Senior Security IAM Engineer (Madrid)

Senior Security IAM Engineer (Madrid)

26 sep
|
Scopely
|
Madrid

26 sep

Scopely

Madrid

Scopely is looking for a Senior IAM Security Enginee"r to join our Information Security team on a remote basis in Spain. This role will focus on building, scaling, and securing Scopely’s identity and access management ecosystem across our cloud, SaaS, AI, and remote access environments, with a strong emphasis on Terraform-based IAM automation, access workflow engineering, least-privilege design, identity risk reduction, and AI-assisted operational workflows.
This is a highly technical, hands‑on role for someone who can operate across AWS, GCP, Okta, AWS IAM Identity Center, Zero Trust access models, identity governance workflows, and modern AI-enabled engineering environments, while building scalable identity systems through Infrastructure as Code, workflow orchestration, and automation‑first security engineering.
What You Will Do
Build and Evolve Modern IAM Architecture
Design and evolve Scopely’s IAM architecture to support a high-scale, cloud-first environment across AWS, GCP, SaaS applications, AI tooling, and remote access platforms.
Lead initiatives around:
Federated identity architecture using SAML, OIDC, OAuth, and SCIMWorkforce identity and access patterns across internal platformsLeast-privilege role design and access segmentationRBAC and ABAC models for cloud and SaaS environmentsCentralized access models using Okta, AWS IAM Identity Center, Google Cloud IAM, and cloud-native IAM servicesSecure cross-account and cross-project access patternsService account, workload identity, and non-human identity governanceZero Trust identity and access control design
Partner with engineering, infrastructure, and security teams to:
Standardize secure identity and access patternsReduce identity sprawl and excessive permissionsImprove access visibility and auditabilityBuild scalable identity controls for a fast-moving engineering environment
Own Terraform-Based IAM and Access Automation
Own and improve Terraform-based IAM and access automation across Scopely’s cloud and identity environment.
Design, build, and maintain:
Reusable Terraform modules for IAM roles, policies, permission sets, group mappings, and access patternsTerraform workflows for Okta app assignments, group-based access, and IAM Identity Center automationStandardized access modules that can be reused safely across teams and environmentsPolicy-as-code patterns for least privilege and permission boundary enforcementTerraform-driven onboarding and offboarding flows for identity-related systemsAutomation for service account and workload identity provisioningAccess reporting and audit visibility pipelines connected to code-based IAM workflows
Drive improvements in:
Standardization of IAM modules, variables, role definitions, and policy structuresRepeatability and consistency of access changesReduction of manual IAM operationsAuditability and change traceabilitySafe rollout of identity changes through code review and pull request workflows
Ensure mature Terraform engineering practices around:
State managementDrift detection and remediationRollback planningBlast-radius awareness for IAM changesSafe promotion of access changes into production
Automate Identity and Access Workflows
Build scalable automation for identity lifecycle management, access requests, entitlement changes, access reviews, and day-to-day IAM operations.
Design and implement:
Provisioning and deprovisioning automationAccess request and approval workflowsGroup-based access assignment and role mappingOkta app integration and assignment automationIAM Identity Center permission set automationSelf-service identity workflows for internal teamsIdentity reporting and access visibility pipelinesOperational tooling that reduces repetitive IAM work
Work with:
Terraform and Infrastructure as Code workflowsPython, Bash, PowerShell, and APIsCI/CD systems and Git-based change managementOkta Workflows and similar orchestration toolingServiceNow, ticketing, and operational workflow integrationsAI tools such as Claude Code, Codex, and similar engineering assistantsMCP-enabled integrations, agentic workflows, and internal automation platforms
Drive improvements in:
RepeatabilityAuditabilityOperational safetyReduction of manual IAM workSecure-by-default access onboarding
Strengthen Identity Security and Risk Reduction
Lead initiatives to reduce identity-related risk across human and non-human identities.
Design and implement controls for:
Excessive permissions and privilege escalation reductionService account and workload identity hardeningLong-lived credential reductionCross-account trust policy review and hardeningPermission boundary enforcementRole lifecycle managementJust-in-time and time-bound privileged accessBreak‑glass access workflowsIdentity anomaly detection and misuse investigation
Use native and third‑party tooling to identify and remediate risk, including:
AWS IAM Access AnalyzerCloudTrailGuardDutyGCP‑native IAM and audit servicesOkta System Log and access reportingCIEM, CSPM, and related cloud security platforms
Improve Zero Trust and Privileged Access Security
Partner with IAM, platform, and security teams to strengthen Zero Trust and privileged access controls across Scopely’s environment.
Support and enhance:
Twingate connectors, resources, and access policy designIdentity‑aware remote access controlsZero Trust segmentation for internal applications and privileged systemsPrivileged access workflowsPAM platform integrations such as BritiveAdaptive access controlsMFA and passwordless adoptionFederated access into AWS, GCP,



