GCP IAM Lead / Manager
Apply now »Date: Sep 22, 2026
Location: New York, New York, US
Company: sistemasgl
GCP IAM Lead / Manager
Location: New York, NY
Compensation: $90,000–$140,000 annually
Employment Type: Full-time
Position Summary
We are seeking an experienced GCP IAM Lead / Manager to support a Deloitte project team delivering secure, scalable cloud identity and access management capabilities. This role will own the design, governance, and delivery of Google Cloud Platform (GCP) Identity and Access Management solutions across multiple onboarding efforts.
The ideal candidate has deep hands-on GCP IAM expertise, strong Terraform and infrastructure-as-code governance experience, and a security-by-design mindset. You will establish repeatable IAM patterns, guide engineering teams through implementation, manage access-control risks and exceptions, and partner with security and compliance stakeholders to support audit-ready delivery.
This role is well suited for an IAM leader who can balance architecture, delivery execution, governance, and operational support in a complex enterprise environment. The work will emphasize least-privilege access, resource-level permissions, well-managed service accounts, documented controls, and scalable onboarding standards. Google recommends granting roles at the smallest practical scope, avoiding broad basic roles in production, and using separate service accounts with narrowly scoped privileges for distinct application components.cloud.google+1
Key Responsibilities
-
Lead the design and implementation of GCP IAM solutions supporting enterprise cloud onboarding and migration initiatives.
-
Define and maintain IAM reference architectures, including role-based access control (RBAC) models, group-based access patterns, service account strategy, privileged-access patterns, and authentication and authorization controls.
-
Establish secure-by-default IAM standards for Google Cloud environments, with a focus on least privilege, segregation of duties, role scoping, temporary access, and auditability.
-
Develop and govern Terraform standards for IAM, including reusable module patterns, safe role-binding strategies, code-review requirements, change controls, and drift-management practices.
-
Lead IAM design reviews and provide technical guidance to engineering teams implementing cloud access controls.
-
Evaluate and approve IAM exceptions; document risks, compensating controls, remediation plans, and approval decisions.
-
Partner with cybersecurity, risk, compliance, platform engineering, application teams, and project stakeholders to define and implement access-control requirements.
-
Configure and manage IAM roles, policies, groups, service accounts, permissions, conditional access, and privileged-access controls.
-
Design and maintain secure service-account practices, including dedicated application identities, minimal permissions, lifecycle management, access reviews, and reduction of unnecessary service-account keys.
-
Support user authentication and authorization requirements across GCP projects, applications, APIs, services, and data platforms.
-
Troubleshoot and resolve IAM-related access, authentication, authorization, provisioning, policy, and service-account issues.
-
Manage delivery across multiple onboarding efforts, including priorities, timelines, dependencies, risks, and stakeholder communications.
-
Define the IAM operating model, including runbooks, incident-response procedures, access-request processes, access recertification inputs, monitoring, and support escalation paths.
-
Conduct regular IAM audits, access reviews, policy assessments, and compliance checks against established security standards and project requirements.
-
Develop and maintain technical documentation for IAM architectures, configurations, policies, implementation procedures, operational processes, and audit evidence.
-
Track and report IAM delivery metrics, onboarding progress, exceptions, remediation activities, operational incidents, and control effectiveness.
Required Qualifications
-
7+ years of experience in identity and access management, cloud security, cybersecurity engineering, or related technical roles.
-
Strong hands-on experience designing and implementing GCP IAM solutions in enterprise environments.
-
Demonstrated experience developing IAM architecture patterns for complex cloud environments, including RBAC, service accounts, privileged access, authorization models, and least-privilege controls.
-
Experience leading multiple technical workstreams, engineering teams, or cloud onboarding efforts.
-
Strong experience with Terraform and infrastructure as code, including IAM modules, policy management, code review, change control, and deployment governance.
-
Experience implementing and managing IAM policies, roles, permissions, groups, service accounts, authentication, authorization, and access reviews.
-
Knowledge of cloud-security concepts, including least privilege, segregation of duties, privileged access, access lifecycle management, logging, auditing, and incident response.
-
Experience troubleshooting identity, authentication, authorization, and access-control issues in a cloud environment.
-
Strong stakeholder-management skills and the ability to communicate technical controls, risks, design decisions, and implementation requirements to technical and nontechnical audiences.
-
Ability to create clear technical documentation, runbooks, process flows, standards, and audit-support materials.
Preferred Qualifications
-
Experience in financial services, consulting, banking, wealth management, insurance, or another highly regulated industry.
-
Experience working on large-scale cloud migration, cloud transformation, application onboarding, or enterprise platform modernization initiatives.
-
Familiarity with Google Cloud security services, organization policies, Cloud Identity, Google Workspace, Cloud Logging, Security Command Center, or IAM Recommender.
-
Experience with access recertification, identity governance and administration (IGA), privileged access management (PAM), or entitlement-management processes.
-
Experience with CI/CD pipelines and automated Terraform deployment practices.
-
Knowledge of compliance and control frameworks, such as NIST, SOC 2, ISO 27001, PCI DSS, SOX, or internal risk-management standards.
-
Relevant certifications, such as Google Professional Cloud Security Engineer, Google Professional Cloud Architect, CISSP, CISM, CCSP, or Terraform Associate.
Job Segment:
Developer, Risk Management, Engineer, Cyber Security, Temporary, Technology, Finance, Engineering, Security, Contract