The English-language job board for Spain

Cloud Identity and Access Operations Expert

Remote, Madrid·Added 3 days ago

Still open when we checked on 8 Oct

Mapfre

85 open roles

Overview

Job details

  • Fully remote

    Per the ad.

Requirements

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Work in English

    English is required, per the ad.

  • Have 5+ years of experience

    Mid-level role.

  • University degree

    “Grado en Ingeniería Informática, de Telecomunicaciones o similares.” — per the ad.

Benefits

  • Private health insurance

    Per the ad: paid by the employer, or taken through flexible pay.

  • Life insurance

    Per the ad.

  • Flexible pay plan

    Take part of your salary as tax-free benefits, per the ad.

Skills

This job advert was originally written in Spanish.

Requirements

What we're looking for

A degree in Computer Engineering, Telecommunications Engineering, or a related field.

Advanced level of English to take part in international projects.

Training and knowledge in:

Microsoft EntraID, Active Directory, and hybrid identity, applied to the lifecycle, integration, synchronization, and security of identities.

Automated processes for onboarding, modification, mobility, review, suspension, and offboarding, including provisioning, deprovisioning, reconciliation, attribute transformation, and exception handling.

Integration with source systems, IAM/IGA solutions, directories, cloud platforms, and corporate applications through connectors, APIs, and automated flows.

Technical management and control of users, groups, applications, roles, Administrative Units, devices, and non-human identities, including service accounts, service principals, managed identities, and workload identities.

Microsoft EntraID Governance, Access Reviews, Entitlement Management, PIM, Conditional Access, MFA, passwordless, and Identity Protection.

Enterprise applications and application registrations, including delegated and application permissions, federation, SSO, and SAML 2.0, OAuth 2.0, OpenID Connect, and SCIM protocols.

Advanced automation through PowerShell, Microsoft Graph API, and REST API, including authentication, permissions, queries, pagination, bulk processes, and error handling.

Design and maintenance of idempotent, traceable, and recoverable automations, using Git, testing, validations, retries, alerts, activity logging, and controlled deployment.

Analysis of authentication, audit, provisioning, and risk logs, as well as development of controls, queries, and indicators to detect deviations and evaluate their effectiveness.

Azure RBAC and access models for users, applications, and workloads to Azure resources, including controls over secrets, keys, certificates, and other credentials.

Diagnosis and resolution of complex provisioning, reconciliation, authentication, authorization, federation, and identity integration incidents.

Zero Trust principles, least privilege, segregation of duties, temporary access, and technical management of changes, incidents, and problems in production environments.

Ability to prepare technical documentation, diagrams, procedures, test evidence, and reports. Experience with Power BI or other visualization tools will be valued.

Technical analysis capacity, complex problem solving, and root cause analysis.

Orientation toward automation, continuous improvement, and the reduction of manual tasks.

Ability to develop secure, maintainable, reusable, and documented integrations and solutions.

Rigor in the management of changes, identities, access, and privileges, applying least privilege principles.

Autonomy, initiative, and orientation toward technical quality.

Ability to collaborate with application, cloud, DevOps, infrastructure, and cybersecurity teams.

Ability to communicate and document technical decisions clearly

Nice to have

A minimum of five years of experience in engineering, automation, or technical operation of identity solutions is required, preferably in complex corporate environments.

Demonstrable experience in:

Microsoft EntraID, Active Directory, and hybrid identity.

Automation through PowerShell, Microsoft Graph, and REST API.

Automated provisioning, reconciliation, regularization, and remediation of identities and access.

Application integration through SAML, OAuth 2.0, OpenID Connect, and SCIM.

Management of enterprise applications, permissions, roles, Access Reviews, and Entitlement Management.

Non-human identities, such as service accounts, service principals, managed identities, and workload identities.

Azure RBAC, privileged access, secrets, certificates, and credentials.

Monitoring of identity events, log analysis, indicators, and resolution of complex incidents.

Development of maintainable, idempotent, and recoverable automations, using Git and engineering practices.

Integration with IAM, IGA, PAM, SIEM, ITSM, and cloud automation platforms.

Experience in large organizations or international environments, integration with human resources systems, development of connectors and automations, non-human identities, AWS or other cloud providers, and application of software engineering practices to the identity field will be especially valued.

Experience in project management, vendor coordination, document governance, general Microsoft 365 administration, or user support will be considered complementary, but not a substitute for the required technical experience.

Education & certifications

Microsoft Certified: Identity and Access Administrator Associate, SC-300.

