Unknown Company

Senior IAM Automation Engineer

austin, tx • Posted 1 weeks ago
Hybrid Contract General

Senior IAM Automation EngineerWe're seeking a Senior IAM Automation Engineer to transform how Apex manages workforce identity and access management. This role combines DevOps/SRE practices with deep IAM expertise to eliminate manual, UI-based processes and build self-service, API-driven solutions that scale across our hybrid and multi-cloud environment. As a senior technical contributor, you'll also mentor junior team members and help elevate the team's overall automation and engineering capabilities.You'll focus on workforce identity (employees, contractors, partners) while collaborating with our CIAM team who handles customer-facing identity services.

As a technical leader, you'll drive the implementation of Tines as our strategic automation platform, develop infrastructure-as-code for identity systems, and architect integrations that enable the business to move fast without compromising security.As IAM evolves with AI adoption, you'll help lead our response to emerging non-human identity (NHI) challenges, partnering with SecOps to develop governance for AI agents, service accounts, and machine identities. You'll also leverage AI tools effectively and responsibly in your daily work to accelerate automation development and problem-solving.This role requires someone who can write production code, architect distributed systems, and translate business requirements into automated solutions, not just configure IAM platforms.What You'll DoBuild infrastructure-as-code for identity systems - Develop and maintain Terraform, PowerShell, and Python automation across our hybrid infrastructure (on-prem AD/Adaxes, Entra ID, Okta, AWS IAM, GCP/GCI) to enable repeatable, version-controlled deployments with proper change management.Design API-driven automation and integrations - Architect scalable solutions that orchestrate identity workflows across HRIS (Workday), ticketing (ServiceNow), collaboration platforms (Slack, Teams, M365), and enterprise applications, leveraging APIs and SDKs to eliminate manual processes.Implement observability and self-healing capabilities - Build monitoring, alerting, and automated remediation for identity systems to reduce operational toil, improve reliability, and enable proactive issue detection across authentication flows and provisioning processes.Enable rapid application onboarding - Create automation frameworks and integration patterns that allow the business to onboard new SaaS applications with minimal manual intervention while maintaining security and compliance standards.Pioneer non-human identity (NHI) governance - Partner with SecOps to develop policies, controls, and automation for managing AI agents, LLM API keys, service accounts, bot identities, and machine-to-machine authentication as AI adoption accelerates across the organization.Mentor and develop junior team members - Share your hard-won experience and technical expertise to elevate the team's capabilities. Conduct code reviews, pair programming sessions, and knowledge transfer that builds automation skills, IAM expertise, and engineering judgment across the team.Drive technical innovation in the identity space - Evaluate emerging tools and practices, establish CI/CD pipelines for IAM deployments, and leverage AI-powered development tools (LLMs, code generation, AI assistants) responsibly to accelerate automation delivery and stay ahead of business needs.Required Skills & ExperienceTechnical ExpertiseSoftware development proficiency - 5+ years writing production code (Python, PowerShell, Go, or similar) with strong API and SDK integration experienceIAM architecture skills - Deep understanding of SSO protocols (SAML, OIDC), provisioning standards (SCIM), directory services (Active Directory, Entra ID), and enterprise IAM platforms (Okta strongly preferred)Infrastructure-as-Code mastery - Hands-on experience with Terraform, Ansible, or similar tools, plus CI/CD pipelines for automated deploymentsDevOps/SRE practices - Experience building observable, reliable systems with appropriate monitoring, logging, and incident response capabilitiesWorkflow automation platforms - Demonstrated ability to implement and govern low-code/code-first automation tools (Tines, Workato, n8n, or similar)Platform ExperienceDemonstrated hands-on experience with the following:Enterprise SSO and IAM (Okta, Entra ID/Azure AD)Directory services and management (Active Directory, Adaxes)Cloud IAM (AWS IAM, GCP Cloud Identity)Workflow automation (Tines preferred, or similar platforms)Integrations with HRIS systems (Workday, BambooHR, ADP)Engineering MindsetProblem-solving ability - Experience debugging complex distributed systems, analyzing API integrations, and optimizing automated workflowsPragmatic engineering - Balance between perfect and done; build iteratively with continuous improvementAI-augmented productivity - Comfortable leveraging AI tools (LLMs, code assistants, AI pair programming) responsibly to accelerate development while maintaining code quality and securityForward-thinking security - Interest in emerging IAM challenges like non-human identities, AI agent governance, and machine identity managementMentorship and knowledge sharing - Genuine interest in developing junior engineers through code reviews, pairing, and transferring hard-won lessons from production experienceTechnical communication - Document architecture decisions, create operational runbooks, and explain technical concepts to business stakeholdersEmployee experience focus - Understand that internal users are customers; design automation that enables productivity without frictionQualificationsRequired:7-10+ years in DevOps, SRE, or software engineering roles with significant IAM/identity automation focusDemonstrated experience building automation solutions for enterprise IAM platforms using APIs, scripting, and infrastructure-as-codeTrack record of implementing workflow automation or orchestration platforms in production environmentsUnderstanding of both technical IAM implementations and business processes (joiner/mover/leaver, access requests, compliance)Experience working in hybrid on-premises and cloud environmentsPreferred:Experience with Tines or similar low-code automation platformsBackground bridging Corporate IT and Engineering teamsHRIS integration experience, especially with WorkdayFamiliarity with compliance requirements (SOC1/2, audit trails, access certifications)Interest or experience in Non-Human Identity managementDemonstrated use of AI tools to enhance productivity in automation or infrastructure workActive contributions to IAM automation communities or open-source projectsEducation:Bachelor's degree in Computer Science, Software Engineering, or related field; degree requirement may be substituted with equivalent years of technical experienceWhat Success Looks LikeWithin your first year, you'll have:Established Tines as the automation platform for workforce identity with documented standards and governanceReduced employee onboarding time and access provisioning through automated workflowsImplemented infrastructure-as-code for critical IAM systems with version control and CI/CD pipelinesBuilt self-service capabilities that significantly reduce help desk ticket volumeCreated observability dashboards and automated access certification processesPartnered with SecOps to establish initial NHI governance frameworks for AI agents and service accountsDemonstrated effective and responsible use of AI tools to accelerate automation developmentElevated the team's technical capabilities through mentorship and knowledge sharing, enabling greater autonomy and engineering maturityDeveloped strong partnerships with HR, Enterprise Apps, and cross-functional teamsPositioned workforce IAM as a technical enabler rather than a bottleneck

Back to Job Search