Staff Identity & Access Management Engineer

Belgrade EV Full-time Posted Oct 2, 2026
Apply on Rivian and Volkswagen Group Technologies (opens in a new tab) Sourced via jobs.ashbyhq.com · Posted 2026-10-02

About this role

Rivian and Volkswagen Group Technologies is hiring a Staff Identity & Access Management Engineer, full-time, on-site in Belgrade, in the EV sector.

About Us

Rivian and Volkswagen Group Technologies is a joint venture between two industry leaders with a clear vision for automotive’s next chapter. From operating systems to zonal controllers to cloud and connectivity solutions, we’re addressing the challenges of electric vehicles through technology that will set the standards for software-defined vehicles around the world.

The road to the future is uncharted. By combining our expertise across connectivity, AI, security and more, we’ll map a new way forward. Working together, we’ll create a future that’s more connected, more intelligent, more sustainable for everyone.

Role Summary

RV Tech is building its enterprise identity program from the ground up, and the Staff IAM Engineer runs it. You are the directly responsible individual for the full identity program: the workforce identity platform, identity governance, privileged access, non-human identities, secrets management, and the Helpdesk operations that sit on top of all of it. You own the outcomes, the roadmap, the team, and the vendors.

This is a player-coach role. You will design and build, lead a small agile team of engineers and contractors, direct external implementation partners, and personally represent identity controls to auditors across multiple certification regimes. You will also be the person who finds a creative way through resource constraints, most often by applying AI engineering and automation where headcount is not available.

Responsibilities

Program Leadership

  • Serve as the directly responsible individual for the enterprise identity program across all of its pillars: workforce identity platform (IdP), identity governance and administration (IGA), privileged access management (PAM), non-human identity (NHI) governance, secrets management, and device trust.

  • Own the identity roadmap end to end: define priorities, sequence delivery, manage dependencies across IT, Product, and partner teams, and report status, risks, and decisions to leadership and steering committees.

  • Juggle multiple concurrent high-priority projects with shifting priorities; keep each one operationally successful and make explicit, defensible trade-offs when resources conflict.

  • Build and lead a small, agile, effective identity team: hire, develop, and set standards for full-time engineers and a contractor workforce.

  • Manage external implementation partners and vendors: scope statements of work, hold partners to delivery and quality commitments, control spend, and run vendor evaluations and RFPs for new identity capabilities.

Identity Platform Operations

  • Own operation of the enterprise workforce identity platform: tenant configuration, access policies, MFA and adaptive access, lifecycle automation, and application integrations (SSO and SCIM).

  • Lead identity-related Helpdesk operations: own the L2/L3 support model, SLAs, and runbooks; resolve escalations personally when needed; and eliminate recurring ticket classes through automation and self-service.

  • Lead the identity workstream in operational and cybersecurity incidents: direct containment (session revocation, credential resets, access suspension), produce post-incident evidence, and own identity-related corrective actions.

  • Define platform observability and operational KPIs: alerting on authentication anomalies, policy drift, integration failures, and lifecycle errors.

  • Drive stabilization and optimization of the identity platform, including retirement of legacy identity dependencies.

Access Governance & Audit

  • Own quarterly user access reviews (UARs) end to end: scope, reviewer coordination, completion tracking, revocation remediation, and audit-ready records.

  • Own identity control design and evidence for the TISAX, ISO 27001, SOC 2, and SOX control environments; serve as the primary identity point of contact for internal and external auditors across all four regimes.

  • Own governance of non-human identities (service accounts, service principals, API credentials, machine identities): discovery, ownership attestation, rotation, and decommissioning.

  • Detect and remediate excessive privileges and risky entitlements; design preventive controls so they do not recur.

Scaling & Growth

  • Lead the privileged access management capability: strategy, tool selection, rollout, and operating model.

  • Lead the enterprise secrets management program: adoption, developer workflows, and integration with the identity lifecycle.

  • Apply AI engineering and automation to scale the identity function: agentic investigation and remediation of access anomalies, automated evidence collection, lifecycle automation, and self-service.

  • Build identity data pipelines and governance tooling on the enterprise data platform, feeding identity signals into detection and response.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Security, Information Systems, or a related technical field (required).

  • 8+ years in identity and access management, with 3+ years as the accountable lead for a production workforce identity program or platform.

  • Experience building and leading a small, agile, effective team, including managing a contractor workforce and directing external implementation partners and vendors.

  • Deep hands-on experience with major identity platforms, including Okta, Microsoft Entra ID, Ping Identity, or comparable workforce IdPs, including tenant design, policy architecture, and lifecycle automation.

  • Expert knowledge of SAML, OIDC, OAuth 2.0, SCIM, and directory services (Entra ID/Active Directory) in hybrid enterprise environments.

  • Exemplary written and verbal communication skills, with demonstrated experience presenting identity controls and evidence directly to auditors for TISAX, ISO 27001, SOC 2, and/or SOX.

  • Experience leading identity-related Helpdesk or service operations (L2/L3 support model, SLAs, runbooks) and leading identity response during security incidents.

  • Hands-on coding experience (Python or similar) and working experience with infrastructure and data platforms such as Terraform, Databricks, AWS, and GCP.

  • Demonstrated ability to manage multiple concurrent high-priority projects with varying priorities, and to solve resource constraints creatively, particularly through automation and AI engineering.

  • Experience owning access governance processes (user access reviews, NHI governance) in a regulated environment.

Preferred Qualifications

  • Advanced vendor certification on a major identity platform (e.g., Okta Certified Consultant or Developer, Microsoft Identity and Access Administrator).

  • Experience selecting and deploying IGA, PAM, and enterprise secrets management platforms.

  • Experience leading an identity platform migration or consolidation.

  • Experience building AI-assisted or agentic security automation.

  • SIEM integration and detection engineering experience for identity signals.

  • Experience in an automotive, joint-venture, or multi-entity enterprise environment.

First 90 Days

  • Produce a program ownership dossier covering architecture, integrations, risks, controls, operational KPIs, team and vendor plan, and a 12-month roadmap across all identity pillars.

Description from Rivian and Volkswagen Group Technologies's official posting. Always confirm details on the company careers page.

Apply on Rivian and Volkswagen Group Technologies Applications go directly to Rivian and Volkswagen Group Technologies. Curated by Larry Sherwood Jr.

About Rivian and Volkswagen Group Technologies

Rivian and Volkswagen Group Technologies

Company in the mobility sector tracked nightly on the Mobility Jobs board.

Ready to apply?
Apply on Rivian and Volkswagen Group Technologies (opens in a new tab) You'll be redirected to jobs.ashbyhq.com to complete your application.

Not the one? Get new EV roles by email, weekday mornings, only when something new lands.

Larry Sherwood Jr.

About Larry Sherwood Jr.

Talent Acquisition Leader specializing in mobility, EV, and frontier tech. 1,000+ hires across roles ranging from production technicians to VPs, including 48 hires for the AFEELA U.S. launch at Sony Honda Mobility (98% offer acceptance, $1.5M+ agency savings). SHRM-CP certified. Build recruiting functions from scratch, no agencies.

SONY HONDA MOBILITYFISKERSHRM-CP1,000+ HIRES

Currently open to senior TA leadership roles in the United States. larrysherwoodjr.com · Resume (PDF)

Read Larry's guides →
Job no longer open? Let me know

Curated by Larry Sherwood Jr. on the free Mobility Jobs board. Pulled nightly from company applicant tracking systems. Apply directly on the source link above to be considered.