Security Identity Engineer
Location: Dallas, TX or Toronto, ON preferred; New York, NY also considered
Project: AWS Project Omni – Next-Generation Observability
Environment: Enterprise AWS / SRE / Observability
Position Overview
We are seeking a highly experienced AWS Forward Deployed Engineer to work embedded with the client’s Site Reliability Engineering (SRE) and Observability team on Project Omni, AWS’s next-generation observability capability.
This engineer will help build and integrate Omni end-to-end within a large-scale, regulated enterprise AWS environment. The primary focus of this role is AWS Identity and Access Management, including AWS IAM Identity Center (IdC), enterprise federation, entitlements, fine-grained authorization, and secure data boundaries.
The ideal candidate combines deep AWS identity and security expertise with strong hands-on engineering capabilities across AWS multi-account infrastructure, CloudWatch observability, backend/API development, and Infrastructure as Code (IaC).
The client already has a mature AWS identity-federation environment, including an established custom credential-vending/SAML broker and existing AWS IAM Identity Center adoption for console access. This role will therefore focus on integrating Omni into an existing enterprise identity and entitlement model, rather than designing identity architecture from the ground up.
Important: Project Omni is an unreleased AWS service currently in Private Beta. Work will be performed in non-production environments.
Key Responsibilities
Identity, Federation & Entitlements
- Integrate the Omni API layer with AWS IAM Identity Center (IdC).
- Integrate Omni with the client’s existing enterprise identity-federation environment, including its custom credential-vending/SAML broker.
- Design and implement secure identity and entitlement models across a complex enterprise AWS environment.
- Build authorization policies that enforce appropriate data boundaries across SRE teams, Application teams, and Business Units.
- Implement Attribute-Based Access Control (ABAC) and fine-grained authorization mechanisms.
- Work with authorization technologies such as AWS Verified Permissions and/or Open Policy Agent (OPA).
- Ensure identity and access-control solutions align with enterprise security, governance, and audit requirements.
AWS Multi-Account Governance & Data Routing
- Design and automate cross-account connectivity to aggregate logs, metrics, and traces across multiple AWS Organizations.
- Implement secure cross-account observability using CloudWatch cross-account capabilities and AWS Observability Access Manager (OAM).
- Work with OAM sink and source configurations across large AWS environments.
- Leverage AWS Organizations, organization-level APIs, policies, and CloudFormation StackSets to automate infrastructure provisioning.
- Support automated deployment of source links and related resources across an AWS estate of approximately 15,000 accounts.
- Design solutions capable of operating reliably and securely at significant enterprise scale.
End-to-End Feature Development
- Build, test, and deploy features spanning the AWS infrastructure layer through the backend API layer supporting the Omni user experience.
- Work across CloudWatch, Omni, IAM, CloudTrail, flow logs, APIs, and supporting AWS infrastructure.
- Develop reliable and high-performance APIs using Python, Java, or Go.
- Build API services capable of efficiently querying CloudWatch, CloudTrail, and flow-log data.
- Implement caching strategies and asynchronous data-fetching patterns to improve API performance and scalability.
- Troubleshoot complex integration and performance issues across infrastructure, identity, observability, and application layers.
Cloud Observability
- Design and implement solutions using Amazon CloudWatch Metrics, Logs, Alarms, and Contributor Insights.
- Implement and manage CloudWatch cross-account observability/OAM.
- Work extensively with CloudTrail, VPC/flow logs, telemetry aggregation, and operational monitoring.
- Support enterprise-scale observability patterns across multiple AWS Organizations and accounts.
Infrastructure as Code & Automation
- Automate AWS infrastructure deployment using Terraform and/or AWS CDK.
- Develop repeatable, scalable, and governed infrastructure deployment patterns.
- Use AWS CloudFormation StackSets for large-scale multi-account deployments.
- Integrate infrastructure deployments into CI/CD pipelines such as GitLab CI.
- Ensure infrastructure automation supports enterprise governance, change control, security, and auditability.
Documentation & Client Enablement
- Produce clear technical and architectural documentation for the Omni implementation.
- Create Architecture Decision Records (ADRs), design documents, integration guides, and operational runbooks.
