Skip to main content

Senior Cybersecurity Engineer, Identity and Access Management (IAM)

On-siteFull timeSenior

Belgrade, Belgrade, Serbia · Posted 10 hr. ago

Role Summary

Rivian is seeking a Senior Cybersecurity Engineer, Identity and Access Management (IAM) to help design, build, and improve the identity systems and controls that protect Rivian's people, applications, infrastructure, and data. This is a hands-on IAM engineering role for someone who brings identity depth, strong delivery habits, and the ability to own moderately complex IAM work from design throughvalidation and operational support.You will help deliver reliable, auditable IAM services across Microsoft Entra ID, Conditional Access, privileged access management, credential vaulting, identity governance, and lifecycle workflows. The work includes reducing fragile manual processes, improving operational readiness, and leaving behind patterns that make the next similar change easier and safer.Primary charter: deliver senior IAM ownership across priority identity areas, improving reliability, control quality, automation, and operational supportability while supporting Rivian's move toward a stronger Zero Trust access posture.Location: Belgrade, Serbia (onsite/hybrid at a Rivian location; remote is not available). Participation in an incident on-call rotation is required.

Responsibilities

● IAM Ownership: Design and deliver improvements across priority IAM areas, with current emphasis on Microsoft Entra ID, Conditional Access, privileged access management, non-human identity, PKI/secrets, and identity governance.● Privileged Access and Non-Human Identity: Strengthen privileged access management, vaulted credentials, service accounts, workload identities, and secrets through clearer ownership and safer controls.● Identity Governance and Lifecycle: Improve IAM workflows such as access requests, approvals, reviews, provisioning, deprovisioning, ownership tracking, and evidence generation.● Automation: Improve repeatable IAM workflows through maintainable scripts, jobs, APIs, CLIs, Microsoft Graph integrations, safer change patterns, and clearer handoffs.● Service Evolution: Evolve IAM services with monitoring, runbooks, incident response, and fixes that reduce recurring failure modes. Participation in an incident on-call rotation is required.● Collaboration: Work with HR, IT, Enterprise Security, SOC, application owners, and infrastructure partners to make identity controls practical, supportable, and aligned to business needs.

Qualifications

● Experience: 5+ years in identity and access management, cybersecurity engineering, identity platform engineering, or equivalent practical experience.● Identity Platforms: Hands-on experience with Microsoft Entra ID, Microsoft Graph, and Conditional Access in an enterprise environment, with working knowledge of Zero Trust, time-bound access, just-in-time access, step-up authentication, and phishing-resistant methods such as FIDO2/WebAuthn, passkeys, or certificate-based authentication.● IAM Domain Depth: Hands-on ownership across multiple IAM domains, with strength in areas such as privileged access management, non-human identity, PKI, secret management (vaulting, rotation), SSO/federation (SAML, OAuth, OpenID), entitlement/access reviews, or lifecycle (J/M/L) and provisioning (SCIM). Familiarity with Active Directory, Group Policy, and authentication protocols (LDAP, Kerberos, NTLM) is valued.● Automation: Proven ability to build or improve scripts, jobs, workflow logic, or lightweight automation using tools such as Python, PowerShell, Go, or equivalent.● Delivery Practices: Comfortable delivering IAM changes through Git-based change, peer review, validation, documentation, and rollback or recovery planning.● AI-Assisted Engineering: Experience using AI-assisted or AI-accelerated tools in real development, documentation, automation, or operational work.● Operations: Experience supporting production or business-critical systems through monitoring, troubleshooting, incident response, and continuous improvement.● Communication: Clear written and verbal communication; effective in reviews, operational handoffs, and cross-team coordination.

Bonus Points

● Privileged Access at Scale: Experience with privileged access management at scale, Entra ID Governance, BeyondTrust, privileged session management, RBAC/ABAC, credential vaulting, endpoint password management, Entra ID Governance, entitlement models, or equivalent access-control patterns.● Non-Human Identity and Secrets: Experience with enterprise secrets management, internal PKI, vault-backed credential handling, X.509/mTLS, KMS/HSM, or secrets-management tooling such as HashiCorp Vault or equivalent.● Platform and Cloud Delivery: Experience with CI/CD, infrastructure as code (Terraform, CloudFormation), AWS or equivalent cloud platforms, GitOps, observability, or supportable internal tooling.● Software-Engineering Depth: Experience raising automation quality through testing, versioning, packaging, reusable modules, or maintainable internal tools.● Agentic Workflows: Experience using or shaping AI-agent workflows that go beyond individual prompting, especially for development, automation, documentation, or operations.● Active Directory Modernization: Experience with Active Directory hardening, migration, deprovisioning, decommissioning, or modernization work that reduces legacy identity risk.

Locations
Belgrade, Belgrade, Serbia
Education
bachelor degree
Experience
5+ years

Categories

Skills