Rivianvw.Tech logo
Posted 4h agoBelgrade • Remote

Identity & Access Management Engineer

MiddleRemote~€5,000 – €6,700 / mo
Required Skills
Identity and Access ManagementSAMLOIDCSCIMPythonSQLCloud Identity Platform
Job Description

About Us

Rivian and Volkswagen Group Technologies is a joint venture between two industry leaders with a clear vision for automotive’s next chapter. From operating systems to zonal controllers to cloud and connectivity solutions, we’re addressing the challenges of electric vehicles through technology that will set the standards for software-defined vehicles around the world.

The road to the future is uncharted. By combining our expertise across connectivity, AI, security and more, we’ll map a new way forward. Working together, we’ll create a future that’s more connected, more intelligent, more sustainable for everyone.

Role Summary

RV Tech runs its enterprise workforce identity on a modern cloud identity platform. The IAM Engineer keeps that platform running well and makes it better every quarter. You will own the day-to-day operation of the cybersecurity identity platform — lifecycle workflows, application integrations, access policies, and identity-related incidents — and you will be the engineer who turns manual access processes into automated, auditable ones. You work closely with the IAM Architect, who owns the identity roadmap and architecture; you own execution, operational health, and continuous improvement.

This is a hands-on role on a small team with real ownership of a production identity platform.

Responsibilities

Cybersecurity Identity Operations (core)

  • Operate and administer the enterprise identity platform tenant: policy tuning, group and rule management, MFA and adaptive access configuration, and tenant hygiene.

  • Onboard and maintain SSO integrations (SAML/OIDC) and SCIM provisioning for the enterprise application portfolio; own the application integration backlog.

  • Build and maintain joiner/mover/leaver automation with identity workflow tooling and HR-driven provisioning; investigate and resolve lifecycle failures.

  • Provide L2 and L3 support for identity-related Helpdesk tickets (access issues, SSO/MFA failures, provisioning errors); resolve within SLA, drive root cause and permanent fixes, and feed recurring issues back into automation and runbooks.

  • Support operational and cybersecurity incidents involving identity: account compromise, suspicious authentication activity, privilege misuse, and outage response — including containment actions (session revocation, credential resets, access suspension) and post-incident evidence.

  • Monitor identity platform system logs and operational health; define alerts for authentication anomalies, policy drift, and integration failures.

  • Support stabilization and optimization of the identity platform, including retirement of legacy identity dependencies.

Access Governance

  • Support quarterly user access reviews (UARs) end to end: generate review populations, coordinate with application and manager reviewers, track completion, remediate revocations, and produce audit-ready access review records.

  • Support governance of non-human identities — service accounts, service principals, API credentials — including discovery, ownership attestation, rotation, and decommissioning.

  • Detect and remediate excessive privileges and risky permission combinations.

  • Maintain identity control evidence for the ISO 27001 / TISAX control environment; keep runbooks and integration documentation current in Confluence.

Automation & Continuous Improvement

  • Identify manual IAM processes and automate them using identity workflow tooling, Python/SQL, and APIs.

  • Contribute to identity automation and governance tooling on the enterprise data platform: attribute-driven provisioning, automated deprovisioning, and identity event pipelines into the SIEM.

  • Propose and implement improvements to identity controls aligned to the zero-trust roadmap (device assurance, passwordless/FIDO2, conditional access).

Qualifications

Minimum Qualifications:

  • Bachelor's degree in Computer Science, Information Security, Information Systems, or a related technical field (required).

  • 3–6 years in identity and access management engineering or administration, with 1+ years hands-on operating a cloud identity platform in production.

  • Experience with major identity platforms, including Okta, Microsoft Entra ID, Ping Identity, or comparable workforce IdPs.

  • Working knowledge of SAML, OIDC, OAuth 2.0, SCIM, and directory services (Entra ID/Active Directory) in hybrid enterprise environments.

  • Experience building or maintaining lifecycle automation (joiner/mover/leaver) with an HR system of record.

  • Scripting ability in Python or PowerShell and comfort working with REST APIs and SQL.

  • Strong troubleshooting discipline: able to trace an access failure across HRIS, IdP, and target application and document the fix.

  • Clear written English; able to produce runbooks and audit evidence that a non-engineer can follow.

  • Ability to work an overlap of at least 3–4 hours with Pacific Time and to travel to Palo Alto once or twice per year.

