA Architecture & Engineering

  • Architect and implement IGA capabilities including identity lifecycle (joiner/mover/leaver), access request workflows, approvals, provisioning/deprovisioning automation, certifications, and role/entitlement governance.

  • Design and maintain the identity lifecycle management (ILM) framework and controls across the environment.

  • Build and enhance IAM integrations (e.g., HR source, directories, SaaS apps) using industry standards (SCIM, SAML/OIDC, APIs) and automation patterns.

Privileged Access Management (PAM) & Secrets Management

  • Engineer and mature PAM controls and operating processes for privileged identities and activities, including access request/approval patterns, time-bound elevation, auditing, and least privilege enforcement.

  • Implement and manage secrets management capabilities (vaulting, rotation, access control, auditability) for human and non-human identities, including service principals and automation identities.

Scripting, Automation, and Development

  • Develop automation using scripting and software engineering practices (e.g., PowerShell/Python/Bash), including CI/CD-friendly workflows and infrastructure-as-code patterns (e.g., Terraform).

  • Create repeatable solutions for access governance, role engineering, connector onboarding, reporting/analytics, and operational runbooks.

Operations, Incident Support, and Continuous Improvement

  • Respond to IAM operational work (tickets/requests) requiring engineering changes and enhancements.

  • Assist in investigation and remediation of IAM incidents and issues, improving controls and automation to prevent recurrence.

  • Conduct proofs-of-concept (POCs), partner with vendors, and recommend solutions aligned to security and business requirements.

Collaboration, Advisory, and Documentation

  • Serve as a trusted advisor to stakeholders—translating complex IAM topics into clear recommendations and implementation plans.

  • Produce and maintain technical documentation, standards, and procedures supporting audits and operational readiness.

  • Mentor peers and positively influence the team’s technical direction.

Required Technical Skills (Must Have)

  • IGA architecture & engineering expertise (identity lifecycle, RBAC/ABAC concepts, access reviews/certifications, entitlement modeling, SoD/least privilege).

  • Privileged Access Management (PAM) concepts and hands-on implementation (JIT/JEA, session controls, privileged identity separation, auditing).

  • Secrets management (vaulting, rotation, access policies, non-human identity security).

  • Scripting and development skills (e.g., SQL, JavaScript, PowerShell, Python, Velocity, SOAPUI, ARC, Postman, Java/J2EE, Bash; API integration; Git-based workflows).

  • Experience designing and operating IAM controls in modern enterprise environments (cloud + SaaS) - especially Azure, including authentication/authorization and identity governance patterns.

Preferred Skills (Nice to Have)

  • Experience with IGA platforms (e.g., Saviynt, SailPoint, Omada) and IAM directories/IDPs (e.g., Entra ID/Azure AD).

  • Experience with PAM and secrets tooling (e.g., CyberArk, Delinea, BeyondTrust, Akeyless, HashiCorp Vault, Azure Key Vault, AWS Secrets Manager).

  • Familiarity with compliance frameworks and evidence collection for audits (SOX/SOC2/ISO27001-style controls).

  • Experience integrating IAM with ticketing/workflow systems and operational processes.

You Are 

Typically requires a minimum of:

  • BA/BS in Computer Science, Engineering, Math, or a related subject

  • 5+ years of IAM experience

  • 3+ years of PAM and/or Secrets Management experience

  • 3+ years of cloud experience (e.g., Azure, AWS, G-Suite)

  • Equivalent work experience.


Where we Work

We are embracing an office-first culture, encouraging three days a week in office for most roles, with meaningful opportunities to collaborate and celebrate in person.

Each role may have specific requirements or flexibility depending on the scope of the position, so we encourage you to verify this with your recruiter during your first interview.

Benefits

As an employee at OneTrust, you will be part of the OneTeam. That means you’ll receive support physically, mentally, and emotionally so that you can do your best work both in and out of the office. This includes comprehensive healthcare coverage, flexible PTO, equity RSUs, annual performance bonus opportunities, retirement account support, 14+ weeks of paid parental leave, career development opportunities, company-paid privacy certification exam fees, and much more. Specific benefits differ by country. For more information, talk to your recruiter or visit onetrust.com/careers.

Resources  

Check out the following to learn more about OneTrust and its people: 

  • OneTrust Careers on YouTube
  • @LifeatOneTrust on Instagram
Your Data

You have the right to have your personal data updated or removed. You also have the right to have a copy of the information OneTrust holds about you. Further details about these rights are available on the website in our Privacy OverviewYou can change your mind at any time and have your personal data removed from our database. In order to do this you must contact us and let us know you wish to be removed. The request should be made on the Data Subject Request Form.


