At Capgemini Engineering, the world leader in engineering services, we bring together a global team of engineers, scientists, and architects to help the world’s most innovative companies unleash their potential. From autonomous cars to life-saving robots, our digital and software technology experts think outside the box as they provide unique R&D and engineering services across all industries. Join us for a career full of opportunities. Where you can make a difference. Where no two days are the same.
Your Role
IAM & Security Architecture
- Design identity and access architectures based on modern standards (OIDC, OAuth2 + Token Exchange, SAML).
- Architect and operate IAM systems across multi cloud and hybrid environments.
- Implement cloud native workload identity mechanisms (AWS IRSA, Azure Workload Identity, GKE Workload Identity).
- Design and deploy ReBAC (Relationship Based Access Control) using OpenFGA, Authzed, or Zanzibar inspired models.
- Define security controls and compliance measures aligned with SecNumCloud, NIS2, GDPR, and Zero Trust frameworks.
Cloud Architecture
- Design secure by design cloud architectures across at least two hyperscalers (AWS, Azure, GCP).
- Develop cloud standards (landing zones, network patterns, IAM guardrails) for critical workloads.
- Support engineering teams in implementing native cloud identity and security features.
Infrastructure as Code (IaC)
- Develop and maintain Terraform and/or Crossplane modules to automate IAM and security policies.
- Integrate IaC pipelines with policy-as-code controls (OPA, Conftest, Rego).
Enterprise Architecture & Integration
- Produce end to end blueprints for authentication and authorization flows across internal and external systems.
- Define integration patterns leveraging API Gateways and federated identity standards.
- Ensure architectural alignment with enterprise principles, integration standards, and security controls.
Governance & Adoption
- Lead architectural reviews, ensuring compliance with security and cloud governance standards.
- Promote IAM and Zero Trust best practices across the organization.
- Act as a strategic advisor to engineering, cybersecurity, and product teams.