IAM Engineer
- Role
- Security
- Employment
- Full-time
- Company size
- Startup
Open to HU, PL, PT, RO, GB only. Set where you work from to check your eligibility.
No BS summary
IAM engineer for a remote full-time role hiring in Hungary, Poland, Portugal, Romania, or the UK. Needs production identity/access management experience with Okta or similar IDPs, SCIM provisioning, access reviews, and automation in Python, Go, or similar.
Core skills
Required skills
An Introduction to Primer
Primer is the unified infrastructure for global payments. We give finance and payments teams the visibility and control to reduce complexity, improve performance, and capture more revenue - all from a single platform.
Backed by Sofina, Peak XV Partners, ICONIQ, Tencent, Accel, and Balderton, we're building the payments layer the world's best companies rely on.
Watch our showcase >
Read up on our $100m Series C
Learn more about our culture >
Which team will you be joining? You're joining the Security team at a critical inflection point. We're standing up dedicated IAM alongside GRC and Workplace Technology, and this role is the connective tissue that makes all three effective.
Every new joiner, internal move, and leaver flows through IAM provisioning. You'll own the day-to-day queue, but you're not just firefighting. You'll be building the automation that shrinks that queue: SCIM-based day-one provisioning, deprovisioning pipelines, access review automation. This is where the long-term leverage lives.
You'll report to the Head of Security and partner closely with the GRC and Workplace Technology teams. Unlike many security roles that sit in isolation, this one is partnership-driven. You'll work with people, engineering, workplace technology, compliance, and the wider infrastructure team to make provisioning and access governance actually work at scale.
What will you be doing?
- Stabilise and own the IAM request queue as the company scales. You'll inherit an active backlog, understand which requests are genuinely urgent and which are nice-to-have, and establish a baseline for time-to-resolution that holds steady as the company grows.
- Build and maintain SCIM auto-provisioning flows for day-one account setup across our SaaS tools (Okta, Slack, GitHub, etc.). This is the highest-leverage workload reduction project. You'll own the end-to-end flow from requirements through implementation and troubleshooting.
- Design and execute the IAM enrolment improvements roadmap, including finalising Mac/Windows enrolment, progressing the Okta rollout, and building the fallback workflows in Tines. You'll work with engineering and infrastructure teams to understand technical dependencies and ship these initiatives on time.
- Partner with GRC to run automated access reviews and certification campaigns. You'll design the review workflows, maintain the data pipelines, and work toward measurable reduction in standing access and access sprawl.
- Progress IAM-related technical debt and risk. You'll own JIT/PAM initiatives, least-privilege evidence collection for audits, and the automation roadmap that underpins context-aware access.
- Remove identity and provisioning load from Workplace Technology, freeing that team to focus on IT support, device management, and people systems.
What we're looking for
- You've shipped identity or access management systems in production before—whether at a fintech, security-focused company, or infrastructure-heavy environment. You understand Okta (or similar IDPs), SCIM provisioning, access review workflows, and the real-world friction of scaling identity at a growing company.
- You're equally comfortable building automation (Python, Go, or similar) and integrating tools like Tines, Okta, and cloud IAM services. You don't need to be a security expert, but you need to understand the why behind least-privilege, deprovisioning, and audit trails.
- You have strong operational ownership. You'll inherit a backlog and make the call on what's urgent, what can wait, and what needs engineering help. You own the queue, not the other way around.
- You can learn Primer's specific stack and people-systems on the job. What matters is your ability to reason through access problems and translate business requirements into working systems.
- You collaborate well with non-engineering functions (GRC, People, compliance, engineering). This role sits at the seam between functions; you need to be genuinely curious about what they need and how to help.
You may not like it here
- We've grown faster than our IAM automation, and you won't fix that in month one. It takes months to ship the automation that shrinks the queue.
- There's ambiguity on the roadmap. As GRC and Workplace Technology mature, their IAM needs will shift. You'll need to be comfortable reprioritising and re-scoping as the business changes.
- The leverage is automation, not headcount. You're here to build systems that scale, not to hire a team underneath you.
- We're remote-first and globally distributed. You'll be the sole person owning this domain. You'll need to document heavily and build trust across asynchronous channels.
✅ A typical interview process
- An initial intro call with a Talent Partner
- An interview with the Hiring Manager
- Challenge Stage - Contextualised to the role
- A final, values-alignment interview
What's the culture like at Primer?
