Apply on Scopely’s site →

Senior Security IAM Engineer

Scopely · Spain

Senior Engineering Posted 2026-09-21 Full time
Apply on Scopely’s site →

Scopely is looking for a Senior IAM Security Enginee r to join our Information Security team on a remote basis in Spain.

This role will focus on building, scaling, and securing Scopely’s identity and access management ecosystem across our cloud, SaaS, AI, and remote access environments, with a strong emphasis on Terraform-based IAM automation, access workflow engineering, least-privilege design, identity risk reduction, and AI-assisted operational workflows.

This is a highly technical, hands-on role for someone who can operate across AWS, GCP, Okta, AWS IAM Identity Center, Zero Trust access models, identity governance workflows, and modern AI-enabled engineering environments, while building scalable identity systems through Infrastructure as Code, workflow orchestration, and automation-first security engineering.

What You Will Do

Build and Evolve Modern IAM Architecture

Design and evolve Scopely’s IAM architecture to support a high-scale, cloud-first environment across AWS, GCP, SaaS applications, AI tooling, and remote access platforms.

Lead initiatives around:

Federated identity architecture using SAML, OIDC, OAuth, and SCIM

Workforce identity and access patterns across internal platforms

Least-privilege role design and access segmentation

RBAC and ABAC models for cloud and SaaS environments

Centralized access models using Okta, AWS IAM Identity Center, Google Cloud IAM, and cloud-native IAM services

Secure cross-account and cross-project access patterns

Service account, workload identity, and non-human identity governance

Zero Trust identity and access control design

Partner with engineering, infrastructure, and security teams to:

Standardize secure identity and access patterns

Reduce identity sprawl and excessive permissions

Improve access visibility and auditability

Build scalable identity controls for a fast-moving engineering environment

Own Terraform-Based IAM and Access Automation

Own and improve Terraform-based IAM and access automation across Scopely’s cloud and identity environment.

Design, build, and maintain:

Reusable Terraform modules for IAM roles, policies, permission sets, group mappings, and access patterns

Terraform workflows for Okta app assignments, group-based access, and IAM Identity Center automation

Standardized access modules that can be reused safely across teams and environments

Policy-as-code patterns for least privilege and permission boundary enforcement

Terraform-driven onboarding and offboarding flows for identity-related systems

Automation for service account and workload identity provisioning

Access reporting and audit visibility pipelines connected to code-based IAM workflows

Drive improvements in:

Standardization of IAM modules, variables, role definitions, and policy structures

Repeatability and consistency of access changes

Reduction of manual IAM operations

Auditability and change traceability

Safe rollout of identity changes through code review and pull request workflows

Ensure mature Terraform engineering practices around:

State management

Drift detection and remediation

Rollback planning

Blast-radius awareness for IAM changes

Safe promotion of access changes into production

Automate Identity and Access Workflows

Build scalable automation for identity lifecycle management, access requests, entitlement changes, access reviews, and day-to-day IAM operations.

Design and implement:

Provisioning and deprovisioning automation

Access request and approval workflows

Group-based access assignment and role mapping

Okta app integration and assignment automation

IAM Identity Center permission set automation

Self-service identity workflows for internal teams

Identity reporting and access visibility pipelines

Operational tooling that reduces repetitive IAM work

Work with:

Terraform and Infrastructure as Code workflows

Python, Bash, PowerShell, and APIs

CI/CD systems and Git-based change management

Okta Workflows and similar orchestration tooling

ServiceNow, ticketing, and operational workflow integrations

AI tools such as Claude Code, Codex, and similar engineering assistants

MCP-enabled integrations, agentic workflows, and internal automation platforms

Drive improvements in:

Repeatability

Auditability

Operational safety

Reduction of manual IAM work

Secure-by-default access onboarding

Strengthen Identity Security and Risk Reduction

Lead initiatives to reduce identity-related risk across human and non-human identities.

Design and implement controls for:

Excessive permissions and privilege escalation reduction

Service account and workload identity hardening

Long-lived credential reduction

Cross-account trust policy review and hardening

Permission boundary enforcement

Role lifecycle management

Just-in-time and time-bound privileged access

Break-glass access workflows

Identity anomaly detection and misuse investigation

Use native and third-party tooling to identify and remediate risk, including:

AWS IAM Access Analyzer

CloudTrail

GuardDuty

GCP-native IAM and audit services

Okta System Log and access reporting

CIEM, CSPM, and related cloud security platforms

Improve Zero Trust and Privileged Access Security

Partner with IAM, platform, and security teams to strengthen Zero Trust and privileged access controls across Scopely’s environment.

