{"id":2068908,"url":"https://alion.io/job/scopely-senior-security-iam-engineer-2","title":"Senior Security IAM Engineer","company":{"id":953,"name":"Scopely","domain":"scopely.com","url":"https://alion.io/company/scopely","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":{"grade":"B","score":78,"open_postings":16,"ghost_share":0,"stale_share":0.688,"repost_share":0,"time_to_fill_p50_days":61,"computed_at":"2026-10-09T06:01:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["London, United Kingdom"],"countries":["GB"],"hiring_countries":["GB"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":92000,"max_usd":171000,"period":"year","method":"role_seniority_country_cell","sample_n":36},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Agentic Workflows","optional":false},{"name":"AI Agents","optional":false},{"name":"Anomaly Detection","optional":false},{"name":"AWS","optional":false},{"name":"CI/CD","optional":false},{"name":"Claude Code","optional":false},{"name":"GCP","optional":false},{"name":"Git","optional":false},{"name":"Human-in-the-Loop","optional":false},{"name":"IAM","optional":false},{"name":"ISO 27001","optional":false},{"name":"Least Privilege","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"Model Context Protocol","optional":false},{"name":"Okta","optional":false},{"name":"OpenAI Codex","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"ServiceNow","optional":false},{"name":"SOC 2","optional":false},{"name":"State Management","optional":false},{"name":"Terraform","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Twingate","optional":false},{"name":"Zero Trust","optional":false},{"name":"CyberArk","optional":true},{"name":"Wiz","optional":true}],"status":"live","first_seen_at":"2026-10-08T03:11:16Z","employer_posted_date":"2026-10-08","last_verified_at":"2026-10-10T00:32:51Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"Scopely is looking for a Senior IAM Security Enginee r to join our Information Security team on a remote basis or hybrid basis if located in Barcelona. This role will focus on building, scaling, and securing Scopely’s identity and access management ecosystem across our cloud, SaaS, AI, and remote access environments, with a strong emphasis on Terraform-based IAM automation, access workflow engineering, least-privilege design, identity risk reduction, and AI-assisted operational workflows.\nThis is a highly technical, hands-on role for someone who can operate across AWS, GCP, Okta, AWS IAM Identity Center, Zero Trust access models, identity governance workflows, and modern AI-enabled engineering environments, while building scalable identity systems through Infrastructure as Code, workflow orchestration, and automation-first security engineering.\nWhat You Will Do\nBuild and Evolve Modern IAM Architecture\nDesign and evolve Scopely’s IAM architecture to support a high-scale, cloud-first environment across AWS, GCP, SaaS applications, AI tooling, and remote access platforms.\nLead initiatives around:\nFederated identity architecture using SAML, OIDC, OAuth, and SCIM\nWorkforce identity and access patterns across internal platforms\nLeast-privilege role design and access segmentation\nRBAC and ABAC models for cloud and SaaS environments\nCentralized access models using Okta, AWS IAM Identity Center, Google Cloud IAM, and cloud-native IAM services\nSecure cross-account and cross-project access patterns\nService account, workload identity, and non-human identity governance\nZero Trust identity and access control design\nPartner with engineering, infrastructure, and security teams to:\nStandardize secure identity and access patterns\nReduce identity sprawl and excessive permissions\nImprove access visibility and auditability\nBuild scalable identity controls for a fast-moving engineering environment\nOwn Terraform-Based IAM and Access Automation\nOwn and improve Terraform-based IAM and access automation across Scopely’s cloud and identity environment.\nDesign, build, and maintain:\nReusable Terraform modules for IAM roles, policies, permission sets, group mappings, and access patterns\nTerraform workflows for Okta app assignments, group-based access, and IAM Identity Center automation\nStandardized access modules that can be reused safely across teams and environments\nPolicy-as-code patterns for least privilege and permission boundary enforcement\nTerraform-driven onboarding and offboarding flows for identity-related systems\nAutomation for service account and workload identity provisioning\nAccess reporting and audit visibility pipelines connected to code-based IAM workflows\nDrive improvements in:\nStandardization of IAM modules, variables, role definitions, and policy structures\nRepeatability and consistency of access changes\nReduction of manual IAM operations\nAuditability and change traceability\nSafe rollout of identity changes through code review and pull request workflows\nEnsure mature Terraform engineering practices around:\nState management\nDrift detection and remediation\nRollback planning\nBlast-radius awareness for IAM changes\nSafe promotion of access changes into production\nAutomate Identity and Access Workflows\nBuild scalable automation for identity lifecycle management, access requests, entitlement changes, access reviews, and day-to-day IAM operations.