SaaS platforms, and internal toolsSecure vendor and contractor access patterns
Drive improvements in:
Human identity securityNon‑human identity securityAccess visibilityPrivileged session controlAccess policy consistency across environments
Support Identity Investigations, Monitoring, and Audit Readiness
Partner with Security Operations, Compliance, and Infrastructure teams to improve identity monitoring, investigation, and audit readiness.
Build and enhance:
IAM troubleshooting runbooksIdentity-related detection and triage workflowsAccess review processesPermission reporting and evidence collectionIAM logging and monitoring designOperational metrics for identity security maturity
Support investigations involving:
Suspicious access activityIdentity and permission abuseMisconfigured app integrationsBroken federation and provisioning flowsRisky SaaS integrationsService account misuseCross‑account access issues
Collaborate with compliance and audit stakeholders to ensure:
SOC 2 and ISO 27001 alignmentAccess review evidence readinessDocumentation of IAM controls and workflowsClear traceability for privileged access and entitlement changes
Build AI‑Assisted Identity Security Workflows
Design and improve AI‑assisted and automation‑first workflows that help Scopely scale identity security safely.
Lead initiatives around:
AI‑assisted access review analysisAI‑assisted troubleshooting and documentation supportIntelligent triage for identity‑related findingsSecurity chatops integrationsIdentity workflow automation using agents and orchestration systemsInternal copilots for IAM operations and knowledge supportAI‑assisted recommendations for access hygiene and remediationMCP‑enabled identity tooling and integrations
Work with:
Claude Code, Codex, and similar AI‑assisted engineering toolsMCP‑based workflows and agentic automation patternsInternal automation platforms and workflow enginesAPIs, event‑driven automation, and identity telemetry pipelines
Ensure safe adoption of AI by applying:
Human‑in‑the‑loop approval controlsLeast‑privilege access to tools and dataLogging and auditability for AI‑assisted workflowsPrompt and data handling safeguardsClear separation between recommendations and privileged actions
Act as a Technical Leader
Partner with engineering, platform, IT, and studio teams to align IAM strategy with Scopely’s operational and business goals.
Provide expert guidance on:
Modern IAM architectureFederated identity designLeast‑privilege engineeringZero Trust access modelsNon‑human identity riskIAM automation strategyTerraform design patterns for identity and access managementAccess governance in fast‑growing environmentsSecure access design for engineering teamsSafe use of AI in identity and access workflows
Influence teams to:
Adopt secure identity patternsAutomate IAM safelyReduce reliance on manual access processesImprove cloud and SaaS access consistencyBuild scalable and maintainable identity controls
Raise the bar for:
Identity‑aware securityAutomation‑first IAM operationsPractical access governanceEngineering‑driven IAM designAI‑assisted identity operations
What We’re Looking For
Core Experience
8–12+ years in IAM security engineering, cloud security, identity architecture, or related security engineering rolesStrong experience operating in cloud‑first, high‑scale environmentsExperience partnering directly with engineering, infrastructure, and security teamsExperience designing and operating IAM solutions for general organizations with complex access needsStrong track record in identity modernization, least privilege, and access automationProven experience building automation and reusable engineering patterns, not just handling manual IAM operations
Technical Skills
Cloud and Identity
Strong hands‑on experience with:
AWS IAM, AWS Organizations, IAM Identity Center, SCPs, IAM roles and policies, CloudTrail, GuardDuty, IAM Access Analyzer, SSMGCP IAM, service accounts, workload identity patterns, organization/folder/project models, and audit servicesOkta administration including groups, rules, app integrations, assignments, lifecycle management, and troubleshootingSAML, OIDC, OAuth, SCIM, and federated identity designCross‑account and cross‑project access controlsService account and workload identity governanceTwingate administration or comparable ZTNA and remote access platforms, including connectors, resources, access policies, and policy troubleshooting
Infrastructure as Code and Automation
Strong hands‑on experience with:
Terraform‑based IAM and access automation in productionDesigning reusable Terraform modules for IAM roles, policies, permission sets, group mappings, and access patternsTerraform state management, drift detection, rollback planning, and safe deployment of IAM changesGit‑based workflows, pull requests, and code review for infrastructure and identity changesPython, Bash, PowerShell,



