SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Scopely, a leading video game and interactive entertainment company (home to MONOPOLY GO!, Pokémon GO, Stumble Guys, and others), is seeking a Senior Security IAM Engineer to join its Information Security team on a remote basis in Spain.
This is a highly technical, hands-on role focused on building, scaling, and securing Scopely's identity and access management ecosystem across cloud (AWS, GCP), SaaS, AI, and remote access environments. You will drive initiatives around federated identity architecture (SAML, OIDC, OAuth, SCIM), workforce identity patterns, least-privilege role design, RBAC/ABAC models, centralized access management (Okta, AWS IAM Identity Center, Google Cloud IAM), Zero Trust identity design, and service account/workload identity governance.
Key responsibilities include:
**IAM Architecture & Design**: Design and evolve Scopely's IAM architecture to support high-scale, cloud-first environments. Lead initiatives around federated identity, least-privilege access segmentation, centralized access models, secure cross-account/cross-project patterns, and Zero Trust design. Partner with engineering, infrastructure, and security teams to standardize secure identity patterns, reduce identity sprawl, improve access visibility, and build scalable controls for fast-moving engineering environments.
**Terraform-Based IAM Automation**: Own and improve Terraform-based IAM and access automation. Design, build, and maintain reusable Terraform modules for IAM roles, policies, permission sets, group mappings, and access patterns. Create Terraform workflows for Okta app assignments, group-based access, and IAM Identity Center automation. Implement policy-as-code patterns, Terraform-driven onboarding/offboarding flows, service account provisioning automation, and access reporting pipelines. Ensure mature Terraform engineering practices around state management, drift detection, rollback planning, and safe production promotion.
**Identity & Access Workflow Automation**: Build scalable automation for identity lifecycle management, access requests, entitlement changes, and access reviews. Design and implement provisioning/deprovisioning automation, access request/approval workflows, group-based access assignment, Okta app integration automation, IAM Identity Center permission set automation, self-service identity workflows, and identity reporting pipelines. Work with Terraform, Python, Bash, PowerShell, APIs, CI/CD systems, Okta Workflows, ServiceNow integrations, and AI tools (Claude Code, Codex). Drive improvements in repeatability, auditability, operational safety, and reduction of manual IAM work.
**Identity Security & Risk Reduction**: Lead initiatives to reduce identity-related risk across human and non-human identities. Design and implement controls for excessive permissions reduction, service account/workload identity hardening, long-lived credential reduction, cross-account trust policy hardening, permission boundary enforcement, role lifecycle management, just-in-time/time-bound privileged access, break-glass workflows, and identity anomaly detection. Use native and third-party tooling including AWS IAM Access Analyzer, CloudTrail, GuardDuty, GCP-native services, Okta System Log, CIEM, and CSPM platforms.
**Zero Trust & Privileged Access**: Partner with IAM, platform, and security teams to strengthen Zero Trust and privileged access controls. Support and enhance Twingate connectors/resources, identity-aware remote access controls, Zero Trust segmentation, privileged access workflows, PAM platform integrations (Britive), adaptive access controls, MFA/passwordless adoption, and federated access into AWS, GCP, SaaS, and internal tools.
**Identity Monitoring, Investigation & Audit**: Partner with Security Operations, Compliance, and Infrastructure teams to improve identity monitoring, investigation, and audit readiness. Build IAM troubleshooting runbooks, identity-related detection/triage workflows, access review processes, permission reporting, IAM logging/monitoring design, and operational metrics. Support investigations involving suspicious access activity, identity/permission abuse, misconfigured app integrations, broken federation flows, risky SaaS integrations, service account misuse, and cross-account access issues. Collaborate with compliance/audit stakeholders to ensure SOC 2 and ISO 27001 alignment, access review evidence readiness, and clear traceability for privileged access changes.
**AI-Assisted Identity Security Workflows**: Design and improve AI-assisted and automation-first workflows to help Scopely scale identity security safely. Lead initiatives around AI-assisted access review analysis, troubleshooting support, intelligent triage for identity findings, security chatops integrations, identity workflow automation using agents/orchestration systems, internal copilots for IAM operations, AI-assisted access hygiene recommendations, and MCP-enabled identity tooling. Work with Claude Code, Codex, MCP-based workflows, agentic automation patterns, internal automation platforms, APIs, and event-driven automation. Ensure safe AI adoption through human-in-the-loop approvals and responsible AI practices.
**Requirements**: The posting indicates this is a senior-level role requiring deep expertise in IAM, cloud security (AWS/GCP), Okta, Terraform, and modern identity architecture. Candidates should have demonstrated experience with federated identity protocols, Zero Trust design, infrastructure-as-code practices, identity automation, and cloud security tooling. Experience with Python/Bash scripting, CI/CD workflows, and identity governance platforms is expected. Familiarity with AI-assisted engineering tools and modern security practices is valued.