Capgemini Engineering

E2S Architect

Capgemini Engineering

Lisboa, PT (Hybrid)

Job Type Permanent
Experience Experienced Professionals
Posted 4 weeks ago
Hybrid Experienced Professionals Level

Your Role

IAM & Security Architecture

  • Design identity and access architectures based on modern standards, including OIDC, OAuth2 with Token Exchange, and SAML.
  • Architect and operate IAM systems across multicloud and hybrid environments.
  • Implement cloud-native workload identity mechanisms such as AWS IRSA, Azure Workload Identity, and GKE Workload Identity.
  • Design and deploy relationship-based access control using OpenFGA, Authzed, or Zanzibar-inspired models.
  • Define security controls and compliance measures aligned with SecNumCloud, NIS2, GDPR, and Zero Trust frameworks.

Cloud Architecture

  • Design secure-by-design cloud architectures across at least two hyperscalers: AWS, Azure, or GCP.
  • Develop cloud standards, including landing zones, network patterns, and IAM guardrails, for critical workloads.
  • Support engineering teams in implementing native cloud identity and security features.

Infrastructure as Code (IaC)

  • Develop and maintain Terraform and/or Crossplane modules to automate IAM and security policies.
  • Integrate IaC pipelines with policy-as-code controls such as OPA, Conftest, and Rego.

Enterprise Architecture & Integration

  • Produce end-to-end blueprints for authentication and authorization flows across internal and external systems.
  • Define integration patterns leveraging API gateways and federated identity standards.
  • Ensure architectural alignment with enterprise principles, integration standards, and security controls.

Governance & Adoption

  • Lead architectural reviews, ensuring compliance with security and cloud governance standards.
  • Promote IAM and Zero Trust best practices across the organization.
  • Act as a strategic advisor to engineering, cybersecurity, and product teams.

Your Profile

  • 8+ years of experience in IAM and/or cybersecurity.
  • Deep understanding of OIDC, OAuth2 with Token Exchange, and SAML.
  • Strong proficiency with Keycloak and/or Ory.
  • Hands-on experience with at least two hyperscalers: AWS, Azure, or GCP.
  • Experience with AWS IRSA, Azure Workload Identity, or GKE Workload Identity.
  • Proven experience implementing ReBAC with OpenFGA, Authzed, or Zanzibar-style approaches.
  • Solid understanding of SecNumCloud, NIS2, GDPR, and Zero Trust.
  • Ability to write IaC for IAM using Terraform and/or Crossplane.
  • Experience with integration architecture involving API gateways and IAM.

Nice-to-Have Skills

  • Cloud certifications in AWS, Azure, or GCP.
  • Security certifications such as CISSP, CCSP, or Security+.

What You’ll Love About Working Here

  • Multicultural and inclusive team environment.
  • Supportive atmosphere promoting work-life balance.
  • Hybrid work.
  • Career growth programs, training, and certifications in cutting-edge technologies.
  • Exciting national and international projects.
  • Health and life insurance.
  • Referral program with bonuses for talent recommendations.
  • Great office locations.

About Capgemini

Capgemini is an AI-powered global business and technology transformation partner with nearly 60 years of heritage and 420,000 team members in more than 50 countries. The company delivers end-to-end services and solutions across strategy, technology, design, engineering, and business operations.

Similar Job Openings