IAM Engineer managing Identity & Access Management capabilities at Luminor Group. Drive secure access, compliance, and automation across hybrid environments in the banking sector.
Responsibilities
Implement and operate IAM solutions across the IAM stack, including identity lifecycle management (Joiner/Mover/Leaver), access request workflows, and governance controls.
Engineer secure access controls using least privilege, need‑to‑know, and segregation of duties principles; support recertification and access assurance activities with solid evidence trails.
Manage cloud identity controls in Microsoft Entra ID / Azure AD, including Conditional Access, identity protection, role management, and troubleshooting access issues.
Support application onboarding for SSO, ensuring integrations follow secure authentication/authorization standards (e.g., SAML/OAuth/OIDC) and meet security requirements.
Work with IGA capabilities (including platforms such as IBM Security Verify Governance) to onboard/offboard applications, model entitlements/access profiles, and maintain reporting for audits and stakeholders.
Operate and improve Active Directory fundamentals (GPO/LDAP/domain controllers), hygiene and remediation initiatives, and monitoring practices.
Automate repetitive tasks and improve reliability using scripting (PowerShell/Python) and API‑driven integrations, contributing to a more efficient IAM “as‑a‑service” model.
Contribute to incident/change handling and cross‑team collaboration (Security Engineering, Platform, Network, application owners), including clear documentation and reporting.
Requirements
Experience: 3+ years (or strong equivalent) implementing and/or operating IAM in an enterprise environment (regulated industry experience is a strong plus).
Core IAM knowledge: SSO, MFA, access governance concepts (JML, approvals, recertification, SoD), and practical understanding of how to make IAM controls auditable and repeatable.
Strong understanding for the RBAC and ABAC models.
Protocols & standards: hands‑on familiarity with authentication/authorization standards such as SAML and OAuth (OIDC knowledge is a plus).
Cloud identity: experience with Azure AD / Entra ID (Conditional Access, identity protection, roles, app integrations).
Directory services: solid fundamentals in Active Directory (GPO, LDAP, domain controllers, operational hygiene).
Automation mindset: scripting (PowerShell and/or Python) and comfort working with APIs and structured data to streamline IAM operations.
Collaboration & communication: strong English and the ability to work effectively with multiple stakeholders (Security, IT, platform teams, system owners).
Nice to have : Experience with IGA platforms (e.g., IBM Security Verify Governance, SailPoint, Okta, etc. ) and entitlement/access model design.
AWS IAM experience (roles/policies/federation patterns) in hybrid identity architectures.
DevOps/IaC familiarity (GitLab, CI/CD, Terraform) and knowledge of how to embed IAM controls into delivery and operations workflows.
Flexibility. Flexible working hours, Hybrid work, and the possibility to work from anywhere in the EU, Iceland, Switzerland, and the UK (in total 90 days per year).
International teams. Teams that go outside Pan-Baltic borders, where people value challenging work together with good humor and having fun.
More vacation. Additional weeks of vacation are available to all employees who have been in the company for 1 year or more.
Volunteer time off. We care about giving back to society, therefore, you will get additional days off for volunteering purposes.
Paid leave. We are proud of our employees who are participating in military training. Therefore, Luminor offers 30 fully paid calendar days for military training every year.
Health benefits. A competitive benefits package in addition to your salary that includes health insurance after the first 3 months pass in all three Baltic states, as well as Health days in case of your absence due to sickness without a doctor's note needed.
Wellbeing. Access to tools and resources that help you feel good and be productive at work and in life.
Professional growth. Internal and external training programs, workshops, conferences, online training, etc.
Special Offer for Luminor products & services. Enjoy special offers & pricing for products and services provided by Luminor.
Project Development Engineer Intern supporting automation projects with Repair Engineering Groups at Teradyne. Collaborating on ongoing projects and developing engineering tools in Costa Rica.
Manufacturing Engineer I at Crown Equipment Corporation supporting process technology and implementing improvements based on engineering analysis. Collaborating on product introductions and fielding production issues.
(Senior) Cloud Consultant & Engineer at Wavestone helping clients with cloud strategies and solutions. Engaging in projects with modern technologies in a hybrid working environment.
Senior Digital Rail Solutions Engineer at Hitachi Rail involved in developing digital tools for railway operators. Bridging the gap between maintenance needs and software solutions with a hands - on approach.
Secondary Engineer designing and implementing control systems for high voltage substations at Hitachi Energy. Enhancing engineering skills in office and on - site across Norway.
Substation Engineer overseeing document turnover and file management for substations in renewable energy. Coordinating with engineers and ensuring regulatory compliance across projects.
Identity Provider Engineer specializing in IAM at Booz Allen. Supporting clients with large - scale IAM projects and implementing enterprise - class solutions.
Lead Engineer managing rail signalling and control systems at Transport for NSW. Overseeing teams, ensuring safety and compliance in rail transport infrastructure in a hybrid - friendly role.