Rivian logo
RivianPosted 25 months ago

Senior Cybersecurity Engineer, Identity DevOps and Platform Automation

On-siteBelgrade, Central Serbia, Serbia

Full TimeSenior LevelEnterprise

Job Summary

Design and deliver improvements to IAM platform components emphasizing Microsoft Entra ID, Microsoft Graph, and tenant governance. Build and operate IAM automation, services, CLIs, and APIs through Git-based change, CI/CD, and infrastructure as code on AWS. Improve identity governance and lifecycle workflows including access requests, provisioning, and deprovisioning. Support application onboarding via SAML, OIDC, and SCIM while converting manual patterns into reusable automation. Enhance observability, alerting, and drift detection to support diagnosis and operational readiness. Execute controlled platform changes through design review, peer review, staged rollout, and rollback planning. Participate in an incident on-call rotation. Collaborate with HR, IT, Enterprise Security, SOC, and application owners to align controls with business needs.

Required Qualifications

  • 5+ years in IAM, identity platform engineering, IAM automation, cybersecurity engineering, platform delivery, or equivalent practical experience
  • Hands-on experience with Microsoft Entra ID and Microsoft Graph in enterprise identity environments, including tenant governance, enterprise applications, service principals, directory and tenant configuration, and Conditional Access policies
  • Ability to build maintainable IAM automation, APIs, CLIs, workflows, or lightweight services using Python, PowerShell, Go, or equivalent
  • Delivery through Git, CI/CD, infrastructure as code (Terraform, CloudFormation) on AWS or equivalent cloud platforms using serverless, container, or event-driven patterns
  • Practical familiarity with adjacent IAM areas such as lifecycle, governance (RBAC/ABAC), SSO/federation (SAML, OAuth, OpenID Connect), provisioning (SCIM), privileged access, non-human identity, PKI/secrets (X.509), or Zero Trust access patterns
  • Experience using AI-assisted or AI-accelerated tools in real development, documentation, automation, or operational work
  • Experience supporting production or business-critical systems through monitoring, troubleshooting, validation, incident response, recovery planning, and continuous improvement
  • Clear written and verbal communication; effective in design reviews, handoffs, peer review, and cross-team coordination
  • Participation in an incident on-call rotation

Desired Qualifications

  • Experience building governed self-service, reusable automation, Microsoft Graph-driven workflows (including change notifications/webhooks), platform drift detection, policy-as-code (e.g., OPA/Rego), tenant hygiene automation, or enterprise application governance tooling
  • Experience operating serverless (AWS Lambda, Azure Functions), container-based (Kubernetes, ECS), scheduled, or event-driven (EventBridge, SQS/SNS) workloads in AWS or equivalent cloud platforms with observability (metrics/logs/tracing, e.g., OpenTelemetry), alerting, runbooks, and incident response
  • Experience raising automation quality through testing, versioning, packaging, reusable modules, typed interfaces, structured logging, configuration-driven behavior, or maintainable internal tools
  • Experience with workload identities and service principals, workload identity federation (OIDC-based) and the OAuth client-credentials flow, automation accounts, credential hygiene, secrets management, mTLS/X.509, vault-backed credential handling, or internal PKI patterns

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce