Skip to content

Open nowPosted 18 hours ago

Senior IAM Engineer

Aiven40 open roles

Where
Helsinki, Uusimaa, Finland
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior IAM EngineerAiven · Helsinki, Uusimaa, Finland
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Aiven's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Aiven postings stay open a median of 3 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 18 hours ago

Aiven median: 3 days open

The posting

We’re a global team of over 400 people, working together to push the boundaries of open-source technology and multi-cloud solutions. Our vision is to help developers, builders, and creators bring their ideas to life with speed and simplicity, by providing a cloud data platform that makes open-source databases, search, streaming, and application infrastructure easily accessible to everyone.

You'd be joining an experienced and highly-engaged Security & Compliance team, working closely with Product Security, Security Operations, and Compliance. Identity touches every part of the org, so you'd have real influence over the roadmap and trajectory of Security more broadly, not just IAM. You'd be collaborating with people across the globe, with plenty of opportunity to grow your skillset across a genuinely multi-cloud footprint.

The Role:

We are seeking a proactive and detail-oriented Senior IAM Engineer to join our Security team.

Identity is the control plane for Aiven. Every employee, service, and automation reaches our systems through it, which makes identity and access management the determining factor in ensuring access is efficient, audited, and controlled.

In this role you will own identity and access management end to end: the joiner-mover-leaver lifecycle flowing from our HRIS system through Okta to every downstream application, the access request and review processes that keep entitlements defensible, and the automation that sustains both without manual intervention. You will be the reference point and partner for Engineering, IT, People Operations, and Security Operations on any question concerning who can access what, and on what basis.

You'll work at the center of a wide cross-functional web - partnering closely with Engineering, IT, People Operations, and Security Operations, and acting as the go-to voice on identity for the broader Security & Compliance org. Day to day, you'll live in Okta as your core platform, orchestrating lifecycle automation through Okta Workflows, managing access requests and approvals via Jira, and integrating identity across a growing set of enterprise SaaS tools, major cloud providers (AWS, GCP, Azure), and internal systems. It's a role with real technical range and ownership - you'll move between platform administration, AI integration and automation, and the judgment calls that come with owning access decisions for the whole company.

The role carries genuine technical breadth and will suit an engineer who treats recurring manual work as a defect to be resolved using AI-systems or repeatable automation rather than a task to be repeated.

What You'll Do

  • Identity lifecycle and onboarding/offboarding - own employee lifecycle end to end, from HRIS system through Okta to downstream applications
  • Identity automation - build and maintain automation in Okta Workflows, driven by our HRIS as the source of truth
  • Machine and AI agent identity - extend IAM practices to non-human identities: define how service accounts, bots, and AI agents are provisioned, scoped, reviewed, and deprovisioned, applying the same rigor to machine identity as you do to human access.
  • Access governance - own the access request and approval process, keeping routine access efficient and sensitive access controlled and auditable
  • Self-service access & IGA - continue to build self-service access and define/maintain per-role access policies refined each cycle
  • Application access and provisioning - onboard new applications to SSO and automated provisioning, design role-based access for applications, including Okta group structure, application role mappings, SCIM provisioning, and push groups
  • Security review and cross-functional partnership - review of new integrations and access requests, assessing permission scope and credential exposureAudit and compliance - provide identity evidence for PCI, SOC 2, and ISO 27001

What We’re Looking For:

  • You’re an identity engineer with deep IdP expertise. Okta experience is strongly preferred, but other platforms (Entra ID/Ping) will be considered
  • Five or more years in IAM, identity engineering, or a closely related security discipline, with demonstrable ownership of an identity platform rather than operational support.
  • Proficiency in automation in Python, JavaScript, or similar, to support the automation of routine identity tasks and reduce manual work - for us manual repetitive work is a defect. Fluent with AI tooling and able to understand how to utilize and leverage AI to enhance IAMs capabilities and service delivery.
  • Experience owning technical employee onboarding and offboarding end to end, including managing access requests and approvals, and automating fulfillment through Okta rather than provisioning manually.
  • Hands-on cloud IAM experience with at least one major cloud provider. AWS, GCP, or Azure - including roles, policies, permission boundaries, and identity federation.
  • Experience with Infrastructure as Code for identity resources, such as Terraform, so that access configuration is version-controlled and reviewable
  • Comfort with ambiguity and a strong sense of ownership. Much of this work is undefined until someone defines it, and we are looking for the person who will write it down.

Nice to Have

  • Deep, practical Okta expertise across Universal Directory, profile mappings and sourcing, group rules and Expression Language, application assignments, SSO, and lifecycle management.
  • Demonstrated experience automating identity processes with Okta Workflows or an equivalent identity automation platform, driven by an HRIS as the source of truth.
  • Broader security knowledge beyond identity - for example security operations, vulnerability management, cloud security posture, or incident response.
  • Experience governing machine identities, including service accounts, API tokens, bot users, and credentials for automation platforms or AI agents
  • Exposure to IGA products, GRC platforms, or access certification tooling

Amazing! What’s next:

If you think Aiven is the place for you and that our Values align with yours, send us your resume and we’ll get in touch!

Global Benefits:

Our global benefits are designed to help you thrive and grow, personally and professionally:

  • Participate in Aiven’s equity plan.
  • Balance work and life with our hybrid work policy.
  • Choose the equipment you need to set yourself up for success.
  • Use your Professional Development Plan budget for learning opportunities.
  • Receive holistic wellbeing support through our global Employee Assistance Program.
  • Inquire about our Global Time Off Commitment (Parental and Sick Leave, as well as Personal Time)
  • Enjoy country-specific benefits for our global cast.

How to Recognize and Avoid Employment Scams:

There has been a rise in fake job postings used by scammers to get personal information. At Aiven, all of our emails relating to recruitment come from an @aiven.io, @greenhouse.io or @eu.greenhouse.io domain and all of our interviews are conducted by video call or in person. Our interviews will never occur via text or chat. If you’re unsure of the legitimacy of a job opportunity/offer pertaining to Aiven, please don’t hesitate to reach out to us at [email protected].

Equal Opportunities:

Aiven provides equal employment opportunities to all qualified employees and applicants for employment without regard to age, gender identity, national or ethnic origin, religion, sexual orientation, physical and mental ability, marital and family status or without regard to any other similar personal attributes. Aiven complies with applicable local laws governing non-discrimination in employment in every location in which the company operates. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, transfer, leaves of absence, compensation, training and any other terms and conditions related to employment.

At Aiven we are committed to providing reasonable accommodations for qualified individuals with disabilities or special needs in our working environment and job application procedures. We make all reasonable accommodations for persons with disabilities or who otherwise need support to thrive in the workplace. We are committed to continuously improving workplace accessibility. There is an option to request a discussion in the application process but if you have any questions before applying please write to us at [email protected].

#LI-Hybrid

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Aiven's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Aiven's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Aiven's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.