Why you should join dLocal
dLocal enables the biggest companies in the world to collect payments in 40 countries in emerging markets. Global brands rely on us to increase conversion rates and simplify payment expansion effortlessly. As both a payments processor and a merchant of record where we operate, we make it possible for our merchants to make inroads into the world’s fastest-growing, emerging markets.
By joining us you will be a part of an amazing global team that makes it all happen. Being a part of dLocal means working with 1000+ teammates from 30+ different nationalities and developing an international career that impacts millions of people’s daily lives. We are builders, we never run from a challenge, we are customer‑centric, and if this sounds like you, we know you will thrive in our team.
Senior Security Engineer – Identity & Access
We are not building a traditional, bureaucratic identity and access management function. We are building a modern, highly automated identity security program—and we need a sharp, relentless operator to build it.
Identity is the new perimeter, and managing how our general workforce accesses enterprise systems is one of our highest priorities.
We are looking for a Senior Security Engineer – Identity & Access to help drive our identity evolution alongside our existing senior engineering team. Your mandate is to take that complex web of legacy entitlements and build a highly scalable, automated identity governance machine.
This is not an “ivory tower” strategy role. We do not need someone to draw Visio diagrams and hand them off to junior admins. We need a pragmatic, high‑agency builder who helps design the strategy but has the zero‑ego grit to execute it with their own hands.
Responsibilities
- Engineer the Identity Lifecycle (JML & SoD):
Take on our workforce identity and access ecosystem. Build a highly automated Joiner‑Mover‑Leaver (JML) machine, implementing robust access certifications, Separation of Duties (SoD), and unified IGA frameworks that scale with our hyper‑growth.
- Federation, Zero Trust & Integration: Design and scale our authentication and authorization foundations across cloud, SaaS, and on‑premise environments. Lead identity federation leveraging SAML, OAuth2, OpenID Connect, and SCIM, while driving the adoption of Zero Trust architecture and Adaptive MFA across the enterprise.
- M&A; & Enterprise Transformation: Lead the identity integration strategy for mergers, acquisitions, and massive enterprise transformation initiatives, securely and seamlessly folding new organizations into our identity ecosystem.
- Zero‑Ego Execution: As a senior technical anchor on the team, lead by example. Configure integrations, write RBAC policies, engineer the IGA platforms, and untangle access flows yourself.
- Codify Governance & Shift Left: Design self‑service identity workflows, automated controls, and identity KPIs that force business leaders to explicitly own and accept their access risks. Translate written compliance policies into code.
- Be the IAM Diplomat: When you change how developers and commercial teams authenticate, there is always friction. Act as a key face of our identity transformation,
negotiating with engineering directors and enforcing security without alienating them.
- Resilient Problem Solver: Navigate messy legacy setups and solve long‑standing identity problems using the latest technologies and original thinking.
- Track Record Over Tenure: Demonstrate outcomes through proven design, building, or scaling of Identity and Access programs in fast‑paced, complex environments.
- Deep IGA & Protocol Expertise: Hands‑on experience with modern workforce identity systems, lifecycle processes, protocols, RBAC/ABAC models, and enterprise identity platforms such as SailPoint, Saviynt, and Okta.
- Pragmatic Operator Mindset: Balance strict least‑privilege security with high usability for the business.
- Disciplined Multi‑Threading: Manage an enterprise identity strategy while simultaneously troubleshooting immediate access escalations.
- Force Multiplier: Mentor engineers, provide leadership, and document solutions so systems are scalable, well‑understood, and maintainable.
Qualifications
- Experience navigating the identity and access requirements of highly regulated environments (PCI‑DSS, SOX, SOC 2).
- Familiarity with machine identity governance, secrets management, and API access.
- Relevant industry certifications demonstrating dedication to the identity domain.
Benefits
- Flexibility: Flexible schedules and performance‑driven focus.
- Fintech industry: Dynamic environment with plenty to build and boost creativity.
- Referral bonus program: Reward for referring ideal candidates.
- Social budget: Monthly budget to spend with your team (in‑person or remote).
- dLocal Houses: Opportunity to rent a house and cowork with your team anywhere in the world.
#J-18808-Ljbffr
📌 Senior Security Engineer – Identity & Access (Madrid)
🏢 dLocal
📍 Madrid