Senior Cloud Iam Engineer (us Federal)

Workday Workday · Enterprise · USA.VA.Reston

Senior Cloud IAM Engineer role at Workday, focusing on managing identity, entitlements, and permissions in a US Federal air-gapped cloud environment (AWS, Azure/EntraID, GCP). The role involves automating identity administration, authentication, and authorization using infrastructure and compliance as code, CI/CD pipelines, and standard federation protocols (OAUTH, OIDC, SAML, SCIM). Experience with SEIM tools, NIST 800-53, and DoD/Intel control frameworks is required. Requires US citizenship and potential on-site presence in the DMV area.

What you'd actually do

  1. managing entitlements and permissions in a cloud services environment (AWS, Azure/EntraID or GCP)
  2. automate identity administration, authentication and authorization to resources in the air-gapped network
  3. understand infrastructure and compliance as code, using CI/CD pipelines
  4. work with other teams in cloud engineering and the broader Cybersecurity organization
  5. support one or more direct or indirect contracts with the U.S. Federal Government

Skills

Required

  • managing entitlements and permissions in a cloud services environment (AWS, Azure/EntraID or GCP)
  • automating identity administration, authentication and authorization
  • infrastructure as code
  • compliance as code
  • CI/CD pipelines
  • OAUTH, OIDC, SAML and SCIM
  • Python or other programming languages
  • integrating cloud platforms with external tools like Okta, EntraID or similar for centralized authentication and SSO
  • utilizing one or more SEIM tools (Splunk or similar) for log aggregation and analysis, threat playbooks and auditing
  • NIST 800-53 and DoD/Intel control frameworks
  • identity governance workflows
  • user lifecycle management (joiners, movers, leavers)

Nice to have

  • active TS/SCI w/CI Poly

What the JD emphasized

  • United States citizens
  • security clearance at the TS/SCI w/CI Poly level
  • 5+ years as a cloud engineer, focused on IAM
  • NIST 800-53 and DoD/Intel control frameworks