Summary
Growe is seeking an Access Engineer & IAM Auditor to build and operate standardized, risk-based access audit processes across a complex, multi-system environment. The role audits GCP IAM, LDAP, PAM, and IGA tools, prepares audit-ready evidence, tracks remediation actions, and continuously improves audit methodologies and documentation.
Responsibilities
- Design and implement a standardized access audit process from scratch - methodology, cadence, evidence collection, and reporting templates
- Define risk-based audit scope and sampling methodology appropriate for a large, complex, multi-system landscape
- Run regular (scheduled/periodic) and ad-hoc access audits across the environment, including privileged and administrative accounts
- Audit GCP IAM, LDAP, and PAM tools for stale accounts, excessive permissions, orphaned access, and misconfigurations
- Prepare clear, audit-ready reports and evidence packages suitable for internal review and external auditors
- Track remediation actions with system and application owners through to closure, escalating overdue items as needed
- Maintain audit documentation and process runbooks to ensure repeatability and continuity
- Continuously refine the audit methodology based on findings, tooling changes, and evolving compliance requirements
Skills
- 2+ years in the position of Access Engineer/IAM Auditor or similar
- Experience designing and building an access audit process from scratch
- Hands-on experience with GCP/LDAP (roles, permissions, service accounts, org policies)
- Hands-on experience with Privileged Access Management (PAM) tools and privileged/admin account audits
- Experience working across IGA tools (e.g., One Identity, Okta, Entra ID, Keycloak)
- Familiarity with compliance frameworks such as ISO 27001, SOC 2, and NIST
- Ability to hold system and application owners accountable to remediation timelines without formal authority over their teams
- Strong team-player orientation with the ability to maintain a positive and constructive atmosphere within the team
- High reliability and consistency in delivering work to a high standard of accuracy and attention to detail
- Self-dependent, result-oriented mindset
- A growth mindset - comfortable acknowledging mistakes, learning from them, and implementing corrective measures to prevent recurrence
Qualifications
Must Haves
- 2+ years in the position of Access Engineer/IAM Auditor or similar
- Experience designing and building an access audit process from scratch
- Hands-on experience with GCP/LDAP (roles, permissions, service accounts, org policies)
- Hands-on experience with Privileged Access Management (PAM) tools and privileged/admin account audits
- Experience working across IGA tools (e.g., One Identity, Okta, Entra ID, Keycloak)
- Familiarity with compliance frameworks such as ISO 27001, SOC 2, and NIST
- Ability to hold system and application owners accountable to remediation timelines without formal authority over their teams
- Strong team-player orientation with the ability to maintain a positive and constructive atmosphere within the team
- High reliability and consistency in delivering work to a high standard of accuracy and attention to detail
- Self-dependent, result-oriented mindset
- A growth mindset - comfortable acknowledging mistakes, learning from them, and implementing corrective measures to prevent recurrence