Job Title: Senior Security Engineer (IAM / ICAM)
Location:
MedellÃn, Colombia
Experience:
5+ years
Language:
Fluent English required
Role Overview
We are looking for a hands-on Senior Security Engineer with strong experience in Identity and Access Management (IAM) and Identity, Credential, and Access Management (ICAM). This role will focus on designing, implementing, and supporting secure identity architectures across enterprise environments. The ideal candidate will have experience with authentication, authorization, identity governance, access controls, and security best practices in cloud and hybrid environments.
Key Responsibilities
Design, implement, and maintain enterprise IAM and ICAM solutions.
Manage identity lifecycle processes including provisioning, deprovisioning, role-based access control, and privileged access management.
Support authentication technologies such as SSO, MFA, federation, and directory services.
Partner with infrastructure, cloud, application, and security teams to integrate identity controls into enterprise platforms.
Monitor access-related security risks, policy violations, and compliance requirements.
Conduct access reviews, entitlement audits, and remediation activities.
Develop automation for identity workflows, access governance, and policy enforcement.
Support incident response and investigations related to identity and access security.
Requirements
5+ years of experience in cybersecurity, IAM, or security engineering roles.
Strong knowledge of IAM and ICAM concepts, identity governance, and access control models.
Hands-on experience with SSO, MFA, federation, LDAP, Active Directory, and privileged access management.
Experience with cloud identity platforms in
Amazon Web Services
,
Microsoft Azure
, or
Google Cloud
.
Good understanding of security frameworks, governance, compliance, and audit requirements.
Scripting or automation experience using Python, PowerShell, or similar tools.
Strong troubleshooting, communication, and stakeholder management skills.
Fluent English communication is required.
Preferred
Experience with platforms such as
Okta
,
Ping Identity
,
CyberArk
, or
SailPoint
.
Security certifications such as CISSP, Security+, or vendor-specific IAM certifications.