Principal Cloud Iam Engineer

Workday

Reston, VA, USA
Base: $184,800 - $277,200 usd (reston); base: $167...
Fully remote
10+ years cloud security or iam experience
Aws iam foundations scps multi-account architecture
Okta enterprise scale sso adaptive mfa scim
This role involves owning the strategy, design, and long-term direction of the IAM program for a Fortune 500 company safeguarding data for 60+ million people

Job Summary

  • This role involves owning the strategy, design, and long-term direction of the IAM program for a Fortune 500 company safeguarding data for 60+ million people.
  • You will architect bold solutions at the intersection of identity, security, and engineering excellence to secure AI-driven workloads and human identities.
  • The position offers a flexible work approach requiring at least half of the time in-office or with customers while providing competitive compensation and stock grants.

Matching Summary

This role involves owning the strategy, design, and long-term direction of the IAM program for a Fortune 500 company safeguarding data for 60+ million people.

Salary

Base: $184,800 - $277,200 USD (Reston); Base: $167,200 - $300,000 USD (Other US locations); Bonus/Equity: Eligible for Workday Bonus Plan and annual refresh stock grants

Skills & Requirements

Must-have

  • 10+ years cloud security or IAM experience
  • AWS IAM foundations SCPs multi-account architecture
  • Okta enterprise scale SSO adaptive MFA SCIM
  • Federation protocols SAML OIDC OAuth2 debugging
  • Terraform infrastructure-as-code CI/CD integration
  • AI agentic identity NHI lifecycle management
  • Zero Trust identity-aware perimeters conditional access

Nice-to-have

  • GCP familiarity advantageous
  • AI security tooling LLM access governance
  • Risk mitigation mindset pragmatic trade-offs
  • Mentoring less senior engineers
  • Cross-functional technical alignment without authority

Key Requirements

  • 10+ years experience in cloud security or IAM
  • 3+ years in senior or architect-level role
  • Hands-on engagement with AI and agentic identity
  • AWS Certified Security Specialty signal of depth

Work Rights

Not specified

Tailored Resume

Cover Letter