[Remote] Senior AWS Identity & Security Engineer – SRE / Cloud Security
Auto ImportNote: The job is a remote job and is open to candidates in USA. ICONMA, an IT Services and Consulting company, is seeking a Senior AWS Identity & Security Engineer focused on SRE and Cloud Security. The role will design and implement AWS identity, authorization, cross-account observability, infrastructure automation, and high-performance APIs at enterprise scale, while documenting and enabling client teams.
Responsibilities
- Identity & Entitlements: Integrate the API layer with AWS IAM Identity Center (IdC) and build a policy engine to enforce data boundaries (SRE vs. App Team vs. Business Unit). This includes integrating Omni into the client’s existing identityfederation model — an established custom credentialvending / SAML broker on the primary landing zone plus existing IdC adoption for console access
- CrossAccount Data Routing: Implement and automate links to aggregate logs, metrics, and traces across multiple AWS Organizations
- EndtoEnd Feature Delivery: Build, test, and deploy features from the AWS infrastructure layer (CloudWatch / Omni / IAM) up through the API layer that serves the UI, using CloudWatch crossaccount capabilities. May include writing highperformance APIs (in Go, Python, or Java) to query CloudWatch, CloudTrail, and flow logs, and implementing efficient caching strategies
- Infrastructure as Code (IaC): Automate the deployment of all resources using Terraform or AWS CDK, leveraging AWS CloudFormation StackSets to deploy source links to 15,000 accounts
- Enablement: Produce clear architecture and integration documentation and enable the client’s teams to operate and extend the Omni identity and routing model, working as an embedded SME alongside the client’s SRE and observability leadership
Skills
- Advanced. Identity & Security (Primary) AWS IAM Identity Center (IdC), SAML/OIDC federation, and integration with an existing enterprise federation / credentialvending model
- Advanced. Attributebased access control (ABAC) and finegrained authorization engines such as AWS Verified Permissions or Open Policy Agent (OPA)
- Advanced. AWS Organizations, CloudFormation StackSets, and Orglevel APIs and policies. Able to automate resource provisioning at a scale of 15,000 accounts
- Proficient. Python, Java, or Go. Building highperformance REST/API services to query CloudWatch, CloudTrail, and flow logs, with efficient caching strategies and asynchronous data fetching
- Advanced. CloudWatch (Metrics, Logs, Alarms, Contributor Insights), CloudWatch crossaccount observability / OAM (sink and source configuration), CloudTrail, and flow logs
- Advanced. Terraform or AWS CDK, with CI/CD pipelines (e.g. GitLab CI) for automated infrastructure deployment
- 12.00 Years of Experience
Benefits
- Health Benefits
- Referral Program
- Excellent growth and advancement opportunities
- Remote work arrangement
Company Overview
Company H1B Sponsorship