The English-language job board for Spain

Senior Security IAM Engineer

Remote, ES - Spain·Added today

Still open when we checked on 8 Oct

Scopely

83 open roles

Overview

Job details

  • Fully remote

    Per the ad.

Requirements

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Work in English

    English is required, per the ad.

  • Have 8+ years of experience

    Senior-level role.

Skills

Requirements

What we're looking for

  • 8-12+ years in IAM security engineering, cloud security, identity architecture, or related security engineering roles
  • Strong experience operating in cloud-first, high-scale environments
  • Experience partnering directly with engineering, infrastructure, and security teams
  • Experience designing and operating IAM solutions for global organizations with complex access needs
  • Strong track record in identity modernization, least privilege, and access automation
  • Proven experience building automation and reusable engineering patterns, not just handling manual IAM operations
  • AWS IAM, AWS Organizations, IAM Identity Center, SCPs, IAM roles and policies, CloudTrail, GuardDuty, IAM Access Analyzer, SSM
  • GCP IAM, service accounts, workload identity patterns, organization/folder/project models, and audit services
  • Okta administration including groups, rules, app integrations, assignments, lifecycle management, and troubleshooting
  • SAML, OIDC, OAuth, SCIM, and federated identity design
  • Cross-account and cross-project access controls
  • Service account and workload identity governance
  • Twingate administration or comparable ZTNA and remote access platforms, including connectors, resources, access policies, and policy troubleshooting
  • Terraform-based IAM and access automation in production
  • Designing reusable Terraform modules for IAM roles, policies, permission sets, group mappings, and access patterns
  • Terraform state management, drift detection, rollback planning, and safe deployment of IAM changes
  • Git-based workflows, pull requests, and code review for infrastructure and identity changes
  • Python, Bash, PowerShell, or similar scripting languages
  • API integrations and workflow automation
  • Provisioning and deprovisioning automation
  • Access reporting and policy standardization
  • CI/CD integration for identity-related workflows
  • Policy-as-code and automation-first IAM
  • How to convert manual IAM processes into reusable code-driven workflows
  • How to build transferable, scalable access patterns across teams and environments
  • Safe production change practices for identity and access automation
  • Least privilege and role engineering
  • RBAC and ABAC design
  • Identity threat modeling
  • Privileged access and JIT access models
  • Identity lifecycle management
  • Non-human identity risk reduction
  • Identity logging and monitoring
  • Access reviews and audit readiness
  • Security controls for SaaS and cloud identity systems

Nice to have

  • Claude Code, Codex, and similar AI-assisted engineering tools
  • MCP integrations and agent-based automation workflows
  • AI-assisted detection, triage, remediation support, and documentation
  • Prompt security, model safety, and human-in-the-loop operational controls
  • Evaluating and safely operationalizing AI tooling in security environments
  • Builder mindset - creates scalable IAM systems, not one-off fixes
  • Automation-first mentality - reduces manual effort through safe automation
  • Systems thinker - connects IAM, cloud, SaaS, developer workflows, and operational risk
  • AI-forward mindset - embraces intelligent automation while applying practical security guardrails
  • Pragmatic and engineering-oriented - balances security with usability and speed
  • High ownership - operates effectively in complex, fast-moving environments
  • Strong communicator - able to explain IAM risks and solutions to engineers, IT, and leadership
  • Experience with Britive, CyberArk, SailPoint, or similar PAM/PIM platforms
  • Experience with Okta Workflows, CIEM platforms, or identity governance tooling
  • Experience with Wiz, GuardDuty, Astrix, or similar tools for identity-related investigations
  • Experience in gaming, SaaS, or multi-studio environments
  • Experience with passwordless authentication, WebAuthn, or FIDO2
  • Experience building AI-assisted workflows for IAM operations, documentation, access reviews, or investigations
  • Familiarity with AI security frameworks, governance, and safe agentic automation patterns
  • Security certifications such as CISSP, AWS Security Specialty, or relevant IAM/cloud certifications

The role

Scopely is looking for a Senior IAM Security Engineer to join our Information Security team on a remote basis or hybrid basis if located in Barcelona. This role will focus on building, scaling, and securing Scopely's identity and access management ecosystem across our cloud, SaaS, AI, and remote access environments, with a strong emphasis on Terraform-based IAM automation, access workflow engineering, least-privilege design, identity risk reduction, and AI-assisted operational workflows.

