Rodeo
Get started

Scopely

Senior Security IAM Engineer

London
Posted about 7 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Senior IAM Security Engineer

Scopely is looking for a Senior IAM Security Engineer to join our Information Security team on a remote basis or hybrid basis if located in Barcelona. This role will focus on building, scaling, and securing Scopely’s identity and access management ecosystem across our cloud, SaaS, AI, and remote access environments, with a strong emphasis on Terraform-based IAM automation, access workflow engineering, least-privilege design, identity risk reduction, and AI-assisted operational workflows.

This is a highly technical, hands-on role for someone who can operate across AWS, GCP, Okta, AWS IAM Identity Center, Zero Trust access models, identity governance workflows, and modern AI-enabled engineering environments, while building scalable identity systems through Infrastructure as Code, workflow orchestration, and automation-first security engineering.

What You Will Do

Build and Evolve Modern IAM Architecture

Design and evolve Scopely’s IAM architecture to support a high-scale, cloud-first environment across AWS, GCP, SaaS applications, AI tooling, and remote access platforms. Lead initiatives around:

  • Federated identity architecture using SAML, OIDC, OAuth, and SCIM
  • Workforce identity and access patterns across internal platforms
  • Least-privilege role design and access segmentation
  • RBAC and ABAC models for cloud and SaaS environments
  • Centralized access models using Okta, AWS IAM Identity Center, Google Cloud IAM, and cloud-native IAM services
  • Secure cross-account and cross-project access patterns
  • Service account, workload identity, and non-human identity governance
  • Zero Trust identity and access control design Partner with engineering, infrastructure, and security teams to:
  • Standardize secure identity and access patterns
  • Reduce identity sprawl and excessive permissions
  • Improve access visibility and auditability
  • Build scalable identity controls for a fast-moving engineering environment

Own Terraform-Based IAM and Access Automation

Own and improve Terraform-based IAM and access automation across Scopely’s cloud and identity environment. Design, build, and maintain:

  • Reusable Terraform modules for IAM roles, policies, permission sets, group mappings, and access patterns
  • Terraform workflows for Okta app assignments, group-based access, and IAM Identity Center automation
  • Standardized access modules that can be reused safely across teams and environments
  • Policy-as-code patterns for least privilege and permission boundary enforcement
  • Terraform-driven onboarding and offboarding flows for identity-related systems
  • Automation for service account and workload identity provisioning
  • Access reporting and audit visibility pipelines connected to code-based IAM workflows Drive improvements in:
  • Standardization of IAM modules, variables, role definitions, and policy structures
  • Repeatability and consistency of access changes
  • Reduction of manual IAM operations
  • Auditability and change traceability
  • Safe rollout of identity changes through code review and pull request workflows Ensure mature Terraform engineering practices around:
  • State management
  • Drift detection and remediation
  • Rollback planning
  • Blast-radius awareness for IAM changes
  • Safe promotion of access changes into production

Automate Identity and Access Workflows

Build scalable automation for identity lifecycle management, access requests, entitlement changes, access reviews, and day-to-day IAM operations. Design and implement:

  • Provisioning and deprovisioning automation
  • Access request and approval workflows
  • Group-based access assignment and role mapping
  • Okta app integration and assignment automation
  • IAM Identity Center permission set automation
  • Self-service identity workflows for internal teams
  • Identity reporting and access visibility pipelines
  • Operational tooling that reduces repetitive IAM work Work with:
  • Terraform and Infrastructure as Code workflows
  • Python, Bash, PowerShell, and APIs
  • CI/CD systems and Git-based change management
  • Okta Workflows and similar orchestration tooling
  • ServiceNow, ticketing, and operational workflow integrations
  • AI tools such as Claude Code, Codex, and similar engineering assistants
  • MCP-enabled integrations, agentic workflows, and internal automation platforms Drive improvements in:
  • Repeatability
  • Auditability
  • Operational safety
  • Reduction of manual IAM work
  • Secure-by-default access onboarding

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Strengthen Identity Security and Risk Reduction

Lead initiatives to reduce identity-related risk across human and non-human identities. Design and implement controls for:

  • Excessive permissions and privilege escalation reduction
  • Service account and workload identity hardening
  • Long-lived credential reduction
  • Cross-account trust policy review and hardening
  • Permission boundary enforcement
  • Role lifecycle management
  • Just-in-time and time-bound privileged access
  • Break-glass access workflows
  • Identity anomaly detection and misuse investigation Use native and third-party tooling to identify and remediate risk, including:
  • AWS IAM Access Analyzer
  • CloudTrail
  • GuardDuty
  • GCP-native IAM and audit services
  • Okta System Log and access reporting
  • CIEM, CSPM, and related cloud security platforms