or similar scripting languagesAPI integrations and workflow automationProvisioning and deprovisioning automationAccess reporting and policy standardizationCI/CD integration for identity‑related workflows
Strong understanding of:
Policy‑as‑code and automation‑first IAMHow to convert manual IAM processes into reusable code‑driven workflowsHow to build transferable, scalable access patterns across teams and environmentsSafe production change practices for identity and access automation
AI and Emerging Technologies
Experience or strong interest in:
Claude Code, Codex, and similar AI‑assisted engineering toolsMCP integrations and agent‑based automation workflowsAI‑assisted detection, triage, remediation support, and documentationPrompt security, model safety, and human‑in‑the‑loop operational controlsEvaluating and safely operationalizing AI tooling in security environments
Security Expertise
Strong understanding of
Least privilege and role engineeringRBAC and ABAC designIdentity threat modelingPrivileged access and JIT access modelsIdentity lifecycle managementNon‑human identity risk reductionIdentity logging and monitoringAccess reviews and audit readinessSecurity controls for SaaS and cloud identity systems
Aptitudes
Builder mindset - creates scalable IAM systems, not one‑off fixesAutomation‑first mentality - reduces manual effort through safe automationSystems thinker - connects IAM, cloud, SaaS, developer workflows, and operational riskAI‑forward mindset - embraces intelligent automation while applying practical security guardrailsPragmatic and engineering‑oriented - balances security with usability and speedHigh ownership - operates effectively in complex, fast‑moving environmentsStrong communicator - able to explain IAM risks and solutions to engineers, IT, and leadership
Bonus Points
Experience with Britive, CyberArk, SailPoint, or similar PAM/PIM platformsExperience with Okta Workflows, CIEM platforms, or identity governance toolingExperience with Wiz, GuardDuty, Astrix, or similar tools for identity‑related investigationsExperience in gaming, SaaS, or multi‑studio environmentsExperience with passwordless authentication, WebAuthn, or FIDO2Experience building AI‑assisted workflows for IAM operations, documentation, access reviews, or investigationsFamiliarity with AI security frameworks, governance, and safe agentic automation patternsSecurity certifications such as CISSP, AWS Security Specialty, or relevant IAM/cloud certifications
This role is ideal for someone who is excited about building modern identity security beyond traditional approaches and wants to help Scopely scale secure access across cloud, SaaS, AI, and engineering environments. If you enjoy solving IAM challenges with Terraform, automation, reusable engineering patterns, and well‑designed identity systems, we’d love to hear from you.
About Scopely
Scopely is a leading video game and global interactive entertainment company, home to many of the world’s most beloved and enduring experiences, including two of the most successful mobile games of all‑time “MONOPOLY GO!” and “Pokémon GO,” along with “Stumble Guys,” “Star TrekTM Fleet Command,” “MARVEL Strike Force,” “WWE Champions,” the Scrabble® franchise, “Yahtzee® With Buddies,” and many others. Across mobile, web, PC, and console, Scopely creates, develops, publishes, and live‑operates one of the most diversified and award‑winning portfolios in the games industry — bringing hundreds of millions of players together through a shared love of play.
Founded in 2011, Scopely is powered by its exceptional team — including thousands of world‑class gamemakers around the globe, a distinctive tenet‑driven culture, and its proprietary technology platform, Playgami. Together, these strengths have fueled Scopely’s position as the #1 mobile games company in the U.S. and #2 globally, generating more than $10 billion in lifetime revenue. Whether building global sensations like “MONOPOLY GO!” from the ground up, or expanding through strategic acquisitions, including the FoxNext, GSN, and Scopely Explore games businesses — Scopely consistently delivers experiences players love today and return to for years to come.
Recognized multiple times as one of the "100 Most Influential Companies in the World" by TIME magazine and one of Fast Company’s "World's Most Innovative Companies" and “Best Workplaces for Innovators,” Scopely believes that video games can be a force for good — creating meaningful connections, vibrant communities, and making life better through play.
Scopely has global operations and partners across four continents in more than a dozen countries worldwide. For more information, visit: https://www.scopely.com/
Notice to Candidates
Scopely will never request payment or financial information during the application or hiring process.
Should you have any questions or encounter any fraudulent requests/emails/websites, please immediately contact [email protected]. Our job applicant privacy policies are available here: California Privacy Notice and EEA/UK Privacy Notice.
Employment at Scopely is based solely on a person's merit and qualifications. Scopely does not discriminate against any employee or applicant because of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), or any other basis protected by law. We also consider qualified applicants with arrest or conviction records, consistent with applicable federal, state and local law.
#J-18808-Ljbffr

📌 Senior Security IAM Engineer (Madrid)
🏢 Scopely
📍 Madrid

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: senior security iam engineer (madrid) / madrid

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: senior security iam engineer (madrid) / madrid