\nDesign and implement:\nProvisioning and deprovisioning automation\nAccess request and approval workflows\nGroup-based access assignment and role mapping\nOkta app integration and assignment automation\nIAM Identity Center permission set automation\nSelf-service identity workflows for internal teams\nIdentity reporting and access visibility pipelines\nOperational tooling that reduces repetitive IAM work\nWork with:\nTerraform and Infrastructure as Code workflows\nPython, Bash, PowerShell, and APIs\nCI/CD systems and Git-based change management\nOkta Workflows and similar orchestration tooling\nServiceNow, ticketing, and operational workflow integrations\nAI tools such as Claude Code, Codex, and similar engineering assistants\nMCP-enabled integrations, agentic workflows, and internal automation platforms\nDrive improvements in:\nRepeatability\nAuditability\nOperational safety\nReduction of manual IAM work\nSecure-by-default access onboarding\nStrengthen Identity Security and Risk Reduction\nLead initiatives to reduce identity-related risk across human and non-human identities.\nDesign and implement controls for:\nExcessive permissions and privilege escalation reduction\nService account and workload identity hardening\nLong-lived credential reduction\nCross-account trust policy review and hardening\nPermission boundary enforcement\nRole lifecycle management\nJust-in-time and time-bound privileged access\nBreak-glass access workflows\nIdentity anomaly detection and misuse investigation\nUse native and third-party tooling to identify and remediate risk, including:\nAWS IAM Access Analyzer\nCloudTrail\nGuardDuty\nGCP-native IAM and audit services\nOkta System Log and access reporting\nCIEM, CSPM, and related cloud security platforms\nImprove Zero Trust and Privileged Access Security\nPartner with IAM, platform, and security teams to strengthen Zero Trust and privileged access controls across Scopely’s environment.\nSupport and enhance:\nTwingate connectors, resources, and access policy design\nIdentity-aware remote access controls\nZero Trust segmentation for internal applications and privileged systems\nPrivileged access workflows\nPAM platform integrations such as Britive\nAdaptive access controls\nMFA and passwordless adoption\nFederated access into AWS, GCP, SaaS platforms, and internal tools\nSecure vendor and contractor access patterns\nDrive improvements in:\nHuman identity security\nNon-human identity security\nAccess visibility\nPrivileged session control\nAccess policy consistency across environments\nSupport Identity Investigations, Monitoring, and Audit Readiness\nPartner with Security Operations, Compliance, and Infrastructure teams to improve identity monitoring, investigation, and audit readiness.\nBuild and enhance:\nIAM troubleshooting runbooks\nIdentity-related detection and triage workflows\nAccess review processes\nPermission reporting and evidence collection\nIAM logging and monitoring design\nOperational metrics for identity security maturity\nSupport investigations involving:\nSuspicious access activity\nIdentity and permission abuse\nMisconfigured app integrations\nBroken federation and provisioning flows\nRisky SaaS integrations\nService account misuse\nCross-account access issues\nCollaborate with compliance and audit stakeholders to ensure:\nSOC 2 and ISO 27001 alignment\nAccess review evidence readiness\nDocumentation of IAM controls and workflows\nClear traceability for privileged access and entitlement changes\nBuild AI-Assisted Identity Security Workflows\nDesign and improve AI-assisted and automation-first workflows that help Scopely scale identity security safely.\nLead initiatives around:\nAI-assisted access review analysis\nAI-assisted troubleshooting and documentation support\nIntelligent triage for identity-related findings\nSecurity chatops integrations\nIdentity workflow automation using agents and orchestration systems\nInternal copilots for IAM operations and knowledge support\nAI-assisted recommendations for access hygiene and remediation\nMCP-enabled identity tooling and integrations\nWork with:\nClaude Code, Codex, and similar AI-assisted engineering tools\nMCP-based workflows and agentic automation patterns\nInternal automation platforms and workflow engines\nAPIs, event-driven automation, and identity telemetry pipelines\nEnsure safe adoption of AI by applying:\nHuman-in-the-loop approval controls\nLeast-privilege access to tools and data\nLogging and auditability for AI-assisted workflows\nPrompt and data handling safeguards\nClear separation between recommendations and privileged actions\nAct as a Technical Leader\nPartner with engineering, platform, IT, and studio teams to align IAM strategy with Scopely’s operational and business goals.