via Greenhouse · 4 de septiembre de 2026 ·hace 15 días

Sr. Identity and Access Management Engineer

OneTrust
Madrid
Este anuncio proviene de Greenhouse
Ver oferta original ↗

<div class="content-intro"><h3>Strength in Trust </h3>
<p><span data-contrast="auto">OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society.</span><span data-ccp-props="{}"> </span></p></div><h3>The Challenge</h3>
<p data-pm-slice="1 3 []">As a Senior IAM Engineer, you will design, build, and operate core identity security capabilities across the enterprise. This includes <strong>Identity Governance &amp; Administration (IGA) architecture</strong>, <strong>Privileged Access Management (PAM)</strong>, and <strong>secrets management</strong>, as well as the automation and integrations that enable secure access at scale.</p>
<p>This role is responsible for <strong>multiple areas of IAM</strong> (not just a single platform), and will contribute at a strategy, design, and execution level—partnering with Security, IT, and Engineering teams to deliver secure, reliable identity services.</p>
<h3>Your Mission</h3>
<p><strong>IAM / IGA Architecture &amp; Engineering</strong></p>
<ul>
<li>
<p>Architect and implement <strong>IGA capabilities</strong> including identity lifecycle (joiner/mover/leaver), access request workflows, approvals, provisioning/deprovisioning automation, certifications, and role/entitlement governance.</p>
</li>
<li>
<p>Design and maintain the <strong>identity lifecycle management (ILM) framework and controls</strong> across the environment.</p>
</li>
<li>
<p>Build and enhance IAM integrations (e.g., HR source, directories, SaaS apps) using industry standards (SCIM, SAML/OIDC, APIs) and automation patterns.</p>
</li>
</ul>
<p><strong>Privileged Access Management (PAM) &amp; Secrets Management</strong></p>
<ul>
<li>
<p>Engineer and mature <strong>PAM controls</strong> and operating processes for privileged identities and activities, including access request/approval patterns, time-bound elevation, auditing, and least privilege enforcement.</p>
</li>
<li>
<p>Implement and manage <strong>secrets management</strong> capabilities (vaulting, rotation, access control, auditability) for human and non-human identities, including service principals and automation identities.</p>
</li>
</ul>
<p><strong>Scripting, Automation, and Development</strong></p>
<ul>
<li>
<p>Develop automation using <strong>scripting and software engineering practices</strong> (e.g., PowerShell/Python/Bash), including CI/CD-friendly workflows and infrastructure-as-code patterns (e.g., Terraform).</p>
</li>
<li>
<p>Create repeatable solutions for access governance, role engineering, connector onboarding, reporting/analytics, and operational runbooks.</p>
</li>
</ul>
<p><strong>Operations, Incident Support, and Continuous Improvement</strong></p>
<ul>
<li>
<p>Respond to IAM operational work (tickets/requests) requiring engineering changes and enhancements.</p>
</li>
<li>
<p>Assist in investigation and remediation of IAM incidents and issues, improving controls and automation to prevent recurrence.</p>
</li>
<li>
<p>Conduct proofs-of-concept (POCs), partner with vendors, and recommend solutions aligned to security and business requirements.</p>
</li>
</ul>
<p><strong>Collaboration, Advisory, and Documentation</strong></p>
<ul>
<li>
<p>Serve as a trusted advisor to stakeholders—translating complex IAM topics into clear recommendations and implementation plans.</p>
</li>
<li>
<p>Produce and maintain technical documentation, standards, and procedures supporting audits and operational readiness.</p>
</li>
<li>
<p>Mentor peers and positively influence the team’s technical direction.</p>
</li>
</ul>
<p><strong>Required Technical Skills (Must Have)</strong></p>
<ul>
<li>
<p><strong>IGA architecture &amp; engineering expertise</strong> (identity lifecycle, RBAC/ABAC concepts, access reviews/certifications, entitlement modeling, SoD/least privilege).</p>
</li>
<li>
<p><strong>Privileged Access Management (PAM)</strong> concepts and hands-on implementation (JIT/JEA, session controls, privileged identity separation, auditing).</p>
</li>
<li>
<p><strong>Secrets management</strong> (vaulting, rotation, access policies, non-human identity security).</p>
</li>
<li>
<p><strong>Scripting and development skills</strong> (e.g., SQL, JavaScript, PowerShell, Python, Velocity, SOAPUI, ARC, Postman, Java/J2EE, Bash; API integration; Git-based workflows).</p>
</li>
<li>
<p>Experience designing and operating IAM controls in modern enterprise environments (cloud + SaaS) - especially Azure, including authentication/authorization and identity governance patterns.</p>
</li>
</ul>
<p><strong>Preferred Skills (Nice to Have)</strong></p>
<ul>
<li>
<p>Experience with IGA platforms (e.g., Saviynt, SailPoint, Omada) and IAM directories/IDPs (e.g., Entra ID/Azure AD).</p>
</li>
<li>
<p>Experience with PAM and secrets tooling (e.g., CyberArk, Delinea, BeyondTrust, Akeyless, HashiCorp Vault, Azure Key Vault, AWS Secrets Manager).</p>
</li>
<li>
<p>Familiarity with compliance frameworks and evidence collection for audits (SOX/SOC2/ISO27001-style controls).</p>
</li>
<li>
