03 ago
|
Clarios
|
San Pedro Garza García
03 ago
Clarios
San Pedro Garza García
The Role
The Engineer, IAM is accountable for assisting with the planning, designing, and building of the enterprise digital employee and identity experience from a technical lens.
You help define the future-state strategy, architecture, and roadmap for end-user and identity capabilities — ensuring the workforce can securely, reliably, and efficiently access the tools and information required to deliver business outcomes.
The role centers on intentional design, engineering and technical results, and scalable solutions, working in close partnership with Security, Infrastructure, Applications, global functions and manufacturing, and business leaders.
Success is measured by clarity of strategy, strength of design, technical skill, readiness for transition to Run teams, and alignment to Clarios values and enterprise priorities.
What You’ll Do (Impact Areas)
- Strategy, vision & roadmap (Plan): help define the integral strategy and future-state vision for identity services and capabilities aligned to Clarios business objectives, security posture, and growth plans — keeping strategies principled, risk-aware, and customer-centric while balancing productivity, security, compliance, and cost.
- Solution design & architecture (Build): design scalable, secure, user-centric solutions across identity domains; provide solid technical solutions, troubleshooting, and support for all IAM / Identity services; define standards and patterns that embed identity and access controls into end-user platforms, applications, and collaboration tools; partner with Enterprise Architecture and Security to align to architectural standards, security frameworks, and regulatory requirements; and make deliberate design trade-offs that reduce long-term risk and technical debt.
- Identity & access lifecycle enablement: design enterprise identity lifecycle models (joiner, mover, leaver)
tightly integrated with HR processes and end-user access needs; define access governance, role design, and entitlement models that support least-privilege access while enabling business agility; and establish authentication and access design principles that deliver a seamless user experience without compromising security.
- End-user experience enablement: help define self-service, automation, and digital-experience improvements that simplify access and reduce friction for the workforce, ensuring solutions are globally scalable while allowing for regional and plant-specific requirements.
- Security, risk & compliance by design: embed security and compliance by design — not by exception — across all identity solutions; partner with Risk and Compliance teams to keep new capabilities audit-ready and aligned to enterprise control objectives; and proactively identify and mitigate identity-related risks through strong upfront design and governance.
- Transition readiness & governance: ensure all solutions are fully designed, documented, and ready for transition into Run organizations with clear ownership, controls, and success criteria, and establish design governance, decision frameworks, and success measures for consistent execution and accountability.
- Leadership & influence: influence enterprise direction through strong partnership, clear communication, and fact-based recommendations, and model Clarios values by fostering collaboration, accountability, and a high-performing team culture.
What Success Looks Like
- Well-architected solutions that transition smoothly into Run with minimal rework.
- Reduced long-term risk through intentional, identity-centric design.
- Strong trust from business, security, and IT partners.
Core Competencies
- Deep IAM / Identity engineering across Active Directory, Entra ID, and CyberArk (Saviynt a plus).
- Identity lifecycle design (joiner / mover / leaver) and access governance (RBAC / ABAC, least privilege, zero trust).
- Authentication and authorization design: SSO, MFA, SCIM, PAM, PKI, identity federation, and directory synchronization.
- Secure-by-design thinking across risk, compliance, and audit-readiness.
- Digital workplace architecture and scalable, user-centric solution design.
- Partnership, clear communication, and fact-based influence across enterprise stakeholders.
What You Bring (Qualifications)
Required
- Minimum of five (5) years of experience engineering IAM and Identity Services.
- Strong, hands-on technical capabilities within Identity services — Active Directory, Entra ID, CyberArk (Saviynt is a plus).
- Strong background in digital workplace architecture, identity lifecycle design, and access governance.
- Identity lifecycle management (joiner / mover / leaver processes).
- Technical understanding of authentication vs.
authorization models.
- Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC).
- Least-privilege and zero-trust access principles, plus identity federation and directory synchronization.
- SSO, MFA, SCIM, PAM, PKI, scripting, and technical SME / troubleshooting capabilities.
- Experience with innovative IAM solutions such as passwordless, token, and card authentication within manufacturing environments.
Required Skill Profession
Computer Occupations
📌 Engineer, Identity and Access Management (IAM) (San Pedro Garza García)
🏢 Clarios
📍 San Pedro Garza García