# Principal Cloud IAM Engineer

Hiring organization: [Workday](https://career.thegoodapps.co/organizations/workday)

Canonical page: https://career.thegoodapps.co/jobs/5efd52e4-c221-45ae-9d5a-7711d957c7ca

Listed on Workday's own careers site. Applications go to them directly.

- Employment type: full time
- Seniority: Principal
- Location: Reston, VA
- Salary: 184800 – 277200 USD per year

## Summary

This role owns the strategy and architecture of Workday's Identity and Access Management systems across a complex, multi-cloud enterprise environment. You'll lead IAM decisions that shape security posture, drive cross-functional alignment, and help define emerging patterns for securing AI agents—not manage day-to-day operations.

_Our summary, not Workday's wording._

## Skills named

AWS Organizations, Okta, Security Assertion Markup Language (SAML), Terraform

## Required

- 10+ years cloud security or IAM experience
- 3+ years in senior or architect-level role with strategy ownership
- AWS IAM foundations including SCPs, Identity Center, ABAC, multi-account architecture
- Enterprise-scale Okta experience with SSO, adaptive MFA, SCIM, lifecycle management
- Deep knowledge of SAML, OIDC, OAuth2 in complex environments
- Terraform infrastructure-as-code proficiency
- Hands-on experience with AI and agentic identity including NHI lifecycle and service-to-service trust
- Zero Trust implementation in production
- Ability to drive alignment across teams without direct authority
- Experience mentoring less senior engineers

## Nice to have

- GCP familiarity
- AWS Certified Security Specialty
- Risk mitigation mindset and GRC team engagement
- AI security tooling experience such as identity-aware proxies or agent observability platforms

Apply on Workday's site: https://workday.wd5.myworkdayjobs.com/en-US/Workday/job/USAVAReston/Principal-Cloud-IAM-Engineer_JR-0106596
