AWS IAM/Platform Engineer
- AWS IAM
- AWS
- IAM
- Python
- IaC
- Terraform
- AWS Lambda
- RBAC
- GuardDuty
- CloudTrail
- Step Functions
- Amazon EventBridge
- Git
- CI/CD
- CloudFormation
- Devops
- AWS CDK
- GitOps
- AWS Security Specialty
AWS IAM / Platform Engineer
Location: Raleigh, NC β Hybrid preferred / Remote optional for the right candidate
Experience: 15+ Years
Job Summary
We are seeking an experienced AWS IAM / Platform Engineer with strong expertise in AWS identity, access management, security governance, and automation. The ideal candidate will have hands-on experience designing and managing AWS IAM and IAM Identity Center solutions across enterprise multi-account environments, along with strong Python and Infrastructure-as-Code skills.
Top 3 Required Skills
-
AWS IAM / IAM Identity Center (SSO) / Identity Governance
-
Terraform / Python Automation / AWS Lambda
-
AWS Organizations / RBAC / Access Management
Key Responsibilities
-
Design, implement, and manage AWS IAM and IAM Identity Center solutions across enterprise multi-account AWS environments.
-
Develop and manage IAM policies, permission boundaries, trust relationships, RBAC, permission sets, and least-privilege access models.
-
Manage AWS Organizations governance, including SCPs, RCPs, tag policies, backup policies, guardrails, and account lifecycle controls.
-
Configure and support AWS Control Tower, AWS Config, GuardDuty, CloudTrail, and Security Hub for governance and security posture monitoring.
-
Build event-driven automation using Python, Lambda, Step Functions, EventBridge, Boto3, APIs, and reusable operational components.
-
Implement governance-as-code and IAM automation through Git, CI/CD pipelines, CloudFormation, CDK, or Terraform.
-
Develop automated validation processes for IAM policies, permission sets, and governance configurations.
-
Design and implement cross-account access and permission boundary strategies.
-
Support compliance monitoring and automated remediation using AWS security and governance services.
-
Develop reusable automation frameworks for identity and access management.
-
Collaborate with security, cloud infrastructure, DevOps, and application teams to implement scalable AWS solutions.
-
Troubleshoot complex IAM, access, governance, and automation issues.
-
Maintain version-controlled IAM policies, permission sets, and governance configurations.
Required Qualifications
-
15+ years of overall IT experience with strong AWS platform and security experience.
-
Deep expertise in AWS IAM and IAM Identity Center.
-
Strong understanding of AWS Organizations, Control Tower, IAM policy language, policy evaluation logic, cross-account access, and permission boundaries.
-
Strong experience with RBAC, identity governance, access management, and least-privilege security models.
-
Hands-on experience with AWS Config, GuardDuty, CloudTrail, Security Hub, compliance monitoring, and remediation automation.
-
Strong Python development skills.
-
Hands-on experience with AWS Lambda, Step Functions, EventBridge, Boto3, and APIs.
-
Experience with Git-based source control and CI/CD pipelines.
-
Experience with CloudFormation, AWS CDK, or Terraform.
-
Strong understanding of AWS security and governance best practices.
-
Excellent problem-solving and troubleshooting skills.
Preferred Qualifications
-
Experience implementing enterprise AWS Landing Zones.
-
Experience with AWS account vending, onboarding, and governance automation across AWS Organizations.
-
Hands-on experience managing IAM Identity Center permission sets and account assignments.
-
Experience automating IAM Identity Center through CI/CD pipelines.
-
Familiarity with Terraform, CloudFormation, AWS CDK, and GitOps approaches.
-
Knowledge of compliance frameworks and identity governance patterns.
-
Preferred AWS certifications:
-
AWS Solutions Architect β Associate/Professional
-
AWS Security Specialty
-
AWS DevOps Engineer β Professional
-
Soft Skills
-
Strong analytical and problem-solving abilities.
-
Ability to work independently and take ownership of technical initiatives.
-
Strong stakeholder communication skills.
-
Ability to translate security and governance requirements into scalable AWS solutions.
-
Strong collaboration skills across security, infrastructure, DevOps, and application teams.
-
Ability to manage multiple priorities in an enterprise environment.
AWS IAM/Platform Engineer Β· Apolis