沃尔沃
Digital Engineer —— IAM/数字化工程师(身份与访问管理)负责人
岗位职责
of this position focus on operation, governance, technical upgrading, and unified Access Management. -1 I. Core Responsibilities of IAM System Operation and Governance In alignment with corporate IAM job standards and current phase priorities, core responsibilities focus on the following three dimensions: Platform Operation and Stability Assurance High-Availability Operation : Responsible for daily monitoring and fault response of the IAM platform, ensuring service SLA compliance, and supporting 7×24 stable operation of core business systems. Performance Optimization : Continuously optimize key indicators such as system throughput and response latency, and enhance platform capacity through architecture upgrades, cache strategy adjustments, and other measures. Automated Operation : Introduce AI-assisted operation capabilities, with a plan to implement intelligent IAM code inspection and automatic fault localization by May 2026 to improve operation efficiency. -1 Permission Governance and Compliance Control Full-Lifecycle Permission Management : Establish a closed-loop process for permission application, approval, change, and revocation to implement the principle of least privilege and reduce the risk of unauthorized access. Compliance Auditing : Conduct regular permission compliance checks to meet regulatory
任职要求
such as Level 2 Protection 2.0 and ISO27001, with a 2026 target of achieving a 60% BIAM access rate for local applications in the Asia-Pacific region. Risk Response : Build an abnormal access detection system to enable real-time alerts and automatic handling for risk scenarios such as privileged account abuse and high-frequency failed logins. -1 Capability Enhancement and Architecture Evolution Unified Resource Service Construction : Lead the architectural design of a unified Resource Server to achieve centralized management and fine-grained authorization of API permissions. The DEV environment deployment has been completed, with plans to advance to UAT and production environments in Q2 2026. Access Control Upgrade : Reconstruct the permission engine based on a hybrid RBAC+ABAC model to support dynamic authorization based on user attributes, environmental context, etc., and improve the flexibility of permission management. Unified Technology Stack : Align the IAM system with the corporate unified technology stack, complete deep integration with Huawei Cloud IAM services, and realize dynamic acquisition of temporary AKSK to reduce the risk of key leakage. -1 II. Key Points for Unified Resource Server Construction Based on current project progress, the construction of the unified Resource Server should focus on the following aspects: Architectural Design Principles Centralized Authorization : All business APIs undergo permission verification through the unified Resource Server to avoid consistency issues caused by decentralized management. Standard Protocol Support : Implement token parsing and permission verification based on the OAuth2.0/JWT protocol, compatible with the authentication process of the existing IAM system. Scalability : Adopt a plug-in architectural design to support custom permission rules and extension points, meeting the rapid iteration of future business scenarios. -1 Key Function Implementation Token Verification Service : Provide capabilities for JWT token validity verification, expiration checks, and permission information parsing. Permission Decision Engine : Make permission judgments based on multiple dimensions such as user roles, resource attributes, and operation types, supporting complex rule configurations. Audit Log System : Record all API access requests and permission decision results to meet compliance auditing and problem tracing requirements. -1 Deployment and Migration Plan Environment Deployment : The DEV environment deployment has been completed (https://arch-apac-dtp-dev.digitalvolvo.com/resourcemanagerconsole), and IAM dependency configuration is in progress for the UAT environment. Business Migration : Prioritize integration with high-risk business systems, following a four-step strategy of "assessment → transformation → verification → launch", with plans to complete core system migration by Q3 2026. -1 III. Practical Recommendations for Unified Access Control In combination with corporate application security baselines and best practices, unified access control should be implemented from the following dimensions: Standardization of Identity Authentication Full SSO Coverage : Mandatorily integrate corporate SSO for all internal systems, supporting cross-domain authentication based on the SAML2.0/OIDC protocol. Multi-Factor Authentication : Enable MFA for privileged accounts and sensitive operation scenarios, adopting multiple verification methods such as SMS, tokens, and biometrics. -1 Fine-Grained Permission Management Principle of Least Privilege : Assign necessary permissions based on job requirements, and conduct regular permission cleanups to avoid permission redundancy. Dynamic Permission Adjustment : Automatically revoke or adjust permissions based on changes in user status (e.g., resignation, transfer) to synchronize permissions with the identity lifecycle. -1 Security Auditing and Monitoring Full-Link Logging : Record complete link logs from identity authentication to resource access. Real-Time Risk Alerts : Establish a machine learning-based abnormal behavior analysis model to provide real-time alerts and blocking for suspicious access behaviors. -1 IV. AI-Driven Product Definition and Architecture Upgrade Use AI to analyze business requirements (such as permission application process optimization, new system access requirements), and automatically generate structured PRD (Product Requirements Document) drafts, low-fidelity prototypes, and initial technical solutions. Lead requirement clarification meetings, and use AI to assist in improving PRDs and high-fidelity prototypes to ensure the accuracy and completeness of product definitions. Based on business requirements and technological trends, use AI for system architecture pattern selection, technology stack evaluation, and selection. For example, assess the feasibility of introducing microservice architecture or cloud-native technologies, and use AI to generate detailed architectural design plans and API contracts between components. Without writing code, use AI tools (such as CLI Coding Agent) to automatically generate core code such as domain models, API controllers, business logic (Service), and front-end components based on PRDs, design drafts, and technical solutions, ensuring that the generated code complies with internal coding specifications and architecture standards. -1 Job Requirements
Education and Professional Background Bachelor's degree or above in computer science, information security, software engineering, or related fields 5+ years of relevant IAM work experience, and 3+ years of team management experience -1
Professional Technical Capabilities In-depth understanding of core technologies and concepts in the IAM field, including but not limited to: identity lifecycle management, RBAC/ABAC access control models, SSO (OAuth2/OIDC/SAML), multi-factor authentication, permission auditing, PAM privileged account management, IDaaS, etc. Experience in implementing, operating, or developing mainstream IAM products such as Okta, Azure AD, Alibaba Cloud RAM, Keycloak, Authing, etc. Familiarity with cloud-native architecture, with priority given to candidates with IAM construction experience in cloud environments Knowledge of related fields such as network security and data security Proficiency in AI Coding -1
Competency Requirements Strong sense of ownership, able to promote governance goals in challenging environments Strong cross-departmental communication and coordination skills, able to drive the implementation of complex projects Strong problem analysis and solving skills, able to quickly locate and resolve complex technical issues Proficient in oral English communication, able to work with colleagues in Sweden in English We'd love to receive and review your application. Please feel free to follow Volvo Cars Recruitment Wechat Account (沃尔沃汽车招聘微信公众号) If you want to know more information.
信息来自企业官方招聘渠道
OfferSeek 对公开岗位信息进行聚合、去重和结构化整理,最终申请以企业官方页面为准。