- Produce documentation suitable for client Technology Risk and Security reviews.
- Transfer knowledge to client engineering teams so they can operate, maintain, and extend the Omni identity and routing model.
- Serve as an embedded AWS SME alongside the client’s SRE, Observability, Security, and Engineering leadership.
Required Technical Skills
AWS Identity & Security – Advanced / Primary Skill
- Deep hands-on expertise with AWS IAM Identity Center (IdC).
- Strong experience with SAML and/or OIDC federation.
- Experience integrating AWS services with established enterprise federation and credential-vending models.
- Strong understanding of AWS IAM roles, policies, permissions, entitlements, and enterprise access-control patterns.
- Experience implementing Attribute-Based Access Control (ABAC).
- Experience with fine-grained authorization and policy engines such as AWS Verified Permissions or Open Policy Agent (OPA).
AWS Multi-Account Governance – Advanced
- Advanced experience with AWS Organizations.
- Strong understanding of organization-level AWS APIs, policies, governance, and security controls.
- Experience with AWS CloudFormation StackSets.
- Demonstrated ability to automate infrastructure provisioning across very large multi-account AWS environments.
- Experience designing solutions that can operate across thousands of AWS accounts is strongly preferred.
Cloud Observability – Advanced
- Advanced experience with Amazon CloudWatch, including:
- Metrics
- Logs
- Alarms
- Contributor Insights
- Cross-account observability
- AWS Observability Access Manager (OAM)
- Experience with CloudTrail and VPC/flow logs.
- Strong understanding of telemetry aggregation and enterprise observability architectures.
Backend Development – Proficient
- Strong programming skills in at least one of the following:
- Python
- Java
- Go
- Experience developing high-performance REST/API services.
- Experience integrating APIs with AWS services.
- Understanding of caching strategies, asynchronous data fetching, performance optimization, and scalable backend architecture.
Infrastructure as Code – Advanced
- Advanced hands-on experience with Terraform and/or AWS CDK.
- Experience with automated infrastructure deployment pipelines.
- CI/CD experience, preferably with GitLab CI or similar enterprise CI/CD platforms.
- Strong understanding of repeatable, governed, and auditable cloud deployment practices.
Preferred Qualifications
- AWS Professional or Specialty certification strongly preferred, including:
- AWS Certified Security – Specialty
- AWS Certified Solutions Architect – Professional
- AWS Certified DevOps Engineer – Professional
- Previous experience delivering AWS solutions within a large, regulated enterprise environment.
- Financial services experience strongly preferred.
- Experience operating under formal change-control, security, audit, compliance, and Technology Risk requirements.
- Previous experience within SRE, Cloud Platform Engineering, Observability, Security Engineering, or Cloud Infrastructure environments.
- Experience serving as an embedded technical SME or Forward Deployed Engineer within a client organization.
Professional Requirements
- Strong written and verbal communication skills.
- Ability to communicate complex AWS identity, security, observability, and architecture concepts to technical stakeholders.
- Ability to independently drive technical features from architecture and design through implementation, testing, deployment, documentation, and handoff.
- Strong technical documentation skills.
- Comfortable working directly with client SRE, Engineering, Security, Cloud, and Technology Risk teams.
- Ability to operate effectively in a highly regulated enterprise environment.
- Comfortable working in a client-facing, embedded engineering/consulting capacity.
- Must meet applicable engagement location and time-zone requirements.
- Must complete required AWS and client interviews, onboarding, security, vetting, and tollgate processes.
Ideal Candidate Profile
The ideal candidate is a senior AWS engineer with deep Identity and Access Management expertise who can also deliver solutions end-to-end across infrastructure and application layers.
This individual should be comfortable integrating new AWS capabilities into an established enterprise identity-federation environment, implementing sophisticated authorization models, automating infrastructure across thousands of AWS accounts, building APIs, and working extensively with CloudWatch and cross-account observability.
Candidates who combine AWS IAM/Identity Center expertise, enterprise federation, AWS Organizations, CloudWatch/OAM, Terraform or CDK, and hands-on backend development will be the strongest fit for this position.