We're building a culture where people can do their best work and be proud of the impact they have. You'll be working with people who are mission-driven, smart, and reflective, and who are genuinely invested in building exceptional products and delivering success for our merchants.
We work remotely, and have done since day one. We believe that building a successful, profitable company goes beyond proximity. We invest in our relationships through great remote working practices and thoughtfully designed face-to-face time, including workations, our annual company retreat, and access to co-working spaces across most major cities.
The work is challenging. Scaleups are a challenge, and building category-defining products is a challenge. But there's a meaningful difference between a challenge and a struggle. At Primer, the right challenge comes with the right support: strong onboarding, a collaborative environment, and a team that is genuinely invested in your success. It's never something you face alone.
Our benefits
🌍 We are fully remote and globally distributed; and have been since day one 💰 Competitive share options 🌴 Uncapped holiday, with 25 days minimum to be taken 🗣️ Co-working space access across major cities 📅 Workations & Company Retreat 💻 The best equipment for your role 🏠 £500 towards your home office setup 🔎 Generous learning budget 🏥 Private Medical Insurance 📈 A broad set of additional perks and benefits (depending on location)
Don’t meet every single requirement?
At Primer, we're dedicated to building a diverse, inclusive, and authentic workplace. If you're excited about this role but your experience doesn't align perfectly with every qualification listed, we encourage you to apply. You may be the right candidate for this or other roles.
Primer is committed to the equal treatment of all current and prospective employees and adopts a zero-tolerance approach to discrimination, regardless of age, disability, sex, sexual orientation, pregnancy and maternity, race or ethnicity, religion or belief, gender identity, marriage and civil partnership, or any other background or belief.
What you'll do
- Stabilise and own the IAM request queue as the company scales.
- Inherit an active backlog, assess urgency, and establish a steady time-to-resolution baseline.
- Build and maintain SCIM auto-provisioning flows for day-one account setup across SaaS tools such as Okta, Slack, and GitHub.
- Own the end-to-end SCIM provisioning flow from requirements through implementation and troubleshooting.
- Design and execute the IAM enrolment improvements roadmap.
- Finalise Mac/Windows enrolment.
- Progress the Okta rollout.
- Build fallback workflows in Tines.
- Work with engineering and infrastructure teams to understand technical dependencies and ship IAM initiatives on time.
- Partner with GRC to run automated access reviews and certification campaigns.
- Design access review workflows.
- Maintain data pipelines for access reviews.
- Work toward measurable reduction in standing access and access sprawl.
- Progress IAM-related technical debt and risk.
- Own JIT/PAM initiatives.
- Own least-privilege evidence collection for audits.
- Own the automation roadmap underpinning context-aware access.
- Remove identity and provisioning load from Workplace Technology so that team can focus on IT support, device management, and people systems.
- Document heavily and build trust across asynchronous channels.
What they require
- Experience shipping identity or access management systems in production, whether at a fintech, security-focused company, or infrastructure-heavy environment.
- Understanding of Okta or similar IDPs, SCIM provisioning, access review workflows, and the real-world friction of scaling identity at a growing company.
- Comfortable building automation in Python, Go, or similar.
- Comfortable integrating tools like Tines, Okta, and cloud IAM services.
- Understanding of the reasons behind least-privilege, deprovisioning, and audit trails.
- Strong operational ownership; able to inherit a backlog and decide what is urgent, what can wait, and what needs engineering help.
- Ability to learn Primer's specific stack and people systems on the job.
- Ability to reason through access problems and translate business requirements into working systems.
- Collaborates well with non-engineering functions such as GRC, People, compliance, and engineering.
- Comfortable with roadmap ambiguity, reprioritising, and re-scoping as the business changes.
- Focused on building systems that scale rather than hiring a team underneath them.
- Able to be the sole person owning this domain in a remote-first, globally distributed company.
Benefits
- Fully remote and globally distributed company since day one.
- Competitive share options.
- Uncapped holiday, with 25 days minimum to be taken.
- Co-working space access across major cities.
- Workations and company retreat.
- Best equipment for the role.
- £500 towards home office setup.
- Generous learning budget.
- Private medical insurance.
- A broad set of additional perks and benefits depending on location.
- Strong onboarding.
- Collaborative environment.
- Team invested in your success.
Primer is the unified infrastructure for global payments, giving finance and payments teams visibility and control to reduce complexity, improve performance, and capture more revenue from a single platform.
What people say about this company
3.9/ 5