Rivian and Volkswagen Group Technologies
Staff Identity & Access Management Engineer
Belgrade
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Lead / management
- Country
- RS
- Work mode
- On-site / unstated
- First seen by hirly
- 28 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
About Us
Rivian and Volkswagen Group Technologies is a joint venture between two industry leaders with a clear vision for automotive’s next chapter. From operating systems to zonal controllers to cloud and connectivity solutions, we’re addressing the challenges of electric vehicles through technology that will set the standards for software-defined vehicles around the world.
The road to the future is uncharted. By combining our expertise across connectivity, AI, security and more, we’ll map a new way forward. Working together, we’ll create a future that’s more connected, more intelligent, more sustainable for everyone.
Role Summary
RV Tech is building its enterprise identity program from the ground up, and the Staff IAM Engineer runs it. You are the directly responsible individual for the full identity program: the workforce identity platform, identity governance, privileged access, non-human identities, secrets management, and the Helpdesk operations that sit on top of all of it. You own the outcomes, the roadmap, the team, and the vendors.
This is a player-coach role. You will design and build, lead a small agile team of engineers and contractors, direct external implementation partners, and personally represent identity controls to auditors across multiple certification regimes. You will also be the person who finds a creative way through resource constraints, most often by applying AI engineering and automation where headcount is not available.
Responsibilities
Program Leadership
Serve as the directly responsible individual for the enterprise identity program across all of its pillars: workforce identity platform (IdP), identity governance and administration (IGA), privileged access management (PAM), non-human identity (NHI) governance, secrets management, and device trust.
Own the identity roadmap end to end: define priorities, sequence delivery, manage dependencies across IT, Product, and partner teams, and report status, risks, and decisions to leadership and steering committees.
Juggle multiple concurrent high-priority projects with shifting priorities; keep each one operationally successful and make explicit, defensible trade-offs when resources conflict.
Build and lead a small, agile, effective identity team: hire, develop, and set standards for full-time engineers and a contractor workforce.
Manage external implementation partners and vendors: scope statements of work, hold partners to delivery and quality commitments, control spend, and run vendor evaluations and RFPs for new identity capabilities.
Identity Platform Operations
Own operation of the enterprise workforce identity platform: tenant configuration, access policies, MFA and adaptive access, lifecycle automation, and application integrations (SSO and SCIM).
Lead identity-related Helpdesk operations: own the L2/L3 support model, SLAs, and runbooks; resolve escalations personally when needed; and eliminate recurring ticket classes through automation and self-service.
Lead the identity workstream in operational and cybersecurity incidents: direct containment (session revocation, credential resets, access suspension), produce post-incident evidence, and own identity-related corrective actions.
Define platform observability and operational KPIs: alerting on authentication anomalies, policy drift, integration failures, and lifecycle errors.
Drive stabilization and optimization of the identity platform, including retirement of legacy identity dependencies.
Access Governance & Audit
Own quarterly user access reviews (UARs) end to end: scope, reviewer coordination, completion tracking, revocation remediation, and audit-ready records.
Own identity control design and evidence for the TISAX, ISO 27001, SOC 2, and SOX control environments; serve as the primary identity point of contact for internal and external auditors across all four regimes.
Own governance of non-human identities (service accounts, service principals, API credentials, machine identities): discovery, ownership attestation, rotation, and decommissioning.
Detect and remediate excessive privileges and risky entitlements; design preventive controls so they do not recur.
Scaling & Growth
Lead the privileged access management capability: strategy, tool selection, rollout, and operating model.
Lead the enterprise secrets management program: adoption, developer workflows, and integration with the identity lifecycle.
Apply AI engineering and automation to scale the identity function: agentic investigation and remediation of access anomalies, automated evidence collection, lifecycle automation, and self-service.
Build identity data pipelines and governance tooling on the enterprise data platform, feeding identity signals into detection and response.
Required Qualifications
Bachelor's degree in Computer Science, Information Security, Information Systems, or a related technical field (required).
8+ years in identity and access management, with 3+ years as the accountable lead for a production workforce identity program or platform.
Experience building and leading a small, agile, effective team, including managing a contractor workforce and directing external implementation partners and vendors.
Deep hands-on experience with major identity platforms, including Okta, Microsoft Entra ID, Ping Identity, or comparable workforce IdPs, including tenant design, policy architecture, and lifecycle automation.
Expert knowledge of SAML, OIDC, OAuth 2.0, SCIM, and directory services (Entra ID/Active Directory) in hybrid enterprise environments.
Exemplary written and verbal communication skills, with demonstrated experience presenting identity controls and evidence directly to auditors for TISAX, ISO 27001, SOC 2, and/or SOX.
Experience leading identity-related Helpdesk or service operations (L2/L3 support model, SLAs, runbooks) and leading identity response during security incidents.
Hands-on coding experience (Python or similar) and working experience with infrastructure and data platforms such as Terraform, Databricks, AWS, and GCP.
Demonstrated ability to manage multiple concurrent high-priority projects with varying priorities, and to solve resource constraints creatively, particularly through automation and AI engineering.
Experience owning access governance processes (user access reviews, NHI governance) in a regulated environment.
Preferred Qualifications
Advanced vendor certification on a major identity platform (e.g., Okta Certified Consultant or Developer, Microsoft Identity and Access Administrator).
Experience selecting and deploying IGA, PAM, and enterprise secrets management platforms.
Experience leading an identity platform migration or consolidation.
Experience building AI-assisted or agentic security automation.
SIEM integration and detection engineering experience for identity signals.
Experience in an automotive, joint-venture, or multi-entity enterprise environment.
First 90 Days
Produce a program ownership dossier covering architecture, integrations, risks, controls, operational KPIs, team and vendor plan, and a 12-month roadmap across all identity pillars.
Total Rewards
We build the exceptional — and we believe the people doing that work should be rewarded accordingly. In addition to a competitive base salary, full-time positions may be is eligible to participate in our annual company performance bonus program.
Payments are discretionary and not guaranteed; actual amounts depend on company results and the terms of the plan in effect, and require active employment at the time of payout. This role is also eligible for equity in the form of Restricted Stock Units (RSUs), subject to board approval and the terms of our equity incentive plans, including applicable vesting requirements.
In addition to our compensation programs, we invest in our people with a comprehensive benefits package designed to support the
Similar jobs
- Staff Risk Management EngineerAbbott · United States - Minnesota - St. PaulFirst seen today
- Staff Risk Management EngineerAbbott · United States - Minnesota - St. PaulFirst seen today
- Principal Configuration Management EngineerAg · BelfastFirst seen today
- Identity Access Management EngineerBDO USA Experienced · Columbus, OH, United StatesFirst seen today
- Senior Endpoint Management Engineer (Intune)Fmr · Durham, NCFirst seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job