IAM Engineer (Identity & Access Management) at Luminor Group. Implementing IAM solutions and managing identity lifecycle in hybrid environments.
Responsibilities
Implement and operate IAM solutions across the IAM stack, including identity lifecycle management (Joiner/Mover/Leaver), access request workflows, and governance controls.
Engineer secure access controls using least privilege, need‑to‑know, and segregation of duties principles; support recertification and access assurance activities with solid evidence trails.
Manage cloud identity controls in Microsoft Entra ID / Azure AD, including Conditional Access, identity protection, role management, and troubleshooting access issues.
Support application onboarding for SSO, ensuring integrations follow secure authentication/authorization standards (e.g., SAML/OAuth/OIDC) and meet security requirements.
Work with IGA capabilities (including platforms such as IBM Security Verify Governance) to onboard/offboard applications, model entitlements/access profiles, and maintain reporting for audits and stakeholders.
Operate and improve Active Directory fundamentals (GPO/LDAP/domain controllers), hygiene and remediation initiatives, and monitoring practices.
Automate repetitive tasks and improve reliability using scripting (PowerShell/Python) and API‑driven integrations, contributing to a more efficient IAM “as‑a‑service” model.
Contribute to incident/change handling and cross‑team collaboration (Security Engineering, Platform, Network, application owners), including clear documentation and reporting.
Requirements
3+ years (or strong equivalent) implementing and/or operating IAM in an enterprise environment (regulated industry experience is a strong plus).
Core IAM knowledge: SSO, MFA, access governance concepts (JML, approvals, recertification, SoD), and practical understanding of how to make IAM controls auditable and repeatable.
Strong understanding for the RBAC and ABAC models.
Protocols & standards: hands-on familiarity with authentication/authorization standards such as SAML and OAuth (OIDC knowledge is a plus).
Cloud identity: experience with Azure AD / Entra ID (Conditional Access, identity protection, roles, app integrations).
Directory services: solid fundamentals in Active Directory (GPO, LDAP, domain controllers, operational hygiene).
Automation mindset: scripting (PowerShell and/or Python) and comfort working with APIs and structured data to streamline IAM operations.
Collaboration & communication: strong English and the ability to work effectively with multiple stakeholders (Security, IT, platform teams, system owners).
Benefits
Flexibility. Flexible working hours, Hybrid work, and the possibility to work from anywhere in the EU, Iceland, Switzerland, and the UK (in total 90 days per year).
International teams. Teams that go outside Pan-Baltic borders, where people value challenging work together with good humor and having fun.
More vacation. Additional weeks of vacation are available to all employees who have been in the company for 1 year or more.
Volunteer time off. We care about giving back to society, therefore, you will get additional days off for volunteering purposes.
Paid leave. We are proud of our employees who are participating in military training. Therefore, Luminor offers 30 fully paid calendar days for military training every year.
Health benefits. A competitive benefits package in addition to your salary that includes health insurance after the first 3 months pass in all three Baltic states, as well as Health days in case of your absence due to sickness without a doctor's note needed.
Wellbeing. Access to tools and resources that help you feel good and be productive at work and in life.
Professional growth. Internal and external training programs, workshops, conferences, online training, etc.
Special Offer for Luminor products & services. Enjoy special offers & pricing for products and services provided by Luminor.
AC5 Chief Engineer leading technical direction for Boeing's Phantom Works. Directing engineering personnel for advanced communications, computing, and command control technologies.
Deep Learning Compiler Engineer at NVIDIA developing optimizations for deep learning models and GPUs. Collaborating with cross - functional teams and enhancing the next generation of AI technology.
Sr Insider Threat Engineer at PayPal applying security best practices in a global commerce platform. Enhancing systems security and collaborating with teams for strategic initiatives.
Senior Technical Leader for enterprise virtualization platform at ComPsych. Leading virtualization engineers, guiding design decisions, and managing infrastructure initiatives.
Cybersecurity Engineer providing application - level administration of forensic tools and systems at GDIT. Focused on maintaining and enhancing cybersecurity operations for federal customers.
Cybersecurity Engineer maintaining and enhancing digital forensic and cybersecurity toolsets for critical systems. Ensuring compliance while supporting the application - level administration for federal agency requirements.
Senior Client Engineer enhancing construction projects with data - driven technology from nPlan. Focus on client relationships and maximizing product value in the construction industry.
Standards Engineer responsible for designing, updating, and communicating engineering standards at Liberty, impacting energy and water solutions. Collaborate across departments to ensure compliance and provide training.
Mechanical Engineer performing design and analysis for nuclear power plant components at Westinghouse Electric Company. Evaluating equipment with ASME Code and supporting fabrication processes.
Senior Safety Engineer supporting Nuclear safety case development for submarine defueling and dismantling. Requires engineering degree and knowledge in nuclear safety.