Cloud IAM Specialist
1 tydzień temu
Hi, we are Vodeno. We are innovators in the Banking-as-a-Service space. Our technology is cloud-native, and our teams work in the cloud like fish in water. Supported by a leading global equity firm and the ecosystem of nearly 90 partners, our Platform opens new opportunities for businesses across Europe to integrate financial products and services into their solutions.
As part of the UniCredit Group, Aion Bank and Vodeno will accelerate their digital banking offer in strategic markets and will act as a sandbox for innovation for the wider UniCredit Group.
Based on financial sector know-how and expertise in cloud technology, we provide a set-up of customer-facing and daily banking services which include: digital onboarding, accounts, cards, payments, and lending with a white-label mobile app channel access.
We are defined by the following values:
- Client at the centre - we deliver value to our clients
- Curiosity - we want to know more
- Accountability - we deliver on our promises
- Collaboration - we can achieve more with others
Role Summary
The Cloud IAM Specialist ensures secure and compliant access management across all cloud environments in the bank. The role is essential for safeguarding workloads in GCP, managing service accounts, automating access workflows, and ensuring compliance with regulatory and internal security standards.
Role Purpose
The Cloud IAM Specialist is responsible for managing access rights within Google Cloud Platform (GCP) and Google Workspace, ensuring compliance with the principle of least privilege, internal security policies, and regulatory requirements (DORA, EBA, KNF).This role is critical for protecting banking systems in the cloud, controlling service accounts, and automating access provisioning and deprovisioning.
Key Responsibilities1. IAM Management in GCP and Google Workspace
Maintain and enforce the least privilege principle across all environments.
Design, implement, and review GCP IAM roles (predefined roles, custom roles).
Perform regular access reviews and recertifications (users, groups, service accounts).
Review and manage service account permissions, keys, and their rotation.
Monitor IAM policy changes via Audit Logs and Cloud Asset Inventory.
Build automation tools to support:
granting and removing access,
mass permission updates,
compliance reporting,
API-driven IAM workflows (Cloud Functions, Workflows, IAM API).
Develop scripts to validate and enforce IAM policies at scale.
3. Security Monitoring and Control
Identify permission risks, overprivileged accounts, and misconfigurations.
Use tools such as IAM Recommender, Policy Analyzer, SCC.
Support incident investigations related to access violations.
Ensure compliance with:
SSO
SAML
OAuth 2.0
JWT
Zero Trust access
Provide access reports and evidence for internal and external audits (DORA, KNF, internal audit).
Document IAM processes, controls, and exceptions.
Participate in architecture and risk assessments related to cloud security.
Work closely with DevOps, Data, Platform Engineering, Workspace Admin, and Security Operations.
Advise teams on IAM best practices for new services and migrations.
Support secure design of access models for GCP workloads and Google Workspace integrations.
Strong hands-on experience with GCP IAM (roles, permissions, service accounts, bindings).
Proven experience managing access controls in cloud environments.
Programming skills in Python, Shell and Google Apps Script.
Working experience with Git and repository platforms (GitHub, GitLab, Bitbucket).
Experience in Infrastructure as Code (IaC)
Working experience with JIRA & Confluence
Good understanding of Google Workspace Admin (groups, OUs, directory, policies).
Knowledge of identity and authentication standards:
SSO,
SAML,
OAuth 2.0,
JWT.
Solid understanding of least privilege, zero trust, and cloud security best practices.
Be familiar with GitOps Approach
Experience with Cloud Identity or GCP Identity Platform.
Experience with automation IAM Processes
Certifications such as:
Google Cloud Security Engineer
Google Cloud Professional Engineer
GIAC Cloud Security
CompTIA Security+
Experience working in financial or regulated environments.
Soft Skills
High attention to detail and analytical mindset.
Strong sense of ownership and accountability.
Strong prioritization & troubleshooting skills
Ability to work in a regulated environment with audit exposure.
Effective communication with technical and non-technical stakeholders.
Problem-solving approach and willingness to challenge poor access practices.
You will get an opportunity to work in an innovative, digital bank applying state of the art approaches and technologies.
You will be provided an Individual Development Budget, dedicated to enhancing your professional skills.
If your role permits, we also offer flexible work location.
You and your closest family will be covered with VIP-level private medical care which includes dental treatment and a hospitalisation package.
We care for our colleagues' well being, therefore we cover psychological consultations if you ever feel you need such support.
Aion bank account without fee.
We co-sponsor your Multisport card and cover 50% of its cost.
You will work on computer equipment that delivers the best user experience — Apple MacBook.
Our office in Warsaw offers healthy snacks throughout the day.
We keep our recruiting process simple.
Step 1: Talk with one of our Recruiters about your experience and ambitions
Step 2: Meet with your future team manager for a technical interview
Step 3: Meet with Line Manager to discuss how we fit each other
Diverse teams really are the best teams. Research shows that some candidates may hesitate to apply for a job unless they meet every requirement. If you are excited about working with us, we encourage you to apply - even if you're not 100% sure. We are interested in getting to know you and learning about what you bring to the table.