<p>Experience integrating IAM with ticketing/workflow systems and operational processes.</p>
</li>
</ul>
<h3>You Are </h3>
<p>Typically requires a minimum of:</p>
<ul>
<li>
<p>BA/BS in Computer Science, Engineering, Math, or a related subject</p>
</li>
<li>
<p>5+ years of IAM experience</p>
</li>
<li>
<p>3+ years of PAM and/or Secrets Management experience</p>
</li>
<li>
<p>3+ years of cloud experience (e.g., Azure, AWS, G-Suite)</p>
</li>
<li>
<p>Equivalent work experience.</p>
</li>
</ul>
<p> </p><div class="content-conclusion"><h3><span class="TextRun SCXW202854797 BCX0" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW202854797 BCX0">Where we Work</span></span></h3>
<p>We are embracing an office-first culture, encouraging three days a week in office for most roles, with meaningful opportunities to collaborate and celebrate in person.</p>
<p>Each role may have specific requirements or flexibility depending on the scope of the position, so we encourage you to verify this with your recruiter during your first interview.</p>
<h3><span class="TextRun SCXW202854797 BCX0" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW202854797 BCX0">Benefits</span></span></h3>
<p><span class="TextRun SCXW202854797 BCX0" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW202854797 BCX0">As an employee at </span><span class="NormalTextRun SpellingErrorV2Themed SCXW202854797 BCX0">OneTrust</span><span class="NormalTextRun SCXW202854797 BCX0">, you will be part of the </span><span class="NormalTextRun SpellingErrorV2Themed SCXW202854797 BCX0">OneTeam</span><span class="NormalTextRun SCXW202854797 BCX0">. That means </span><span class="NormalTextRun SCXW202854797 BCX0">you’ll</span><span class="NormalTextRun SCXW202854797 BCX0"> receive support physically, mentally, and emotionally so that you can do your best work both in and out of the office. This includes comprehensive healthcare coverage, flexible PTO, equity RSUs, annual performance bonus opportunities, retirement account support, 14+ weeks of paid parental leave, career development opportunities, company-paid privacy certification exam fees, and much more. Specific benefits differ by country. For more information, talk to your recruiter or visit onetrust.com/careers.</span></span></p>
<h3>Resources </h3>
<p>Check out the following to learn more about OneTrust and its people: </p>
<ul>
<li><a class="fui-Link ___m14voj0 f3rmtva f1ern45e f1deefiw f1n71otn f1q5o8ev f1h8hb77 f1vxd6vx f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1hu3pq6 f11qmguv f19f4twv f1tyq0we f1g0x7ka fhxju0i f1qch9an f1cnd47f fqv5qza f1vmzxwi f1o700av f13mvf36 f9n3di6 f1ids18y fygtlnl f1deo86v f12x56k7 f1iescvh ftqa4ok f50u1b5 fs3pq8b f1hghxdh f1tymzes f1x7u7e9 f1cmlufx f10aw75t fsle3fq" href="https://youtube.com/playlist?list=PLTM-0khp0wIWkO-Bh3IfdSMMOi8606Tl0" target="_blank">OneTrust Careers on YouTube</a></li>
<li><a class="fui-Link ___m14voj0 f3rmtva f1ern45e f1deefiw f1n71otn f1q5o8ev f1h8hb77 f1vxd6vx f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1hu3pq6 f11qmguv f19f4twv f1tyq0we f1g0x7ka fhxju0i f1qch9an f1cnd47f fqv5qza f1vmzxwi f1o700av f13mvf36 f9n3di6 f1ids18y fygtlnl f1deo86v f12x56k7 f1iescvh ftqa4ok f50u1b5 fs3pq8b f1hghxdh f1tymzes f1x7u7e9 f1cmlufx f10aw75t fsle3fq" href="https://www.instagram.com/lifeatonetrust/" target="_blank">@LifeatOneTrust on Instagram</a></li>
</ul>
<h3>Your Data</h3>
<p>You have the right to have your personal data updated or removed. You also have the right to have a copy of the information OneTrust holds about you. Further details about these rights are available on the website in our <a href="https://trustcenter-privacy.my.onetrust.com/policies/39803da3-9bb9-4709-afaf-2ba0a14d09ca?context=eyJkc1BvcnRhbElkIjoiZWM5MmYwZmEtYjFiNi00YzdlLWJmN2ItMDdlNTc2MTQyMGQxIn0%3D" target="_blank">Privacy Overview</a><strong>. </strong>You can change your mind at any time and have your personal data removed from our database. In order to do this you must contact us and let us know you wish to be removed. The request should be made on the <a href="https://privacyportal-cdn.onetrust.com/dsarwebform/37bcc497-a196-48f1-a08b-e897b5a77859/08a01c64-41fd

El mercado para este tipo de puesto

Ofertas similares
304
puestos de Ingeniería en Madrid
Jornada completa
82%
de las ofertas de Ingeniería en España
Teletrabajo posible
33%
de las ofertas de Ingeniería
OneTrust

27 open positions · Amsterdam, London, Madrid, Munich, New York +1

📊 Ingeniería · España
720
active jobs
32.5%
Remote
Ø 3d
avg. online
Top skills in demand
ExcelERPISOPythonAWSCI/CDSQLAzureAgileLean

Preguntas frecuentes

¿Cuántos empleos de Ingeniería hay disponibles en Madrid?
Actualmente 304 puestos de Ingeniería en Madrid en AlmostHired, en 101 empresas diferentes. Nuestros datos se actualizan a diario.
¿Los puestos de Ingeniería ofrecen teletrabajo?
33% de las ofertas de Ingeniería en España permiten teletrabajo, parcial o completo. Para filtrar específicamente puestos en remoto, usa AlmostHired.
¿Cómo sé si encajo en esta oferta?
Sube tu CV — nuestra IA compara tu perfil con los requisitos del puesto y te da una puntuación de coincidencia precisa, con habilidades coincidentes y faltantes.