Security / Identity Engineer — SRE
Dallas, TX
Date Posted:12-Aug-2026
Work Type:On-Site
Job Number:494739
Job Description
Job Title: Security / Identity Engineer — SRE
Duration:4 months
Job Type: Remote
Job Description/ Responsibilities
1. Identity & Entitlements: Integrate the API layer with AWS IAM Identity Center (IdC) and build a policy engine to enforce data boundaries (SRE vs. App Team vs. Business Unit). This includes integrating Omni into the client’s existing identity-federation model — an established custom credential-vending / SAML broker on the primary landing zone plus existing IdC adoption for console access.
2. Cross-Account Data Routing: Implement and automate links to aggregate logs, metrics, and traces across multiple AWS Organizations.
3. End-to-End Feature Delivery: Build, test, and deploy features from the AWS infrastructure layer (CloudWatch / Omni / IAM) up through the API layer that serves the UI, using CloudWatch cross-account capabilities. May include writing high-performance APIs (in Go, Python, or Java) to query CloudWatch, CloudTrail, and flow logs, and implementing efficient caching strategies.
4. Infrastructure as Code (IaC): Automate the deployment of all resources using Terraform or AWS CDK, leveraging AWS CloudFormation StackSets to deploy source links to 15,000 accounts.
5. Enablement: Produce clear architecture and integration documentation and enable the client’s teams to operate and extend the Omni identity and routing model, working as an embedded SME alongside the client’s SRE and observability leadership.
the top skills required
1. Advanced. Identity & Security (Primary) - AWS IAM Identity Center (IdC), SAML/OIDC federation, and integration with an existing enterprise federation / credential-vending model
2. Advanced. Attribute-based access control (ABAC) and fine-grained authorization engines such as AWS Verified Permissions or Open Policy Agent (OPA).
3. Advanced. AWS Organizations, CloudFormation StackSets, and Org-level APIs and policies. Able to automate resource provisioning at a scale of 15,000 accounts.
4. Proficient. Python, Java, or Go. Building high-performance REST/API services to query CloudWatch, CloudTrail, and flow logs, with efficient caching strategies and asynchronous data fetching.
5. Advanced. CloudWatch (Metrics, Logs, Alarms, Contributor Insights), CloudWatch cross-account observability / OAM (sink and source configuration), CloudTrail, and flow logs.
6. Advanced. Terraform or AWS CDK, with CI/CD pipelines (e.g. GitLab CI) for automated infrastructure deployment.
Duration:4 months
Job Type: Remote
Job Description/ Responsibilities
1. Identity & Entitlements: Integrate the API layer with AWS IAM Identity Center (IdC) and build a policy engine to enforce data boundaries (SRE vs. App Team vs. Business Unit). This includes integrating Omni into the client’s existing identity-federation model — an established custom credential-vending / SAML broker on the primary landing zone plus existing IdC adoption for console access.
2. Cross-Account Data Routing: Implement and automate links to aggregate logs, metrics, and traces across multiple AWS Organizations.
3. End-to-End Feature Delivery: Build, test, and deploy features from the AWS infrastructure layer (CloudWatch / Omni / IAM) up through the API layer that serves the UI, using CloudWatch cross-account capabilities. May include writing high-performance APIs (in Go, Python, or Java) to query CloudWatch, CloudTrail, and flow logs, and implementing efficient caching strategies.
4. Infrastructure as Code (IaC): Automate the deployment of all resources using Terraform or AWS CDK, leveraging AWS CloudFormation StackSets to deploy source links to 15,000 accounts.
5. Enablement: Produce clear architecture and integration documentation and enable the client’s teams to operate and extend the Omni identity and routing model, working as an embedded SME alongside the client’s SRE and observability leadership.
the top skills required
1. Advanced. Identity & Security (Primary) - AWS IAM Identity Center (IdC), SAML/OIDC federation, and integration with an existing enterprise federation / credential-vending model
2. Advanced. Attribute-based access control (ABAC) and fine-grained authorization engines such as AWS Verified Permissions or Open Policy Agent (OPA).
3. Advanced. AWS Organizations, CloudFormation StackSets, and Org-level APIs and policies. Able to automate resource provisioning at a scale of 15,000 accounts.
4. Proficient. Python, Java, or Go. Building high-performance REST/API services to query CloudWatch, CloudTrail, and flow logs, with efficient caching strategies and asynchronous data fetching.
5. Advanced. CloudWatch (Metrics, Logs, Alarms, Contributor Insights), CloudWatch cross-account observability / OAM (sink and source configuration), CloudTrail, and flow logs.
6. Advanced. Terraform or AWS CDK, with CI/CD pipelines (e.g. GitLab CI) for automated infrastructure deployment.
Applicant Notices & Disclaimers
- For information on benefits, equal opportunity employment, and location-specific applicant notices, click here
At SPECTRAFORCE, we are committed to maintaining a workplace that ensures fair compensation and wage transparency in adherence with all applicable state and local laws. This position's pay range is $75.00/hr – $80.00/hr.