This is a highly technical, hands-on role for someone who can operate across AWS, GCP, Okta, AWS IAM Identity Center, Zero Trust access models, identity governance workflows, and modern AI-enabled engineering environments, while building scalable identity systems through Infrastructure as Code, workflow orchestration, and automation-first security engineering.

What you'll do

  • Design and evolve Scopely's IAM architecture to support a high-scale, cloud-first environment across AWS, GCP, SaaS applications, AI tooling, and remote access platforms.
  • Federated identity architecture using SAML, OIDC, OAuth, and SCIM
  • Workforce identity and access patterns across internal platforms
  • Least-privilege role design and access segmentation
  • RBAC and ABAC models for cloud and SaaS environments
  • Centralized access models using Okta, AWS IAM Identity Center, Google Cloud IAM, and cloud-native IAM services
  • Secure cross-account and cross-project access patterns
  • Service account, workload identity, and non-human identity governance
  • Zero Trust identity and access control design

Partner with engineering, infrastructure, and security teams to:

  • Standardize secure identity and access patterns
  • Reduce identity sprawl and excessive permissions
  • Improve access visibility and auditability
  • Build scalable identity controls for a fast-moving engineering environment
  • Own and improve Terraform-based IAM and access automation across Scopely's cloud and identity environment.
  • Reusable Terraform modules for IAM roles, policies, permission sets, group mappings, and access patterns
  • Terraform workflows for Okta app assignments, group-based access, and IAM Identity Center automation
  • Standardized access modules that can be reused safely across teams and environments
  • Policy-as-code patterns for least privilege and permission boundary enforcement
  • Terraform-driven onboarding and offboarding flows for identity-related systems
  • Automation for service account and workload identity provisioning
  • Access reporting and audit visibility pipelines connected to code-based IAM workflows
  • Standardization of IAM modules, variables, role definitions, and policy structures
  • Repeatability and consistency of access changes
  • Reduction of manual IAM operations
  • Auditability and change traceability
  • Safe rollout of identity changes through code review and pull request workflows
  • State management
  • Drift detection and remediation
  • Rollback planning
  • Blast-radius awareness for IAM changes
  • Safe promotion of access changes into production
  • Build scalable automation for identity lifecycle management, access requests, entitlement changes, access reviews, and day-to-day IAM operations.
  • Provisioning and deprovisioning automation
  • Access request and approval workflows
  • Group-based access assignment and role mapping
  • Okta app integration and assignment automation
  • IAM Identity Center permission set automation
  • Self-service identity workflows for internal teams
  • Identity reporting and access visibility pipelines
  • Operational tooling that reduces repetitive IAM work
  • Terraform and Infrastructure as Code workflows
  • Python, Bash, PowerShell, and APIs
  • CI/CD systems and Git-based change management
  • Okta Workflows and similar orchestration tooling
  • ServiceNow, ticketing, and operational workflow integrations
  • AI tools such as Claude Code, Codex, and similar engineering assistants
  • MCP-enabled integrations, agentic workflows, and internal automation platforms
  • Repeatability
  • Auditability
  • Operational safety
  • Reduction of manual IAM work
  • Secure-by-default access onboarding
  • Lead initiatives to reduce identity-related risk across human and non-human identities.
  • Excessive permissions and privilege escalation reduction
  • Service account and workload identity hardening
  • Long-lived credential reduction
  • Cross-account trust policy review and hardening
  • Permission boundary enforcement
  • Role lifecycle management
  • Just-in-time and time-bound privileged access
  • Break-glass access workflows
  • Identity anomaly detection and misuse investigation

Use native and third-party tooling to identify and remediate risk, including:

  • AWS IAM Access Analyzer
  • CloudTrail
  • GuardDuty
  • GCP-native IAM and audit services
  • Okta System Log and access reporting
  • CIEM, CSPM, and related cloud security platforms
  • Partner with IAM, platform, and security teams to strengthen Zero Trust and privileged access controls across Scopely's environment.
  • Twingate connectors, resources, and access policy design
  • Identity-aware remote access controls
  • Zero Trust segmentation for internal applications and privileged systems
  • Privileged access workflows
  • PAM platform integrations such as Britive
  • Adaptive access controls
  • MFA and passwordless adoption
  • Federated access into AWS, GCP, SaaS platforms, and internal tools
  • Secure vendor and contractor access patterns
  • Human identity security
  • Non-human identity security
  • Access visibility
  • Privileged session control
  • Access policy consistency across environments

Support Identity Investigations, Monitoring, and Audit Readiness

  • Partner with Security Operations, Compliance, and Infrastructure teams to improve identity monitoring, investigation, and audit readiness.
  • IAM troubleshooting runbooks
  • Identity-related detection and triage workflows
  • Access review processes
  • Permission reporting and evidence collection
  • IAM logging and monitoring design
  • Operational metrics for identity security maturity
  • Suspicious access activity
  • Identity and permission abuse
  • Misconfigured app integrations
  • Broken federation and provisioning flows
  • Risky SaaS integrations
  • Service account misuse
  • Cross-account access issues
  • SOC 2 and ISO 27001 alignment
  • Access review evidence readiness
  • Documentation of IAM controls and workflows
  • Clear traceability for privileged access and entitlement changes
  • Design and improve AI-assisted and automation-first workflows that help Scopely scale identity security safely.
  • AI-assisted access review analysis
  • AI-assisted troubleshooting and documentation support
  • Intelligent triage for identity-related findings
  • Security chatops integrations
  • Identity workflow automation using agents and orchestration systems
  • Internal copilots for IAM operations and knowledge support
  • AI-assisted recommendations for access hygiene and remediation
  • MCP-enabled identity tooling and integrations
  • Claude Code, Codex, and similar AI-assisted engineering tools
  • MCP-based workflows and agentic automation patterns
  • Internal automation platforms and workflow engines
  • APIs, event-driven automation, and identity telemetry pipelines
  • Human-in-the-loop approval controls
  • Least-privilege access to tools and data
  • Logging and auditability for AI-assisted workflows
  • Prompt and data handling safeguards
  • Clear separation between recommendations and privileged actions
  • Partner with engineering, platform, IT, and studio teams to align IAM strategy with Scopely's operational and business goals.
  • Modern IAM architecture
  • Federated identity design
  • Least-privilege engineering
  • Zero Trust access models
  • Non-human identity risk
  • IAM automation strategy
  • Terraform design patterns for identity and access management
  • Access governance in fast-growing environments
  • Secure access design for engineering teams
  • Safe use of AI in identity and access workflows
  • Adopt secure identity patterns
  • Automate IAM safely
  • Reduce reliance on manual access processes
  • Improve cloud and SaaS access consistency
  • Build scalable and maintainable identity controls
  • Identity-aware security
  • Automation-first IAM operations
  • Practical access governance
  • Engineering-driven IAM design
  • AI-assisted identity operations

Additional Info

This role is ideal for someone who is excited about building modern identity security beyond traditional approaches and wants to help Scopely scale secure access across cloud, SaaS, AI, and engineering environments. If you enjoy solving IAM challenges with Terraform, automation, reusable engineering patterns, and well-designed identity systems, we'd love to hear from you.

Please ensure that the résumé/CV you attach is written in English.

About Scopely

Scopely is a global interactive entertainment and mobile gaming company headquartered in Culver City, California. The company develops, publishes, and operates a portfolio of hit mobile games including Monopoly GO!, Star Trek Fleet Command, Marvel Strike Force, Stumble Guys, and Yahtzee with Buddies, reaching hundreds of millions of players worldwide. Scopely is known for its live-ops expertise, data-driven game design, and a culture that blends creative game development with deep analytics and technology.

Scopely has a significant presence in Spain, with a growing team of engineers, designers, producers, and corporate functions supporting its global game portfolio. The company actively hires international talent across disciplines, offering remote-friendly and hybrid roles, and its Spain-based teams work on some of the most recognizable mobile gaming franchises in the world. For international professionals, Scopely offers a fast-paced, product-led environment where data, creativity, and technology intersect, making it an attractive destination for those looking to work on globally successful consumer products.