Improve Zero Trust and Privileged Access Security

Partner with IAM, platform, and security teams to strengthen Zero Trust and privileged access controls across Scopely’s environment. Support and enhance:

  • Twingate connectors, resources, and access policy design
  • Identity-aware remote access controls
  • Zero Trust segmentation for internal applications and privileged systems
  • Privileged access workflows
  • PAM platform integrations such as Britive
  • Adaptive access controls
  • MFA and passwordless adoption
  • Federated access into AWS, GCP, SaaS platforms, and internal tools
  • Secure vendor and contractor access patterns Drive improvements in:
  • Human identity security
  • Non-human identity security
  • Access visibility
  • Privileged session control
  • Access policy consistency across environments

Support Identity Investigations, Monitoring, and Audit Readiness

Partner with Security Operations, Compliance, and Infrastructure teams to improve identity monitoring, investigation, and audit readiness. Build and enhance:

  • IAM troubleshooting runbooks
  • Identity-related detection and triage workflows
  • Access review processes
  • Permission reporting and evidence collection
  • IAM logging and monitoring design
  • Operational metrics for identity security maturity Support investigations involving:
  • Suspicious access activity
  • Identity and permission abuse
  • Misconfigured app integrations
  • Broken federation and provisioning flows
  • Risky SaaS integrations
  • Service account misuse
  • Cross-account access issues Collaborate with compliance and audit stakeholders to ensure:
  • SOC 2 and ISO 27001 alignment
  • Access review evidence readiness
  • Documentation of IAM controls and workflows
  • Clear traceability for privileged access and entitlement changes

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Build AI-Assisted Identity Security Workflows

Design and improve AI-assisted and automation-first workflows that help Scopely scale identity security safely. Lead initiatives around:

  • AI-assisted access review analysis
  • AI-assisted troubleshooting and documentation support
  • Intelligent triage for identity-related findings
  • Security chatops integrations
  • Identity workflow automation using agents and orchestration systems
  • Internal copilots for IAM operations and knowledge support
  • AI-assisted recommendations for access hygiene and remediation
  • MCP-enabled identity tooling and integrations Work with:
  • Claude Code, Codex, and similar AI-assisted engineering tools
  • MCP-based workflows and agentic automation patterns
  • Internal automation platforms and workflow engines
  • APIs, event-driven automation, and identity telemetry pipelines Ensure safe adoption of AI by applying:
  • Human-in-the-loop approval controls
  • Least-privilege access to tools and data
  • Logging and auditability for AI-assisted workflows
  • Prompt and data handling safeguards
  • Clear separation between recommendations and privileged actions

Act as a Technical Leader

Partner with engineering, platform, IT, and studio teams to align IAM strategy with Scopely’s operational and business goals. Provide expert guidance on:

  • Modern IAM architecture
  • Federated identity design
  • Least-privilege engineering
  • Zero Trust access models
  • Non-human identity risk
  • IAM automation strategy
  • Terraform design patterns for identity and access management
  • Access governance in fast-growing environments
  • Secure access design for engineering teams
  • Safe use of AI in identity and access workflows Influence teams to:
  • Adopt secure identity patterns
  • Automate IAM safely
  • Reduce reliance on manual access processes
  • Improve cloud and SaaS access consistency
  • Build scalable and maintainable identity controls Raise the bar for:
  • Identity-aware security
  • Automation-first IAM operations
  • Practical access governance
  • Engineering-driven IAM design
  • AI-assisted identity operations

What We’re Looking For

Core Experience

8–12+ years in IAM security engineering, cloud security, identity architecture, or related security engineering roles Strong experience operating in cloud-first, high-scale environments Experience partnering directly with engineering, infrastructure, and security teams Experience designing and operating IAM solutions for global organizations with complex access needs Strong track record in identity modernization, least privilege, and access automation Proven experience building automation and reusable engineering patterns, not just handling manual IAM operations

Technical Skills

Cloud and Identity

Strong hands-on experience with:

  • AWS IAM, AWS Organizations, IAM Identity Center, SCPs, IAM roles and policies, CloudTrail, GuardDuty, IAM Access Analyzer, SSM
  • GCP IAM, service accounts, workload identity patterns, organization/folder/project models, and audit services
  • Okta administration including groups, rules, app integrations, assignments, lifecycle management, and troubleshooting
  • SAML, OIDC, OAuth, SCIM, and federated identity design
  • Cross-
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

London, England, United Kingdom

Sign up to applySee more jobs like this