Why This Role Stands Out
This hybrid role offers a fantastic opportunity to deepen your expertise in cloud security and identity management, directly impacting an organization's Zero Trust initiatives and AWS environment. You'll thrive here if you're a proactive engineer eager to implement, automate, and operationalize cutting-edge security solutions, making this an exciting step in your career development.
Quick Overview
Job Description
Sofitex Talent Recruitment Fort d'une expérience de plus de 30 ans dans les Ressources Humaines, Sofitex est un réseau international de Travail Temporaire et de Placement en CDI. Sofitex fonde sa dynamique et son succès sur le professionnalisme de ses équipes, sa forte réactivité et sa proximité.
POSTE
For our client located in Luxembourg-City, we are currently looking for an
Cloud Security & IAM Engineer
The role will focus on strengthening cloud identity governance, privileged access management and Zero Trust access controls across the AWS environment.
The engineer will work closely with Platform, Workplace Technology and Security teams to improve the security, scalability and maintainability of the organisation's cloud-native access model.
This is a hands-on engineering role with a strong focus on implementation, operationalisation, and automation rather than governance-only activities.
Main responsibilities
Identity & Access Management
? Support the migration of AWS account federation from Microsoft Entra ID toward Okta.
? Review and redesign AWS IAM roles, permissions, and trust relationships.
? Improve IAM governance, role hygiene, and access standardisation across AWS environments.
Privileged Access Management (PAM/JIT)
? Support the implementation of PAM and Just-In-Time (JIT) access capabilities leveraging Okta.
? Define and implement privileged access governance controls for cloud administration and sensitive systems.
? Improve traceability, monitoring, and operational controls around privileged access paths.
Zero Trust & Network Security
? Review and clean existing Netskope ZTNA configurations.
? Remove wildcard access configurations and dormant rules.
? Standardise access policies and strengthen Zero Trust governance.
? Improve long-term maintainability and policy enforcement processes.
Security Engineering & Automation
? Work closely with Platform teams to automate and operationalise cloud security controls.
? Contribute to infrastructure-as-code and policy-as-code approaches where relevant.
? Support implementation of sustainable security guardrails to reduce future operational overhead.
PROFIL
Requirements
? Strong hands-on AWS security and IAM experience.
? Experience with Okta, SAML/OIDC federation and cloud identity models.
? Experience with privileged access management concepts and cloud-native access governance.
? Good understanding of Zero Trust Network Access (ZTNA) concepts.
? Experience with Netskope or equivalent ZTNA technologies.
? Experience working in cloud-native and infrastructure-as-code environments.
? Ability to work cross-functionally with Security, Platform and Engineering teams.
? Terraform experience
Nice to have
? Experience with cloud compliance or regulated environments.
? Knowledge of DORA, PCI DSS or financial-sector security expectations.
? Experience with policy-as-code or cloud governance tooling.
Contract
? Consulting role, to be filled ASAP
? Contract until end of 2026
? Daily rate : 500-750EUR
Similar jobs
- PL
Cloud Consultant
Proximus Luxembourg
Bertrange🇱🇺Hybrid5 days ago5GMachine LearningAzure+4 - CA
IT Cloud Architect
Cargolux Airlines International SA
Luxembourg🇱🇺Hybrid1 week agoEncryptionAzureGDPR+1Technology - AG
Senior Elasticsearch & Cloud Engineer (m/f)
ARHS Group Part of Accenture
Belvaux, Esch-sur-Alzette🇱🇺On-site2 weeks agoDockerMicroservicesOracle+21Technology - RG
Cloud Architect (m/f)
RTL Group / BCE
Luxembourg🇱🇺Hybrid6 weeks agoAWSActive DirectoryAgile+2Technology - CL
Azure Cloud Engineer (M/F)
CLdN
Luxembourg🇱🇺Hybrid6 weeks agoMFAAzurePowerShell+1Technology - EX
Cloud Engineer (m/f)
Experis
Hesperange🇱🇺Hybrid6 weeks agoGCPAWSAnsible+4Technology