Recruitment fraud warning: OneTrust is aware of scams involving false offers of employment with our company. The fraudulent jobs, interviews and job offers use fake websites, email addresses, group chat and text messages. Be aware that we never ask candidates for personal information, IDs or bank information during the interview process. We do not interview prospective candidates via instant message or group chat, and do not require candidates to purchase products or services, or process payments on our behalf as a condition of any employment offer. Please note that any legitimate interview availability requests will come directly from a OneTrust recruiter with an "@onetrust.com" email address. You may also receive legitimate emails from "@us.greenhouse-mail.io". Recruiters will only reach out to candidates who have applied for a role through our ATS (Greenhouse) or prospects via LinkedIn InMail. Job offers will come from a recruiter and may have a "@docusign.net" email address. For more information or if you have been targeted please reach out to [email protected].

Our Commitment to You 

When you join OneTrust you are stepping onto a launching pad — the countdown has begun. The destination? A career without boundaries working alongside a diverse and inclusive crew who is passionate about doing meaningful work. As a pioneer, your voice and expertise will help chart the direction of an entirely new category. Our commitment to putting people first starts with you. Your growth is part of the mission. Our goal is to give you the power to embark on the next phase of your uniquely, unique career. 

OneTrust provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by local laws.

Skills Required

  • Bachelor’s degree in Computer Science, Engineering, Math, or a related field, or equivalent work experience
  • 5+ years of IAM experience
  • 3+ years of PAM and/or secrets management experience
  • 3+ years of cloud experience, such as Azure, AWS, or G-Suite
  • IGA architecture and engineering expertise, including identity lifecycle, RBAC/ABAC, access reviews, certifications, entitlement modeling, SoD, and least privilege
  • Hands-on PAM implementation experience, including JIT/JEA, session controls, privileged identity separation, and auditing
  • Secrets management experience, including vaulting, rotation, access policies, and non-human identity security
  • Scripting and development skills using technologies such as SQL, JavaScript, PowerShell, Python, Velocity, SOAPUI, ARC, Postman, Java/J2EE, and Bash
  • API integration and Git-based workflow experience
  • Experience designing and operating IAM controls in modern cloud and SaaS enterprise environments, especially Azure
  • Experience with IGA platforms such as Saviynt, SailPoint, or Omada
  • Experience with PAM and secrets tools such as CyberArk, Delinea, BeyondTrust, Akeyless, HashiCorp Vault, Azure Key Vault, or AWS Secrets Manager
  • Familiarity with SOX, SOC 2, or ISO 27001-style compliance controls and audit evidence collection
  • Experience integrating IAM with ticketing and workflow systems

OneTrust Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about OneTrust and has not been reviewed or approved by OneTrust.

  • Healthcare Strength Healthcare coverage is positioned as a standout benefit, including fully company-paid employee premiums with partial dependent coverage plus dental, vision, telemedicine, and disability coverage. Additional offerings such as fertility treatment coverage, EAP support, and wellness reimbursements reinforce the overall health package.
  • Leave & Time Off Breadth Time-off benefits are described as expansive, with unlimited PTO alongside paid holidays, sick time, and paid volunteer time. A companywide recharge week and “work from anywhere” flexibility further strengthen the perceived breadth of leave-related benefits.
  • Parental & Family Support Parental leave is framed as generous, with paid bonding leave for all parents and longer leave for birthing parents, inclusive of adoption and surrogacy. This emphasis on family support appears as a consistent differentiator within the overall rewards package.

OneTrust Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Atlanta, GA
2,000 Employees
Year Founded: 2016

What We Do

OneTrust, the AI-Ready Governance Platform™, enables innovation through the responsible use of data and AI. Trusted by over half of the Fortune 500, we help businesses govern well and move fast, turning responsible data use into a catalyst for growth.

Gallery

Gallery

Similar Jobs

Mastercard Logo Mastercard

Director, Services Business Development - Global Financial Institutions

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Madrid, Comunidad de Madrid, ESP
38800 Employees

Celonis Logo Celonis

Executive Assistant

Big Data • Information Technology • Productivity • Software • Analytics • Business Intelligence • Consulting
Hybrid
Madrid, Comunidad de Madrid, ESP
3000 Employees

Nexthink Logo Nexthink

Principal, Renewal Operations & Strategy

Artificial Intelligence • Big Data • Cloud • Information Technology • Machine Learning • Software
Hybrid
Madrid, Comunidad de Madrid, ESP
1200 Employees

2K Logo 2K

LQA Analyst, Arabic

Gaming • Information Technology • Mobile • Software • Esports
Hybrid
Madrid, Comunidad de Madrid, ESP
4200 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account