Microsoft Certified: Cybersecurity Architect Expert, SC-100.

Microsoft Certified: Azure Security Engineer Associate, AZ-500.

Microsoft Certified: Azure Administrator Associate, AZ-104.

AWS certification related to security, architecture, or cloud operations.

CISA, CISM, CISSP, or equivalent certifications.

Pay & benefits

What you'll get

Flexible working hours and remote work options to help you balance your professional and personal life.

A flexible compensation package that includes: meal vouchers, childcare vouchers, medical insurance, life insurance, employee discounts, and more. And if you live in Madrid, a company shuttle bus is available to get you to the office.

Access to an attractive pension plan.

Discounts on the products and services offered by our company.

Summer intensive schedule.

You'll be in charge of your own learning journey, with access to thousands of resources to keep advancing your technical expertise. Plus, you'll receive an additional €1,100 per year to further develop your skills.

The opportunity to participate in volunteer projects.

A great place to work! We're ranked among the 50 best companies to work for in Spain according to Forbes magazine.

We are diverse, and that makes us unique!

The role

Change your life and continue developing your professional career at Mapfre! You will be part of an international environment where you can innovate by participating in global projects focused on the latest technological trends. All this in a flexible and agile environment surrounded by excellent professionals from all over the world... are you ready?

From the Cybersecurity department, we want to hire a Cloud Identity and Access Operations Expert to perform the maintenance, automation, integration, control, and evolution of corporate cloud identity and access solutions, guaranteeing compliance with the established model, the correction of deviations, and the secure lifecycle of identities. The main scope will be Microsoft EntraID and Azure, including integration with AWS and other cloud environments.

What you'll do

In relation to the automation of the operation, control, maintenance, and technical evolution of the lifecycle of cloud identities and access, you will be responsible for:

Maintaining and evolving the automated lifecycle models and processes for human and non-human identities, ensuring the correct application of attributes, states, owners, authoritative sources, and rules for onboarding, modification, review, suspension, and offboarding.

Maintaining and expanding provisioning, deprovisioning, and reconciliation integrations between human resources systems, directories, Microsoft EntraID, cloud platforms, and applications, through connectors, SCIM, API, and workflows.

Maintaining automated controls over users, groups, applications, roles, authentication methods, Administrative Units, and devices, detecting orphaned, duplicate, inactive, obsolete, unreconciled, ownerless, or residual access objects.

Maintaining and evolving application integration through SAML, OpenID Connect, OAuth 2.0, and SCIM, automating authentication, federation, provisioning, assignment, and access removal processes.

Controlling the lifecycle of non-human identities, including service accounts, applications, service principals, managed identities, workload identities, machines, automations, and digital agents, verifying their purpose, owner, activity, permissions, credentials, validity, rotation, and removal.

Analyzing application and automation permissions, detecting excessive, permanent, unused, or unjustified assignments, and applying the principles of least privilege and segregation of duties.

Maintaining and evolving authentication, authorization, and privileged access controls through Conditional Access, MFA, passwordless, Identity Protection, PIM, Access Reviews, and Entitlement Management.

Maintaining controls over identities and access to Azure resources through Azure RBAC, PIM for Azure Resources, and workload identities, as well as the validity and rotation of secrets, keys, and certificates in coordination with Azure Key Vault and specialized corporate solutions.

Maintaining and evolving identity integration and control in AWS and other cloud providers through federation, IAM Identity Center, roles, policies, and temporary credentials.

Developing, maintaining, and evolving inventory, lifecycle, reconciliation, review, regularization, and remediation automations through PowerShell, Microsoft Graph, REST API, and other corporate capabilities, minimizing manual interventions.

Applying engineering practices to scripts, connectors, and automations, ensuring their idempotency, traceability, maintainability, and recoverability through version control, testing, error management, retries, alerts, documentation, and controlled deployment.

Ensuring compliance with corporate policies, standards, and models through preventive, detective, and corrective controls, adapting them to new needs, risks, and identity typologies.

Maintaining and evolving monitoring and alerting to detect deviations, analyze exceptions not resolved automatically, and develop corrections or new automations to prevent their recurrence.

Maintaining and improving mechanisms for automatic regularization and remediation of identities, access, privileges, permissions, and credentials, prioritizing deviations according to their risk.

Maintaining indicators, queries, and technical reports on volume, quality, compliance, risk, and the effectiveness of controls and remediations.

Resolving complex incidents and exceptions, performing root cause analysis, and incorporating permanent corrective actions into processes, integrations, and controls.