Industry
Gaming
Founded
2011
Employees
1,000–5,000
Headquarters
Culver City, USA
In Spain
Madrid, Barcelona

Good to know if you are moving

  • Scopely is a US company, so international hires typically require a work visa sponsorship; the company has experience with global mobility and relocation support.
  • The company's Spain-based roles span game development, product, engineering, and corporate functions, offering a wide range of entry points for international professionals.
  • Scopely's culture is data-driven and product-focused, with a strong emphasis on live operations (LiveOps) — a valuable environment for professionals coming from traditional game studios.
  • The company works on globally recognized IPs (Monopoly, Star Trek, Marvel), which can be a strong resume builder for professionals in the gaming industry.
  • While the global HQ is in the US, the Spain hub is a growing and strategic part of the company's international operations, particularly for product, engineering, and creative roles.

In their own words

About the company & team

Scopely is a leading video game and global interactive entertainment company, home to many of the world's most beloved and enduring experiences, including two of the most successful mobile games of all-time "MONOPOLY GO!" and "Pokémon GO," along with "Stumble Guys," "Star Trek™ Fleet Command," "MARVEL Strike Force," "WWE Champions," the Scrabble® franchise, "Yahtzee® With Buddies," and many others. Across mobile, web, PC, and console, Scopely creates, develops, publishes, and live-operates one of the most diversified and award-winning portfolios in the games industry - bringing hundreds of millions of players together through a shared love of play.

Founded in 2011, Scopely is powered by its exceptional team - including thousands of world-class gamemakers around the globe, a distinctive tenet-driven culture, and its proprietary technology platform, Playgami. Together, these strengths have fueled Scopely's position as the #1 mobile games company in the U.S. and #2 globally, generating more than $10 billion in lifetime revenue. Whether building global sensations like "MONOPOLY GO!" from the ground up, or expanding through strategic acquisitions, including the FoxNext, GSN, and Scopely Explore games businesses - Scopely consistently delivers experiences players love today and return to for years to come.

Recognized multiple times as one of the "100 Most Influential Companies in the World" by TIME magazine and one of Fast Company's "World's Most Innovative Companies" and "Best Workplaces for Innovators," Scopely believes that video games can be a force for good - creating meaningful connections, vibrant communities, and making life better through play.

Scopely has global operations and partners across four continents in more than a dozen countries worldwide. For more information, visit: https://www.scopely.com/.

Notice to Candidates: Scopely will never request payment or financial information during the application or hiring process. Please apply only through our official website and verify that all Talent Partner communications come from an email address ending in @scopely.com.

Should you have any questions or encounter any fraudulent requests/emails/websites, please immediately contact recruiting@scopely.com. Our job applicant privacy policies are available here: California Privacy Notice and EEA/UK Privacy Notice.

Employment at Scopely is based solely on a person's merit and qualifications. Scopely does not discriminate against any employee or applicant because of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), or any other basis protected by law. We also consider qualified applicants with arrest or conviction records, consistent with applicable federal, state and local law.

All open roles at Scopely
WhatsApp

Staff Engineer, Server

Scopely1d ago
Hybrid in BarcelonaVisa SponsorNo Spanish needed
Hybrid in BarcelonaVisa SponsorNo Spanish needed
Hybrid in BarcelonaNo Spanish needed
US$1 – US$2Hybrid in BarcelonaNo Spanish needed

Senior Security Compliance Engineer

Scopely1d ago2 openings
Hybrid in BarcelonaNo Spanish needed
Hybrid in BarcelonaNo Spanish needed
Hybrid in BarcelonaVisa SponsorNo Spanish needed
Hybrid in BarcelonaNo Spanish needed
Hybrid in BarcelonaNo Spanish needed

Senior Producer

Scopely1d ago
Hybrid in BarcelonaNo Spanish needed

Engineering Manager

Scopely1d ago
Hybrid in BarcelonaNo Spanish needed
Hybrid in BarcelonaNo Spanish needed
See all 83 jobs