jobloom

JobLoom finds jobs directly from company career sites before many job boards, then routes you into detailed role pages like this one.

other

Posted 4 hours ago

Lead SaaS/IAM Specialist

at Wrike

Prague, CzechiaHybrid
You are nearing today's limit. Upgrade for unlimited access.

Requirements

  • Your mission is to balance business agility with absolute data protection across our sprawling SaaS ecosystem (including M365, Slack, Salesforce, etc).
  • By governing the security of third-party integrations: You will audit, restrict, and manage OAuth permissions granted to third-party add-ons and AI extensions, ensuring our enterprise data remains inside approved boundaries.
  • You will partner with Procurement to assess the security profiles of new software vendors by auditing SOC 2 reports, ISO certifications, and CAIQ sheets.
  • experience in Cloud Security, IAM Administration, or IT Security Operations, including 1-2 years of
  • experience leading, mentoring, or acting as a technical coordinator for other engineers. Technical Skills:
  • Deep expertise in identity protocols: SAML 2.0, OIDC, OAuth 2.0, and SCIM.
  • experience with modern IdPs (Okta or Microsoft Entra ID / Azure AD).
  • Scripting capabilities in Python, PowerShell, or Bash to automate security workflows and interact with SaaS APIs.
  • You hold an industry-recognized Cloud Security certification like CCSP or CCSK (Cloud Security Alliance).
  • You hold a specialized identity certification like Microsoft SC-300 or an Okta Certified Professional/Administrator credential. You have direct
  • Leadership Excellence: You have a proven track record of designing technical roadmaps, translating business objectives into actionable engineering sprints, and successfully leading a small-to-midsize security team through complex migrations or infrastructure overhauls.
  • We live in Wrike for project management, utilize Okta / Entra ID, and scripting (Python, PowerShell) for API-driven automation.

Experience

  • Experience: 5+ years of dedicated

Benefits

  • Built for teams and organizations looking to collaborate, create, and exceed every day, Wrike brings everyone and all work into a single place to remove complexity, increase productivity, and free people up to focus on their most purposeful work. Our vision: A world where everyone is free to focus on their most purposeful work, together.
  • 5 Weeks of paid vacation
  • Sick Leave Compensation
  • 5 Paid Uncertified Sick Days
  • 2 weeks fully paid w/ medical certificate, additional
  • 4 weeks paid at 80% salary rate
  • Parental Leave (fully paid): 18 Weeks Maternity / 4 Week Paternity 2 Volunteer Days
  • Meal Vouchers (CZK 220 per working day)
  • Annual Prague Travel Card (Lítačka)
  • Benefit budget with flexible options, including a MultiSport card, Canadian Medical membership, contributions to a pension savings plan and additional choices available through Benefit Plus

Contact

  • Check out our LinkedIn Life Page , Company culture page , Instagram , Wrike Engineering Team , Medium , Meetup.com , Youtube for a feel for what life is like at Wrike.

Additional details

  • As the Lead SaaS/IAM Security Specialist, you will be the primary architect and team leader driving our cloud application security posture.
  • In this role, you will bridge the gap between user enablement and risk management by owning Identity and Access Management (IAM), deploying SaaS Security Posture Management (SSPM) tools to prevent configuration drift, and governing the entire lifecycle of our business applications.
  • Crucially, you will lead, mentor, and scale a high-performing team of security engineers, fostering a collaborative culture rooted in automation and proactive risk reduction. Your Impact:
  • By building and automating robust Identity pipelines: You will design, configure, and maintain our Identity Providers (IdP) using SAML 2.0, OIDC, and OAuth 2.0.
  • You will leverage SCIM to automate provisioning and ensure immediate, airtight offboarding to prevent orphan accounts.
  • By hardening our SaaS posture against configuration drift: You will deploy and manage SaaS Security Posture Management (SSPM) tools.
  • You will establish and enforce security baselines (such as CIS benchmarks) across our key tools, catching unauthorized administrative changes in real time.
  • By mitigating Shadow IT and assessing third-party risk (TPRM): You will analyze CASB, proxy, and endpoint logs to discover unauthorized SaaS usage.
  • By championing technical leadership and team growth : You will build, mentor, and guide a dedicated team of security professionals.
  • By establishing engineering best practices, leading agile workflows, and promoting continuous learning, you will multiply

Find more real-time jobs on JobLoom.