At a relational level, both within the area and with the various entities of the Group and external collaborators:

Providing technical advice to application, infrastructure, cloud, and cybersecurity teams on the secure integration of human and non-human identities.

Participating in initiatives that require authentication, authorization, federation, provisioning, or identity lifecycle management.

Collaborating with the Global SOC in the investigation of incidents related to identities, credentials, access, and privileges, contributing to their resolution and the prevention of recurrences.

Coordinating technically with manufacturers, providers, and internal teams in the diagnosis, maintenance, and evolution of identity solutions.

Promoting knowledge transfer through documentation, best practices, procedures, and reusable components that reduce dependencies and facilitate operational continuity.

How you'll work

In Majadahonda, Community of Madrid.

Hiring process

3 steps4 interviews
  1. First point of contact

    With recruitment team

    Starts from your application, LinkedIn, or a call from the recruitment team or a partner agency; a first conversation about you and the open opportunities.

  2. Interview with Human Resources

    With HR team

    Conversation about your interests, experience, skills and how you approach challenges, plus your questions about Mapfre.

  3. Technical interview

    With the team · 1–2 sessions

    One or two interviews with the team to assess technical skills and explain the day-to-day of the role.

About Mapfre

Mapfre is a global insurance company headquartered in Madrid, Spain, with a strong presence in the insurance and reinsurance markets across Europe, the Americas, and Asia. It offers a wide range of products including life, health, auto, and home insurance, and operates through multiple brands such as Verti. With over 30,000 employees worldwide, Mapfre is one of the largest Spanish multinationals in the insurance sector.

In Spain, Mapfre has its main offices in Madrid and Barcelona, with a significant network of commercial offices across the country. The company is known for its strong corporate culture, focus on digital transformation, and investment in technology and data analytics. For international professionals, Mapfre offers opportunities in areas like data science, cybersecurity, cloud architecture, and finance, with a work environment that values innovation and professional development.

Industry
Insurance
Founded
1933
Employees
10,000–50,000
Headquarters
Madrid, Spain
In Spain
Madrid, Barcelona
Website
mapfre.com

Good to know if you are moving

  • Mapfre is headquartered in Madrid, Spain, and has a large presence in Barcelona and other Spanish cities.
  • The company offers roles in English and Spanish, with many technical positions in data, cloud, and cybersecurity.
  • Mapfre has a strong commitment to digital transformation, investing in AI, data analytics, and cloud infrastructure.
  • International hires may find opportunities in the company's global operations, especially in Latin America and Europe.
  • The company provides a stable work environment with a focus on long-term career development.

In their own words

Additional information

All selection processes at Mapfre are conducted under the principle of EQUAL OPPORTUNITIES and NON-DISCRIMINATION, with the APTITUDES and PERSONAL AND PROFESSIONAL MERIT of the candidate being the criteria on which the final selection for the position is based.

We create work environments that value diversity and are free from discrimination based on sex, race, ideology, religion, sexual orientation, age, nationality, disability, or any other personal, physical, or social condition.

You can consult our Diversity and Equal Opportunities policy: politica-de-diversidad-e-igualdad-de-oportunidades.pdf (mapfre.com)

By applying to this job offer, you are informed and consent to the processing by Mapfre of the personal data you have voluntarily provided through this platform. If you provide personal data of third parties other than yourself, you guarantee that you have obtained and have their prior consent to share their data and that you have informed them accordingly.

MAPFRE, as the controller, will process your data for the sole purpose of processing your participation in selection processes, for which profiles may be created, and the processing of your data may derive the existence of automated decisions. For the purpose of managing your participation in various selection processes in Mapfre Group companies, subsidiaries, and affiliates, and the MAPFRE Foundation, your data may be communicated to said entities and may be subject to international transfer.

You can find additional information about data protection at MAPFRE at https://www.mapfre.com/corporativo-es/clausulas/RRHHseleccion.pdf, where we explain how to exercise your rights of access, rectification, erasure, restriction, objection, and portability of your personal data.

All open roles at Mapfre
WhatsApp

Life and Investment Commercial Executive

Mapfre3d ago3 locations
€30kMadrid
€30kMadrid

CRM Specialist

Mapfre2d ago
Hybrid in MadridNo Spanish needed
Hybrid in MadridNo Spanish needed
Málaga
Majadahonda
Hybrid in MadridNo Spanish needed
Hybrid in MadridNo Spanish needed
Hybrid in MadridNo Spanish needed
See all 85 jobs