Support and enhance:

Twingate connectors, resources, and access policy design

Identity-aware remote access controls

Zero Trust segmentation for internal applications and privileged systems

Privileged access workflows

PAM platform integrations such as Britive

Adaptive access controls

MFA and passwordless adoption

Federated access into AWS, GCP, SaaS platforms, and internal tools

Secure vendor and contractor access patterns

Drive improvements in:

Human identity security

Non-human identity security

Access visibility

Privileged session control

Access policy consistency across environments

Support Identity Investigations, Monitoring, and Audit Readiness

Partner with Security Operations, Compliance, and Infrastructure teams to improve identity monitoring, investigation, and audit readiness.

Build and enhance:

IAM troubleshooting runbooks

Identity-related detection and triage workflows

Access review processes

Permission reporting and evidence collection

IAM logging and monitoring design

Operational metrics for identity security maturity

Support investigations involving:

Suspicious access activity

Identity and permission abuse

Misconfigured app integrations

Broken federation and provisioning flows

Risky SaaS integrations

Service account misuse

Cross-account access issues

Collaborate with compliance and audit stakeholders to ensure:

SOC 2 and ISO 27001 alignment

Access review evidence readiness

Documentation of IAM controls and workflows

Clear traceability for privileged access and entitlement changes

Build AI-Assisted Identity Security Workflows

Design and improve AI-assisted and automation-first workflows that help Scopely scale identity security safely.

Lead initiatives around:

AI-assisted access review analysis

AI-assisted troubleshooting and documentation support

Intelligent triage for identity-related findings

Security chatops integrations

Identity workflow automation using agents and orchestration systems

Internal copilots for IAM operations and knowledge support

AI-assisted recommendations for access hygiene and remediation

MCP-enabled identity tooling and integrations

Work with:

Claude Code, Codex, and similar AI-assisted engineering tools

MCP-based workflows and agentic automation patterns

Internal automation platforms and workflow engines

APIs, event-driven automation, and identity telemetry pipelines

Ensure safe adoption of AI by applying:

Human-in-the-loop approval controls

Least-privilege access to tools and data

Logging and auditability for AI-assisted workflows

Prompt and data handling safeguards

Clear separation between recommendations and privileged actions

Act as a Technical Leader

Partner with engineering, platform, IT, and studio teams to align IAM strategy with Scopely’s operational and business goals.

Provide expert guidance on:

Modern IAM architecture

Federated identity design

Least-privilege engineering

Zero Trust access models

Non-human identity risk

IAM automation strategy

Terraform design patterns for identity and access management

Access governance in fast-growing environments

Secure access design for engineering teams

Safe use of AI in identity and access workflows

Influence teams to:

Adopt secure identity patterns

Automate IAM safely

Reduce reliance on manual access processes

Improve cloud and SaaS access consistency

Build scalable and maintainable identity controls

Raise the bar for:

Identity-aware security

Automation-first IAM operations

Practical access governance

Engineering-driven IAM design

AI-assisted identity operations

What We’re Looking For

Core Experience

8–12+ years in IAM security engineering, cloud security, identity architecture, or related security engineering roles

Strong experience operating in cloud-first, high-scale environments

Experience partnering directly with engineering, infrastructure, and security teams

Experience designing and operating IAM solutions for global organizations with complex access needs

Strong track record in identity modernization, least privilege, and access automation

Proven experience building automation and reusable engineering patterns, not just handling manual IAM operations

Technical Skills

Cloud and Identity

Strong hands-on experience with:

AWS IAM, AWS Organizations, IAM Identity Center, SCPs, IAM roles and policies, CloudTrail, GuardDuty, IAM Access Analyzer, SSM

GCP IAM, service accounts, workload identity patterns, organization/folder/project models, and audit services

Okta administration including groups, rules, app integrations, assignments, lifecycle management, and troubleshooting

SAML, OIDC, OAuth, SCIM, and federated identity design

Cross-account and cross-project access controls

Service account and workload identity governance

Twingate administration or comparable ZTNA and remote access platforms, including connectors, resources, access policies, and policy troubleshooting

Infrastructure as Code and Automation

Strong hands-on experience with:

Terraform-based IAM and access automation in production

Designing reusable Terraform modules for IAM roles, policies, permission sets, group mappings, and access patterns

Terraform state management, drift detection, rollback planning, and safe deployment of IAM changes

Git-based workflows, pull requests, and code review for infrastructure and identity changes

Python, Bash, PowerShell, or similar scripting languages

API integrations and workflow automation

Provisioning and deprovisioning automation

Access reporting and policy standardization

CI/CD integration for identity-related workflows

Strong understanding of:

