hirly

Rivian and Volkswagen Group Technologies

Identity & Access Management Engineer

Belgrade

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Rivian and Volkswagen Group Technologies first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

hirly's read of this role

Seniority
Mid level
Country
RS
Work mode
On-site / unstated
First seen by hirly
28 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

About Us

Rivian and Volkswagen Group Technologies is a joint venture between two industry leaders with a clear vision for automotive’s next chapter. From operating systems to zonal controllers to cloud and connectivity solutions, we’re addressing the challenges of electric vehicles through technology that will set the standards for software-defined vehicles around the world.

The road to the future is uncharted. By combining our expertise across connectivity, AI, security and more, we’ll map a new way forward. Working together, we’ll create a future that’s more connected, more intelligent, more sustainable for everyone.

Role Summary

RV Tech runs its enterprise workforce identity on a modern cloud identity platform. The IAM Engineer keeps that platform running well and makes it better every quarter. You will own the day-to-day operation of the cybersecurity identity platform — lifecycle workflows, application integrations, access policies, and identity-related incidents — and you will be the engineer who turns manual access processes into automated, auditable ones. You work closely with the IAM Architect, who owns the identity roadmap and architecture; you own execution, operational health, and continuous improvement.

This is a hands-on role on a small team with real ownership of a production identity platform.

Responsibilities

Cybersecurity Identity Operations (core)

Operate and administer the enterprise identity platform tenant: policy tuning, group and rule management, MFA and adaptive access configuration, and tenant hygiene.

Onboard and maintain SSO integrations (SAML/OIDC) and SCIM provisioning for the enterprise application portfolio; own the application integration backlog.

Build and maintain joiner/mover/leaver automation with identity workflow tooling and HR-driven provisioning; investigate and resolve lifecycle failures.

Provide L2 and L3 support for identity-related Helpdesk tickets (access issues, SSO/MFA failures, provisioning errors); resolve within SLA, drive root cause and permanent fixes, and feed recurring issues back into automation and runbooks.

Support operational and cybersecurity incidents involving identity: account compromise, suspicious authentication activity, privilege misuse, and outage response — including containment actions (session revocation, credential resets, access suspension) and post-incident evidence.

Monitor identity platform system logs and operational health; define alerts for authentication anomalies, policy drift, and integration failures.

Support stabilization and optimization of the identity platform, including retirement of legacy identity dependencies.

Access Governance

Support quarterly user access reviews (UARs) end to end: generate review populations, coordinate with application and manager reviewers, track completion, remediate revocations, and produce audit-ready access review records.

Support governance of non-human identities — service accounts, service principals, API credentials — including discovery, ownership attestation, rotation, and decommissioning.

Detect and remediate excessive privileges and risky permission combinations.

Maintain identity control evidence for the ISO 27001 / TISAX control environment; keep runbooks and integration documentation current in Confluence.

Automation & Continuous Improvement

Identify manual IAM processes and automate them using identity workflow tooling, Python/SQL, and APIs.

Contribute to identity automation and governance tooling on the enterprise data platform: attribute-driven provisioning, automated deprovisioning, and identity event pipelines into the SIEM.

Propose and implement improvements to identity controls aligned to the zero-trust roadmap (device assurance, passwordless/FIDO2, conditional access).

Qualifications

Minimum Qualifications:

Bachelor's degree in Computer Science, Information Security, Information Systems, or a related technical field (required).

3–6 years in identity and access management engineering or administration, with 1+ years hands-on operating a cloud identity platform in production.

Experience with major identity platforms, including Okta, Microsoft Entra ID, Ping Identity, or comparable workforce IdPs.

Working knowledge of SAML, OIDC, OAuth 2.0, SCIM, and directory services (Entra ID/Active Directory) in hybrid enterprise environments.

Experience building or maintaining lifecycle automation (joiner/mover/leaver) with an HR system of record.

Scripting ability in Python or PowerShell and comfort working with REST APIs and SQL.

Strong troubleshooting discipline: able to trace an access failure across HRIS, IdP, and target application and document the fix.

Clear written English; able to produce runbooks and audit evidence that a non-engineer can follow.

Ability to work an overlap of at least 3–4 hours with Pacific Time and to travel to Palo Alto once or twice per year.

Preferred Qualifications

Vendor certification on a major identity platform (e.g., Okta Certified Professional/Administrator, Microsoft Identity and Access Administrator).

Experience with identity workflow automation and IGA platforms.

Experience with PAM tooling and enterprise password managers.

Exposure to Databricks, Spark, or similar data platforms for event ingestion and processing.

SIEM integration experience for identity signals.

Experience in a TISAX, ISO 27001, or NIST-regulated environment; automotive or joint-venture context a plus.

Total Rewards

We build the exceptional — and we believe the people doing that work should be rewarded accordingly. In addition to a competitive base salary, full-time positions may be is eligible to participate in our annual company performance bonus program.

Payments are discretionary and not guaranteed; actual amounts depend on company results and the terms of the plan in effect, and require active employment at the time of payout. This role is also eligible for equity in the form of Restricted Stock Units (RSUs), subject to board approval and the terms of our equity incentive plans, including applicable vesting requirements.

In addition to our compensation programs, we invest in our people with a comprehensive benefits package designed to support the health, wellbeing, and financial future for full-time employees — including health coverage, retirement savings, time off, and family planning programs. Offerings vary by country. Learn more about our global benefit programs .

External candidates can apply for this role through the Rivian and Volkswagen Group Technologies careers site ( https://rivianvw.tech/#careers ). If you are a current employee, please apply through our internal job board .

Equal Opportunity

Rivian and Volkswagen Group Technologies is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender, gender expression, gender identity, genetic information or characteristics, physical or mental disability, marital/domestic partner status, age, military/veteran status, medical condition, or any other characteristic protected by law. We are also committed to ensuring compliance with all applicable fair employment practice laws regarding citizenship and immigration status.

Rivian and Volkswagen Group Technologies is committed to ensuring that our hiring process is accessible for persons with disabilities. If you have a disability or limitation, such as those covered by the Americans with Disabilities Act, that requires accommodations to assist you in the search and application process, please email us at [email protected].

Candidate Data Privacy

Rivian and Volkswagen Group Technologies” may collect, use and disclose your personal information or personal data (within the meaning of the applica

Original posting on Rivian and Volkswagen Group Technologies's site ↗

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job