Security Platform Engineer-IAM
Listed on 2026-07-31
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing: Infrastructure & Operations, Information Security & Data Protection
Why Stifel
Stifel strives for a culture that puts its clients and associates first: a culture where everyone belongs, everyone is welcome, and everyone contributes to the success of our clients, their careers, and the firm as a whole.
Let’s talk about how you can find your place here at Stifel,
where success meets success
.
Under general supervision, the Security Platform Engineer-IAM is a front-line member of the Identity and Access Management (IAM) team that has responsibility for supporting and evolving enterprise identity, access, and workload identity platforms. The Security Platform Engineer-IAM is responsible for engineering, automation, integration and operational support across cloud permissions, identity governance, privileged access, directory services, SSO/MFA, secrets management, and non-human identity controls.
WhatWe're Looking For
- Contribute to the strategy, design, and management of the enterprise IAM program.
- Design, build, and support identity platform capabilities across cloud, hybrid, and enterprise environments.
- Manage and automate AWS IAM permissions, roles, policies, service accounts, workload identities, and access patterns.
- Develop and maintain Terraform modules, IaC pipelines, and Git Ops-based deployment workflows for identity infrastructure.
- Collaborate across teams and business lines to improve IAM solutions, enhance compliance requirements, and Firm best practices.
- Build automation using Power Shell, Python, Terraform, APIs, and CI/CD tooling.
- Support secrets management platforms and patterns, including credential rotation, vault integrations, machine identity, and secure secret consumption.
- Engineer and govern non-human identities, including service accounts, workload identities, application identities, API credentials, and cloud-native identities.
- Build and develop systems and processes to enforce least privilege in a transparent way.
- Partner with security, infrastructure, cloud, Dev Ops, and application teams to implement secure access patterns.
- Engineer technical configuration changes to deployed solutions.
- Develop documentation to support ongoing IAM systems operations, maintenance and specific problem resolution.
- Strong engineering experience in identity, cloud security, infrastructure automation, or access management.
- Hands-on experience with AWSIAM, including roles, policies, permission boundaries, identity federation, service control policy, service-linked roles, and least-privilege design.
- Strong experience with Terraform for infrastructure automation and identity platform configuration.
- Demonstrated understanding of directory services principles.
- Strong scripting skills for automation, administration, reporting, and operational support (Power Shell, Python, Terraform).
- Proven experience designing, deploying, and supporting Identity and Access management platforms and projects.
- Experience with Git Ops, source control workflows, pull requests, CI/CD pipelines, and controlled deployment practices.
- Experience with secretsmanagement, credential lifecycle management, vaulting patterns, and secure application authentication.
- Understanding of a broad range of IT disciplines that would impact overall security posture.
- Familiarity with non-humanidentity, workload identity, service account governance, machine identity, or application identity security.
- Experience with Microsoft
EntraID, including enterprise applications, app registrations, conditional access concepts, SSO, OAuth, MFA, and identity federation. - Experience with Identity Data Management solutions.
- Knowledge of cloud security frameworks, least privilege, Zero Trust, and identity-first security principles.
- Experience building reusable Terraform modules and policy-as-code controls.
- Minimum
Required:
Bachelor's degree in computer science, information systems, cybersecurity, or a related field, or equivalent experience. - Minimum
Required:
4+ years experience in an Information Technology or Information Security role.
- Minimum
Required:
None.
- Proficient with Azure and/or AWS security and engineering.
- Experience with Secrets Management platforms.
- Exp…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).