Policy-as-code and automation-first IAM

How to convert manual IAM processes into reusable code-driven workflows

How to build transferable, scalable access patterns across teams and environments

Safe production change practices for identity and access automation

AI and Emerging Technologies

Experience or strong interest in:

Claude Code, Codex, and similar AI-assisted engineering tools

MCP integrations and agent-based automation workflows

AI-assisted detection, triage, remediation support, and documentation

Prompt security, model safety, and human-in-the-loop operational controls

Evaluating and safely operationalizing AI tooling in security environments

Security Expertise

Strong understanding of

Least privilege and role engineering

RBAC and ABAC design

Identity threat modeling

Privileged access and JIT access models

Identity lifecycle management

Non-human identity risk reduction

Identity logging and monitoring

Access reviews and audit readiness

Security controls for SaaS and cloud identity systems

Aptitudes

Builder mindset - creates scalable IAM systems, not one-off fixes

Automation-first mentality - reduces manual effort through safe automation

Systems thinker - connects IAM, cloud, SaaS, developer workflows, and operational risk

AI-forward mindset - embraces intelligent automation while applying practical security guardrails

Pragmatic and engineering-oriented - balances security with usability and speed

High ownership - operates effectively in complex, fast-moving environments

Strong communicator - able to explain IAM risks and solutions to engineers, IT, and leadership

Bonus Points

Experience with Britive, CyberArk, SailPoint, or similar PAM/PIM platforms

Experience with Okta Workflows, CIEM platforms, or identity governance tooling

Experience with Wiz, GuardDuty, Astrix, or similar tools for identity-related investigations

Experience in gaming, SaaS, or multi-studio environments

Experience with passwordless authentication, WebAuthn, or FIDO2

Experience building AI-assisted workflows for IAM operations, documentation, access reviews, or investigations

Familiarity with AI security frameworks, governance, and safe agentic automation patterns

Security certifications such as CISSP, AWS Security Specialty, or relevant IAM/cloud certifications

This role is ideal for someone who is excited about building modern identity security beyond traditional approaches and wants to help Scopely scale secure access across cloud, SaaS, AI, and engineering environments. If you enjoy solving IAM challenges with Terraform, automation, reusable engineering patterns, and well-designed identity systems, we’d love to hear from you.

Please ensure that the résumé/CV you attach is written in English.

About Scopely

Scopely is a leading video game and global interactive entertainment company, home to many of the world’s most beloved and enduring experiences, including two of the most successful mobile games of all-time “MONOPOLY GO!” and “Pokémon GO,” along with “Stumble Guys,” “Star Trek™ Fleet Command,” “MARVEL Strike Force,” “WWE Champions,” the Scrabble® franchise, “Yahtzee® With Buddies,” and many others. Across mobile, web, PC, and console, Scopely creates, develops, publishes, and live-operates one of the most diversified and award-winning portfolios in the games industry — bringing hundreds of millions of players together through a shared love of play.

Founded in 2011, Scopely is powered by its exceptional team — including thousands of world-class gamemakers around the globe, a distinctive tenet-driven culture, and its proprietary technology platform, Playgami. Together, these strengths have fueled Scopely’s position as the #1 mobile games company in the U.S. and #2 globally, generating more than $10 billion in lifetime revenue. Whether building global sensations like “MONOPOLY GO!” from the ground up, or expanding through strategic acquisitions, including the FoxNext, GSN, and Scopely Explore games businesses — Scopely consistently delivers experiences players love today and return to for years to come.

Recognized multiple times as one of the "100 Most Influential Companies in the World" by TIME magazine and one of Fast Company s "World s Most Innovative Companies" and “Best Workplaces for Innovators,” Scopely believes that video games can be a force for good — creating meaningful connections, vibrant communities, and making life better through play.

Scopely has global operations and partners across four continents in more than a dozen countries worldwide. For more information, visit: https://www.scopely.com/ .

Notice to Candidates: Scopely will never request payment or financial information during the application or hiring process. Please apply only through our official website and verify that all Talent Partner communications come from an email address ending in @ scopely.com .

Should you have any questions or encounter any fraudulent requests/emails/websites, please immediately contact recruiting@scopely.com. Our job applicant privacy policies are available here: California Privacy Notice and EEA/UK Privacy Notice .

Employment at Scopely is based solely on a person s merit and qualifications. Scopely does not discriminate against any employee or applicant because of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), or any other basis protected by law. We also consider qualified applicants with arrest or conviction records, consistent with applicable federal, state and local law.

Posted by Scopely and synced from their own careers page. DevQuest doesn’t take a fee, doesn’t sit between you and the studio, and doesn’t sell your data — you apply directly with them.

More like this: Engineering jobs · All Scopely openings · Browse every category