Principal Cloud Iam Engineer (us Federal)

Workday Workday · Enterprise · USA.VA.Reston

Workday is seeking a Principal Cloud IAM Engineer to manage entitlements and permissions in a cloud services environment (AWS, Azure/EntraID or GCP) for US Federal Government contracts. The role involves automating identity administration, authentication, and authorization, using infrastructure and compliance as code, and integrating with standard federation protocols. Experience with CI/CD pipelines, SEIM tools, and NIST 800-53 is required.

What you'd actually do

  1. managing entitlements and permissions in a cloud services environment (AWS, Azure/EntraID or GCP)
  2. automate identity administration, authentication and authorization to resources in the air-gapped network
  3. understand infrastructure and compliance as code, using CI/CD pipelines
  4. integrating cloud platforms with external tools like Okta, EntraID or similar for centralized authentication and SSO
  5. utilizing one or more SEIM tools (Splunk or similar) for log aggregation and analysis, threat playbooks and auditing

Skills

Required

  • cloud engineer
  • IAM
  • centralizing authentication/authorization and RBAC/PBAC
  • infrastructure as code
  • Github
  • Terraform
  • automation in Python
  • integrating cloud platforms with external tools like Okta, EntraID or similar for centralized authentication and SSO
  • SEIM tools (Splunk or similar) for log aggregation and analysis, threat playbooks and auditing
  • NIST 800-53
  • DoD/Intel control frameworks
  • identity governance workflows
  • user lifecycle management

Nice to have

  • active TS/SCI w/CI Poly
  • Bachelor's degree or higher in computer science, cybersecurity, or comparable work/educational experience

What the JD emphasized

  • United States citizens
  • security clearance at the TS/SCI w/CI Poly level
  • 8+ years as a cloud engineer, focused on IAM