Staff Identity & Access Management Engineer
- Hiring from
- Serbia
- Work type
- Hybrid
- Posted
- Sep 17, 2026
About Us
Rivian and Volkswagen Group Technologies is a joint venture between two industry leaders with a clear vision for automotive’s next chapter. From operating systems to zonal controllers to cloud and connectivity solutions, we’re addressing the challenges of electric vehicles through technology that will set the standards for software-defined vehicles around the world.
The road to the future is uncharted. By combining our expertise across connectivity, AI, security and more, we’ll map a new way forward. Working together, we’ll create a future that’s more connected, more intelligent, more sustainable for everyone.
Role Summary
RV Tech is building its enterprise identity program from the ground up, and the Staff IAM Engineer runs it. You are the directly responsible individual for the full identity program: the workforce identity platform, identity governance, privileged access, non-human identities, secrets management, and the Helpdesk operations that sit on top of all of it. You own the outcomes, the roadmap, the team, and the vendors.
This is a player-coach role. You will design and build, lead a small agile team of engineers and contractors, direct external implementation partners, and personally represent identity controls to auditors across multiple certification regimes. You will also be the person who finds a creative way through resource constraints, most often by applying AI engineering and automation where headcount is not available.
Responsibilities
Program Leadership
Serve as the directly responsible individual for the enterprise identity program across all of its pillars: workforce identity platform (IdP), identity governance and administration (IGA), privileged access management (PAM), non-human identity (NHI) governance, secrets management, and device trust.
Own the identity roadmap end to end: define priorities, sequence delivery, manage dependencies across IT, Product, and partner teams, and report status, risks, and decisions to leadership and steering committees.
Juggle multiple concurrent high-priority projects with shifting priorities; keep each one operationally successful and make explicit, defensible trade-offs when resources conflict.
Build and lead a small, agile, effective identity team: hire, develop, and set standards for full-time engineers and a contractor workforce.
Manage external implementation partners and vendors: scope statements of work, hold partners to delivery and quality commitments, control spend, and run vendor evaluations and RFPs for new identity capabilities.
Identity Platform Operations
Own operation of the enterprise workforce identity platform: tenant configuration, access policies, MFA and adaptive access, lifecycle automation, and application integrations (SSO and SCIM).
Lead identity-related Helpdesk operations: own the L2/L3 support model, SLAs, and runbooks; resolve escalations personally when needed; and eliminate recurring ticket classes through automation and self-service.
Lead the identity workstream in operational and cybersecurity incidents: direct containment (session revocation, credential resets, access suspension), produce post-incident evidence, and own identity-related corrective actions.
Define platform observability and operational KPIs: alerting on authentication anomalies, policy drift, integration failures, and lifecycle errors.
Drive stabilization and optimization of the identity platform, including retirement of legacy identity dependencies.
Access Governance & Audit
Own quarterly user access reviews (UARs) end to end: scope, reviewer coordination, completion tracking, revocation remediation, and audit-ready records.
Own identity control design and evidence for the TISAX, ISO 27001, SOC 2, and SOX control environments; serve as the primary identity point of contact for internal and external auditors across all four regimes.
Own governance of non-human identities (service accounts, service principals, API credentials, machine identities): discovery, ownership attestation, rotation, and decommissioning.
Detect and remediate excessive privileges and risky entitlements; design preventive controls so they do not recur.
Scaling & Growth
Lead the privileged access management capability: strategy, tool selection, rollout, and operating model.
Lead the enterprise secrets management program: adoption, developer workflows, and integration with the identity lifecycle.
Apply AI engineering and automation to scale the identity function: agentic investigation and remediation of access anomalies, automated evidence collection, lifecycle automation, and self-service.
Build identity data pipelines and governance tooling on the enterprise data platform, feeding identity signals into detection and response.
Required Qualifications
Bachelor's degree in Computer Science, Information Security, Information Systems, or a related technical field (required).
8+ years in identity and access management, with 3+ years as the accountable lead for a production workforce identity program or platform.
Experience building and leading a small, agile, effective team, including managing a contractor workforce and directing external implementation partners and vendors.
Deep hands-on experience with major identity platforms, including Okta, Microsoft Entra ID, Ping Identity, or comparable workforce IdPs, including tenant design, policy architecture, and lifecycle automation.
Expert knowledge of SAML, OIDC, OAuth 2.0, SCIM, and directory services (Entra ID/Active Directory) in hybrid enterprise environments.
Exemplary written and verbal communication skills, with demonstrated experience presenting identity controls and evidence directly to auditors for TISAX, ISO 27001, SOC 2, and/or SOX.
Experience leading identity-related Helpdesk or service operations (L2/L3 support model, SLAs, runbooks) and leading identity response during security incidents.
