- Company Name
- digica
- Job Title
- Freelance Cloud IAM Security Engineer (Brussels)
- Job Description
-
Job Title: Freelance Cloud IAM Security Engineer
Role Summary:
Provide expert design, implementation, and automation of Identity and Access Management (IAM) solutions across Azure and AWS multi‑tenant environments, applying Zero Trust principles and regulatory compliance standards while supporting internal insurance fund clients.
Expectations:
- Minimum 5 years of professional experience in cloud technologies (Azure, AWS) and overarching IT security.
- At least 4 years of hands‑on experience with hybrid cloud deployments and ISO 2700x standards, including ISO 27001 and SOC 2.
- Proven expertise in IAM for Azure AD/Entra ID, AWS IAM, and GCP IAM.
- Strong knowledge of OAuth 2.0, OIDC, SAML, JWT, RBAC/ABAC/PBAC, PIM/PAM.
- Advanced scripting proficiency in PowerShell and Python, with a demonstrated automation mindset.
- Fluency in English and either French or Dutch; bilingual communication preferred.
- Ability to deliver on‑site work (minimum 2 days) and commit to long‑term engagements.
Key Responsibilities:
- Design, deploy, and maintain scalable IAM architectures on Azure and AWS across multiple tenants.
- Implement Zero Trust controls: least privilege, conditional access, MFA, and SSO.
- Develop automated provisioning, role management, and access recertification workflows using IaC tools (Terraform, Bicep, CloudFormation).
- Integrate IAM processes into CI/CD pipelines and produce scripts in Python/PowerShell.
- Manage PAM/PIM solutions and identity governance tools such as SailPoint, Saviynt, CyberArk, and BeyondTrust.
- Strengthen IAM monitoring and auditing through SIEM/SOAR and supporting security tools (IDS, IPS, firewalls).
- Ensure continuous compliance with ISO 27001, GDPR, NIST, and SOC 2 requirements.
Required Skills:
- Cloud platforms: Azure, AWS, (experience with GCP IAM).
- IAM technologies: Azure AD/Entra ID, AWS IAM, identity federations (OAuth 2.0, OIDC, SAML).
- Access control models: RBAC, ABAC, PBAC, PIM, PAM.
- Infrastructure as Code: Terraform, Bicep, CloudFormation.
- Scripting: PowerShell, Python.
- Identity governance tools: SailPoint, Saviynt, CyberArk, BeyondTrust.
- Security monitoring: SIEM, SOAR, IDS, IPS, firewall administration.
- Compliance frameworks: ISO 27001, GDPR, NIST, SOC 2.
- Languages: English + French or Dutch.
Required Education & Certifications:
- Bachelor’s degree or higher in Computer Science, Information Security, or related discipline.
- Relevant certifications: Azure Security Engineer Associate, AWS Certified Security – Specialty, or equivalent (e.g., CompTIA Security+, CISSP, CISM, or similar).