EU
Cloud Engineer with IAM/Entra Specialty (Senior Level)
eTeam UK
đşđ¸ United States
On-site
Senior
7 months ago
- AWS
- AWS Cloud
- Agile
- IAM
- Entra
- SAML
- SCIM
- Conditional Access
- Graph API
- AWS IAM
- DevSecOps
- GitHub
- IaC
- Terraform
- Python
- Bash
- PowerShell
- CloudTrail
- GitHub Actions
- Microsoft Graph
- CloudFormation
7 months ago
Ărsted has signed a contract with AWS. The new contract will fuel our cloud acceleration, strengthen our growth with cloud-based technologies, and help Ărsted stay competitive by driving innovation and cost efficiency.
Long-term, competitive solution to support Ărstedâs growing needs for global infrastructure
Ărsted has in late 2022 completed a tender for cloud infrastructure and services. As we grow our global footprint, we increasingly need to move computing from our own data centres into the cloud. The tender aimed to secure a long-term, competitive cloud supplier to support Ărstedâs growing needs for global infrastructure.
We see the AWS cloud is a catalyst for agility and growth. Ărsted is becoming an increasingly digital company. We need contemporary and scalable infrastructure to support the company on its growth journey towards becoming the number one renewable energy major. By moving from our own data centres and into the cloud globally, we can scale our infrastructure across geographies as and when we need it. Cloud technologies fuel our digitalisation. Ărsted has adopted agile ways of working, so itâs vital that we provide a comprehensive foundation of technical building blocks for developers, analysts, and engineers to deliver the tools they need. This is now enabled by compliant and innovative cloud technologies.
Over the past five years, Ărsted has increased its use of cloud-based technologies and provided the foundation for faster development of applications. Weâve ensured scalability on a range of platforms, all of them cloud-based. The new contract wonât replace those platforms but is a significant addition, first and foremost targeted at reducing the need for our own data centres in the future. The ambition of the programme is to migrate a significant part of the on-premise based applications into AWS as we modernize while we migration â focusing on self-service and easing up operations
The core of the migration is an internal team owning the platform and driving the ambitions â it is a key element for Ărsted to anchor ownership internally. The externals we are looking for are bringing in knowledge and experience so we both scale and speed up our deliveries.
Job Description :
We are looking for a Cloud Engineer with IAM and Entra specialty to automate and scale our AWS Platform. This role focuses heavily on abstraction of IAM complexities toward fully automated, self-service IAM "products" for our internal developers.
Key Responsibilities :
- Federated Access via Entra Id identity provider
- Maintain, and Automate deployment of a solution for Entra Id integration with AWS Identity Center
- Configuration and Maintenance of Entra Id Enterprise App for AWS (Certificate/Secret renewals, SAML assertion, API Permissions, and SCIM provisioning)
- Troubleshoot Entra Id Conditional Access Policies
- Access and Entitlement Management
- Maintain, and Automate deployment of AWS Account Access at scale via the use of AWS Identity Center permission sets and existing AWS Account Vending/Factory.
- Maintain and Automate provisioning of Entra Id Entitlement Management Access Catalogs and Access Packages via Entra Id Graph API/SDK
- Maintain and Automate provisioning of Entra Id PIM Groups, via Entra Id Graph API/SDK
- Internal IAM Self-Service "Products"
- Develop, Maintain, and Automate solutions for providing tailor made "IAM Products", for example to help our internal customers get Entra Id groups created with proper compliance and security configured (e.g Access Reviews, Approval flows)
- General AWS IAM
- Configuration of AWS IAM roles, trust and permission policies (Managed, Customer Managed, and Inline)
- Right Sizing of AWS IAM roles, using AWS Access Analyzer, and similar tools.
- General DevSecOps
- Develop and Maintenance of Github Action workflows for the above areas, using combination of inhouse actions, IaC(Terraform), and scripts (python, bash, powershell depending on the use case)
- Refactor existing IAM Github Action workflows and related IaC to support Policy-as-Code enforcements
- Develop and Maintain integration and acceptance tests and test reports for new & existing IAM code base.
- Assist in Data Driven decisions based upon e.g AWS CloudTrail, Entra Audit and other types of logs and analytic capabilities, to effectively evaluate impact/effect of code changes.
- General Incidents and Support
- Respond and resolve incidents related to IAM, continuously improving our solution to prevent repeat incidents.
- Provide support and guidance for enquiries from our developers, as well as internal customers.
- Access and Entitlement Management
Location:
Warsaw - Poland
The consultant is expected to conduct work from the specified location mentioned in the requisition. They are mandated to support Orstedâs offices for a minimum of two days per week. Fully r emote work is not allowed unless prior agreement with Orstedâs hiring manager. These rules could be modified in the future at Orstedâs discretion.
Remote work in a different country than the one listed in the requisition as âlocationâ is NOT allowed, unless expressly agreed and approved by Orsted Services Procurement, and may cause immediate termination of the WO.
- Requirements :
Skills/Qualifications:
- Advanced proficiency in AWS IAM and/or Microsoft Entra ID.
- Proficiency in Infrastructure as Code, especially Terraform and experience with GitHub Actions.
- Proficiency in Python, Bash and PowerShell.
- Strong programming skills with the ability to interface with the Microsoft Graph API.
- Experience with AWS Service Catalog and AWS CloudFormation
- Certification e.g. Microsoft Identity and Access Administrator (SC-300) will be an advantage.
- Detail-oriented, clear communication, and analytical skills will be essential to succeed in this role.
- Background check required before onboarding of the consultant.
All CVs for Ărsted must be in English. The CV attachment must also be uploaded as a Word file and no logos or supplier branding are allowed. Magnit is vendor neutral and the CV requirements are supposed to ensure the neutrality towards the customer. CVs that donât follow the required formatting will not be considered for submission.
Cloud Engineer with IAM/Entra Specialty (Senior Level) ¡ eTeam UK