Hands-on coding experience (Python or similar) and working experience with infrastructure and data platforms such as Terraform, Databricks, AWS, and GCP.
Demonstrated ability to manage multiple concurrent high-priority projects with varying priorities, and to solve resource constraints creatively, particularly through automation and AI engineering.
Experience owning access governance processes (user access reviews, NHI governance) in a regulated environment.
Preferred Qualifications
Advanced vendor certification on a major identity platform (e.g., Okta Certified Consultant or Developer, Microsoft Identity and Access Administrator).
Experience selecting and deploying IGA, PAM, and enterprise secrets management platforms.
Experience leading an identity platform migration or consolidation.
Experience building AI-assisted or agentic security automation.
SIEM integration and detection engineering experience for identity signals.
Experience in an automotive, joint-venture, or multi-entity enterprise environment.
First 90 Days
Produce a program ownership dossier covering architecture, integrations, risks, controls, operational KPIs, team and vendor plan, and a 12-month roadmap across all identity pillars.
Total Rewards
We build the exceptional — and we believe the people doing that work should be rewarded accordingly. In addition to a competitive base salary, full-time positions may be is eligible to participate in our annual company performance bonus program.
Payments are discretionary and not guaranteed; actual amounts depend on company results and the terms of the plan in effect, and require active employment at the time of payout. This role is also eligible for equity in the form of Restricted Stock Units (RSUs), subject to board approval and the terms of our equity incentive plans, including applicable vesting requirements.
In addition to our compensation programs, we invest in our people with a comprehensive benefits package designed to support the health, wellbeing, and financial future for full-time employees — including health coverage, retirement savings, time off, and family planning programs. Offerings vary by country. Learn more about our global benefit programs.
External candidates can apply for this role through the Rivian and Volkswagen Group Technologies careers site (https://rivianvw.tech/#careers). If you are a current employee, please apply through our internal job board.
Equal Opportunity
Rivian and Volkswagen Group Technologies is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender, gender expression, gender identity, genetic information or characteristics, physical or mental disability, marital/domestic partner status, age, military/veteran status, medical condition, or any other characteristic protected by law. We are also committed to ensuring compliance with all applicable fair employment practice laws regarding citizenship and immigration status.
Rivian and Volkswagen Group Technologies is committed to ensuring that our hiring process is accessible for persons with disabilities. If you have a disability or limitation, such as those covered by the Americans with Disabilities Act, that requires accommodations to assist you in the search and application process, please email us at candidateaccommodations@rivian.com.
Candidate Data Privacy
Rivian and Volkswagen Group Technologies” may collect, use and disclose your personal information or personal data (within the meaning of the applicable data protection laws) when you apply for employment and/or participate in our recruitment processes (“Candidate Personal Data”). This data includes contact, demographic, communications, educational, professional, employment, social media/website, network/device, recruiting system usage/interaction, security and preference information. Rivian and Volkswagen Group Technologies may use your Candidate Personal Data for the purposes of (i) tracking interactions with our recruiting system; (ii) carrying out, analyzing and improving our application and recruitment process, including assessing you and your application and conducting employment, background and reference checks; (iii) establishing an employment relationship or entering into an employment contract with you; (iv) complying with our legal, regulatory and corporate governance obligations; (v) record keeping; (vi) ensuring network and information security and preventing fraud; and (vii) as otherwise required or permitted by applicable law.
Rivian and Volkswagen Group Technologies may share your Candidate Personal Data with (i) internal personnel who have a need to know such information in order to perform their duties, including individuals on our People Team, Finance, Legal, and the team(s) with the position(s) for which you are applying; (ii) Rivian and Volkswagen Group Technologies affiliates; and (iii) Rivian and Volkswagen Group Technologies’ service providers, including providers of background checks, staffing services, and cloud services.
Rivian and Volkswagen Group Technologies may transfer or store internationally your Candidate Personal Data, including to or in the United States, Canada, and the European Union and in the cloud, and this data may be subject to the laws and accessible to the courts, law enforcement and national security authorities of such jurisdictions.
If you provide a mobile telephone number as part of your application or during the recruitment process, Rivian and Volkswagen Group Technologies may use that number to contact you via SMS text message for recruitment-related purposes, including scheduling, logistics, and status updates. Message and data rates may apply. You may opt out of SMS communications at any time by replying STOP to any text message you receive from us. Consent to receive SMS messages is not a condition of applying for or being considered for employment.
Please see our Candidate Data Privacy Notice (English) and Candidate Data Privacy Notice (Serbian) for more information.
--
Please note this job posting represents an open, active vacancy. Additionally, we are not currently accepting applications from third party application services.