Senior IAM Engineer

Madrid, Spain·Security·Full-time·Added 21 days ago

What they offer

  • Full-time hours

    Per the ad.

What they ask for

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Work in English

    English is required, per the ad.

  • Work on-site in Madrid

    No relocation package mentioned.

  • Have senior-level experience

    Senior-level role.

About the job


Are you ready to unlock your potential?

At Straumann Group we're on an exciting journey of growth, innovation, and impact - driven by our mission to improve oral health and transform millions of lives worldwide. United by purpose, we bring our best selves to work every day, embracing a high-performance, player-learner culture that inspires collaboration, curiosity, and ambition. Here, you'll have the opportunity to take charge of your own career, harnessing your skills, passion, and enthusiasm for learning to continually grow and progress. Together, we're not just shaping brighter smiles, we're unlocking the potential of people everywhere, including our own.

Introduction

As Product Owner PAM, you will play a key role in shaping and advancing Straumann Group's enterprise Privileged Access Management (PAM) capabilities. Working within the Global Identity & Access Services team, you will lead the evolution of PAM services while helping strengthen broader Identity and Access Management (IAM) governance, operations, and automation initiatives.

This position combines technical leadership, product ownership, and hands-on engineering. You will collaborate with security, infrastructure, cloud, and business stakeholders to deliver scalable, secure, and future-ready identity solutions that support our global business and cybersecurity objectives.

Your Role

As Product Owner PAM, you will:

  • Own and evolve the enterprise PAM platform, defining priorities, roadmap initiatives, and service improvements.
  • Design, implement, and maintain secure, scalable privileged access solutions.
  • Lead initiatives related to privileged account onboarding, credential vaulting, credential rotation, session monitoring, and privileged access workflows.
  • Drive the adoption of Just-in-Time (JIT) access and Just-Enough Administration (JEA) principles.
  • Collaborate with security, infrastructure, and cloud teams to integrate PAM capabilities across enterprise systems and platforms.
  • Support Identity Governance & Administration (IGA) processes and contribute to the continuous improvement of IAM services.
  • Promote automation and Infrastructure-as-Code approaches for IAM service delivery and configuration management.
  • Maintain architecture standards, technical documentation, and operational procedures.
  • Support audit, compliance, and risk management activities related to identity security and privileged access.
  • Monitor industry developments and recommend improvements that strengthen identity security and operational effectiveness.

Your Profile

Essential

  • Degree in Computer Science, Information Security, or a related discipline, or equivalent professional experience.
  • Experience in Identity & Access Management (IAM) engineering.
  • Hands-on expertise with Privileged Access Management (PAM) solutions and practices, such as CyberArk or BeyondTrust
  • Knowledge of Identity Governance & Administration (IGA) concepts and processes.
  • Understanding of privileged access controls, identity lifecycle management, access certification, role-based access control (RBAC), and segregation of duties (SoD).
  • Experience collaborating with cross-functional stakeholders across technical and business functions.
  • Familiarity with security and compliance frameworks such as NIST or ISO 27001.
  • Strong communication skills, with the ability to explain technical concepts to diverse audiences.

Nice to Have

  • Experience acting as a technical lead or product owner for PAM services.
  • Relevant certifications in IAM, PAM, IGA, CISSP, CISM, or related areas.
  • Experience with non-human identities, service principals, workload identities, or emerging AI-driven identity use cases.
  • Experience implementing automation and code-based approaches within IAM environments.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or disability


How they hire

2 steps1 interviewa task to do
  1. Application

  2. Review · With a Talent Acquisition Advisor

  3. Interview

    Structured, competency-based interview covering prior projects, behavioural and situational questions, skills and achievements; time, format and interviewer are confirmed beforehand.

  4. Assessment

    Not every role

    Used for some roles, typically intern/graduate, sales, operations, management and leadership.

  5. Offer · With a Talent Acquisition Advisor

  • Interview format (video, phone or onsite) and who you will meet are confirmed in advance.
  • Review timing varies with application volume; some roles are reviewed only after the closing date.
WhatsApp