Please note that we may close a job posting early if we receive a large number of exceptional applications.
Good luck
You can contact us at and we will be more than happy to help.
-
Cloud IAM Specialist
1 tydzień temu
Warszawa, Mazovia, Polska Vodeno Pełny etatWhat we doHi, we are Vodeno. We are innovators in the Banking-as-a-Service space. Our technology is cloud-native, and our teams work in the cloud like fish in water. Supported by a leading global equity firm and the ecosystem of nearly 90 partners, our Platform opens new opportunities for businesses across Europe to integrate financial products and services...
-
IBM Cloud Security Engineer
2 dni temu
Warszawa, Mazovia, Polska Ness Solution Pełny etatIBM Cloud Security Engineer – Mid-Level SzukamyIBM Cloud Security Engineera (Mid), który wzmocni nasze zespoły bezpieczeństwa w obszarze monitorowania, ochrony danych i reagowania na incydenty w środowiskach chmurowych oraz hybrydowych. Jeśli dobrze czujesz się w SIEM,automatyzacji i pracy projektowej — zapraszamy Elastyczna forma współpracy,...
-
Senior IAM Automation Engineer
5 dni temu
Warszawa, Mazovia, Polska HelloFresh Pełny etatJoin our R&D Tech Hub in Warsaw HelloFresh Group, the world's leading integrated food solutions provider, is expanding with a new R&D Tech office in Poland. With brands offering meal kits, ready-to-eat meals, and specialty products such as meat, seafood, and pet food, we are seeking individuals who are ready to make an impact from day one. Joining us in...
-
Cloud Engineer
1 tydzień temu
Warszawa, Mazovia, Polska Axiom Software Solutions Limited Pełny etatJD : a Designing, deploying, and maintaining AWS cloud-based infrastructure using CDKb Building reusable cdk pattern for AWS infrastructurec collaborate with cloud architects to ensure cloud security standardsd collaborate with dev teams and support to build the aws infrastructure and deployment supporte Analyze existing business requirements and provide...
-
Cloud Identity Systems
6 dni temu
Warszawa, Mazovia, Polska PTT Consulting Pełny etatYears of experience10+LanguageEnglishType of workFull-time, RemoteWe are looking for a senior-level engineer to design, implement, and govern enterprise identity and security solutions across Global Lottery Technology's multi-cloud environments. The role requires deep expertise in Microsoft Entra ID, leadership in identity initiatives, and a strong focus on...
-
DevOps / Cloud Engineer
1 tydzień temu
Warszawa, Mazovia, Polska ALGOTEQUE Innovation Hub Pełny etatALGOTEQUE to firma doradcza IT, która wspiera startupy, średnie i duże przedsiębiorstwa w tworzeniu i wdrażaniu innowacyjnych technologii. Nasz zespół ma udokumentowane sukcesy w projektowaniu, rozwijaniu, wdrażaniu i integracji rozwiązań programistycznych (AI, ML, BI, Web, Automatyzacja) dla branż takich jak telekomunikacja, energetyka,...
-
Cloud Engineer
5 dni temu
Warszawa, Mazovia, Polska Samba TV Pełny etatSamba TV tracks streaming and broadcast video across the world with our proprietary data and technology. We are on a mission to fundamentally transform the viewing experience for everyone. Our data enables media companies to connect with audiences for new shows and movies, and enables advertisers to engage viewers and measure reach across all their devices....
-
Cloud Engineer
6 dni temu
Warszawa, Mazovia, Polska Samba TV Pełny etat 290 000 zł - 350 000 złSamba TV tracks streaming and broadcast video across the world with our proprietary data and technology. We are on a mission to fundamentally transform the viewing experience for everyone. Our data enables media companies to connect with audiences for new shows and movies, and enables advertisers to engage viewers and measure reach across all their devices....
-
L3 Cloud Engineer
2 tygodni temu
Warszawa, Mazovia, Polska Response Informatics Pełny etatRole:L3 Cloud EngineerWork Mode:Remote work with occasional visit to office on a need basisOvertime Support:Required on-call supportevery 3 weeksJob DescriptionWe are seeking an experiencedL3 / Cloud Engineerto support and oversee complex cloud infrastructure environments with a primary focus onMicrosoft Azure (95%)and limited workloads onAWS (5%). The role...
-
Presales Cloud Engineer
2 tygodni temu
Warszawa, Mazovia, Polska B2B S.A Pełny etatWspierasz procesy sprzedażowe w obszarze chmury i infrastruktury hybrydowej, łącząc kompetencje techniczne z umiejętnościami doradczymi. Twoją misją jest przełożenie potrzeb biznesowych klienta na spójne rozwiązania cloudowe – zorientowane na skalowalność, bezpieczeństwo i efektywność kosztową.Presales Cloud EngineerTwój zakres...