Preferred Qualifications

  • Vendor certification on a major identity platform (e.g., Okta Certified Professional/Administrator, Microsoft Identity and Access Administrator).

  • Experience with identity workflow automation and IGA platforms.

  • Experience with PAM tooling and enterprise password managers.

  • Exposure to Databricks, Spark, or similar data platforms for event ingestion and processing.

  • SIEM integration experience for identity signals.

  • Experience in a TISAX, ISO 27001, or NIST-regulated environment; automotive or joint-venture context a plus.

Total Rewards

We build the exceptional — and we believe the people doing that work should be rewarded accordingly. In addition to a competitive base salary, full-time positions may be is eligible to participate in our annual company performance bonus program.

Payments are discretionary and not guaranteed; actual amounts depend on company results and the terms of the plan in effect, and require active employment at the time of payout. This role is also eligible for equity in the form of Restricted Stock Units (RSUs), subject to board approval and the terms of our equity incentive plans, including applicable vesting requirements.

In addition to our compensation programs, we invest in our people with a comprehensive benefits package designed to support the health, wellbeing, and financial future for full-time employees — including health coverage, retirement savings, time off, and family planning programs. Offerings vary by country. Learn more about our global benefit programs.

External candidates can apply for this role through the Rivian and Volkswagen Group Technologies careers site (https://rivianvw.tech/#careers). If you are a current employee, please apply through our internal job board.

Equal Opportunity

Rivian and Volkswagen Group Technologies is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender, gender expression, gender identity, genetic information or characteristics, physical or mental disability, marital/domestic partner status, age, military/veteran status, medical condition, or any other characteristic protected by law. We are also committed to ensuring compliance with all applicable fair employment practice laws regarding citizenship and immigration status.

Rivian and Volkswagen Group Technologies is committed to ensuring that our hiring process is accessible for persons with disabilities. If you have a disability or limitation, such as those covered by the Americans with Disabilities Act, that requires accommodations to assist you in the search and application process, please email us at [email protected].

Candidate Data Privacy

Rivian and Volkswagen Group Technologies” may collect, use and disclose your personal information or personal data (within the meaning of the applicable data protection laws) when you apply for employment and/or participate in our recruitment processes (“Candidate Personal Data”). This data includes contact, demographic, communications, educational, professional, employment, social media/website, network/device, recruiting system usage/interaction, security and preference information. Rivian and Volkswagen Group Technologies may use your Candidate Personal Data for the purposes of (i) tracking interactions with our recruiting system; (ii) carrying out, analyzing and improving our application and recruitment process, including assessing you and your application and conducting employment, background and reference checks; (iii) establishing an employment relationship or entering into an employment contract with you; (iv) complying with our legal, regulatory and corporate governance obligations; (v) record keeping; (vi) ensuring network and information security and preventing fraud; and (vii) as otherwise required or permitted by applicable law.

Rivian and Volkswagen Group Technologies may share your Candidate Personal Data with (i) internal personnel who have a need to know such information in order to perform their duties, including individuals on our People Team, Finance, Legal, and the team(s) with the position(s) for which you are applying; (ii) Rivian and Volkswagen Group Technologies affiliates; and (iii) Rivian and Volkswagen Group Technologies’ service providers, including providers of background checks, staffing services, and cloud services.

Rivian and Volkswagen Group Technologies may transfer or store internationally your Candidate Personal Data, including to or in the United States, Canada, and the European Union and in the cloud, and this data may be subject to the laws and accessible to the courts, law enforcement and national security authorities of such jurisdictions.

If you provide a mobile telephone number as part of your application or during the recruitment process, Rivian and Volkswagen Group Technologies may use that number to contact you via SMS text message for recruitment-related purposes, including scheduling, logistics, and status updates. Message and data rates may apply. You may opt out of SMS communications at any time by replying STOP to any text message you receive from us. Consent to receive SMS messages is not a condition of applying for or being considered for employment.

Please see our Candidate Data Privacy Notice (English) and Candidate Data Privacy Notice (Serbian) for more information.

--

Please note this job posting represents an open, active vacancy. Additionally, we are not currently accepting applications from third party application services.

Ready to apply? Optimize your CV for this specific jobAI customizes your experience bullets and increases chances to get hired.

Similar Openings in Backend

View all in category