\nProvide expert guidance on:\nModern IAM architecture\nFederated identity design\nLeast-privilege engineering\nZero Trust access models\nNon-human identity risk\nIAM automation strategy\nTerraform design patterns for identity and access management\nAccess governance in fast-growing environments\nSecure access design for engineering teams\nSafe use of AI in identity and access workflows\nInfluence teams to:\nAdopt secure identity patterns\nAutomate IAM safely\nReduce reliance on manual access processes\nImprove cloud and SaaS access consistency\nBuild scalable and maintainable identity controls\nRaise the bar for:\nIdentity-aware security\nAutomation-first IAM operations\nPractical access governance\nEngineering-driven IAM design\nAI-assisted identity operations\nWhat We’re Looking For\nCore Experience\n8-12+ years in IAM security engineering, cloud security, identity architecture, or related security engineering roles\nStrong experience operating in cloud-first, high-scale environments\nExperience partnering directly with engineering, infrastructure, and security teams\nExperience designing and operating IAM solutions for global organizations with complex access needs\nStrong track record in identity modernization, least privilege, and access automation\nProven experience building automation and reusable engineering patterns, not just handling manual IAM operations\nTechnical Skills\nCloud and Identity\nStrong hands-on experience with:\nAWS IAM, AWS Organizations, IAM Identity Center, SCPs, IAM roles and policies, CloudTrail, GuardDuty, IAM Access Analyzer, SSM\nGCP IAM, service accounts, workload identity patterns, organization/folder/project models, and audit services\nOkta administration including groups, rules, app integrations, assignments, lifecycle management, and troubleshooting\nSAML, OIDC, OAuth, SCIM, and federated identity design\nCross-account and cross-project access controls\nService account and workload identity governance\nTwingate administration or comparable ZTNA and remote access platforms, including connectors, resources, access policies, and policy troubleshooting\nInfrastructure as Code and Automation\nStrong hands-on experience with:\nTerraform-based IAM and access automation in production\nDesigning reusable Terraform modules for IAM roles, policies, permission sets, group mappings, and access patterns\nTerraform state management, drift detection, rollback planning, and safe deployment of IAM changes\nGit-based workflows, pull requests, and code review for infrastructure and identity changes\nPython, Bash, PowerShell, or similar scripting languages\nAPI integrations and workflow automation\nProvisioning and deprovisioning automation\nAccess reporting and policy standardization\nCI/CD integration for identity-related workflows\nStrong understanding of:\nPolicy-as-code and automation-first IAM\nHow to convert manual IAM processes into reusable code-driven workflows\nHow to build transferable, scalable access patterns across teams and environments\nSafe production change practices for identity and access automation\nAI and Emerging Technologies\nExperience or strong interest in:\nClaude Code, Codex, and similar AI-assisted engineering tools\nMCP integrations and agent-based automation workflows\nAI-assisted detection, triage, remediation support, and documentation\nPrompt security, model safety, and human-in-the-loop operational controls\nEvaluating and safely operationalizing AI tooling in security environments\nSecurity Expertise\nStrong understanding of\nLeast privilege and role engineering\nRBAC and ABAC design\nIdentity threat modeling\nPrivileged access and JIT access models\nIdentity lifecycle management\nNon-human identity risk reduction\nIdentity logging and monitoring\nAccess reviews and audit readiness\nSecurity controls for SaaS and cloud identity systems\nAptitudes\nBuilder mindset - creates scalable IAM systems, not one-off fixes\nAutomation-first mentality - reduces manual effort through safe automation\nSystems...","description_format":"text","description_chars":16470,"description_truncated":true,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"phd","optional":false},"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false}]},"benefits":[],"hiring_locations":[{"name":"United Kingdom","iso":"GB","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Gaming"],"lifecycle":[{"event":"open","at":"2026-10-08T05:21:22Z"}],"visa":[{"country":"GB","licensed_sponsor":true,"evidence":"Licensed UK visa sponsor (Senior or Specialist Worker, Skilled Worker)","filings_12m":null,"filings_prev_12m":null,"green_card_filings_12m":null,"median_offered_wage_usd":null,"route":"Global Business Mobility: Senior or Specialist Worker; Skilled Worker","cap_exempt":false,"checked_at":"2026-10-08T06:20:15+00:00","sources":["UK Home Office: register of licensed sponsors (workers)"],"filings_for_role_12m":0}],"liveness":{"score":70,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.695,"p_room":1,"age_days":1,"expected_fill_days":61,"reasons":["conf:0","stale_co","wave","velocity","win:early","comp:brand"],"computed_at":"2026-10-09T06:01:00Z"},"pay":null,"html_url":"https://alion.io/job/scopely-senior-security-iam-engineer-2","json_url":"https://alion.io/job/scopely-senior-security-iam-engineer-2.json","meta":{"generated_at":"2026-10-10T01:50:14Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3274,"day_limit":5000,"remaining_today":1726,"minute_limit":60,"resets_at":"2026-10-11T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":953},"rest":"https://alion.io/mcp/rest/get_company?id=953"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fscopely-senior-security-iam-engineer-2"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fscopely-senior-security-iam-engineer-2"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fscopely-senior-security-iam-engineer-2"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/scopely-senior-security-iam-engineer-2\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fscopely-senior-security-iam-engineer-2"}]}