Principal Security Engineer – Identity & Access

dLocal
Madrid, Barcelona, São Paulo, Buenos Aires, Montevideo, Bucharest
Workplace: HybridFull timeFunction: CybersecuritySkills: ["Mentoring","Documentation","Patience","Persistence","Negotiation"]

Build and scale dLocal’s automated identity security program by engineering the identity lifecycle (Joiner-Mover-Leaver, access certifications, separation of duties) and unifying IGA frameworks. Lead identity federation and Zero Trust foundations across cloud, SaaS, and on-prem, using SAML, OAuth2, OpenID Connect, and SCIM alongside Adaptive MFA. Own secure identity integration for mergers and enterprise transformation, translating compliance policies into code and driving “shift-left” governance.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
dLocal
dLocal
1 month ago

Principal Security Engineer – Identity & Access

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 10 hours agoStatus: Live

Job Summary

Build and scale dLocal’s automated identity security program by engineering the identity lifecycle (Joiner-Mover-Leaver, access certifications, separation of duties) and unifying IGA frameworks. Lead identity federation and Zero Trust foundations across cloud, SaaS, and on-prem, using SAML, OAuth2, OpenID Connect, and SCIM alongside Adaptive MFA. Own secure identity integration for mergers and enterprise transformation, translating compliance policies into code and driving “shift-left” governance.
Location: Madrid, Barcelona, São Paulo, Buenos Aires, Montevideo, Bucharest
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Engineer the identity lifecycle (JML & SoD) by building an automated Joiner-Mover-Leaver machine, access certifications, and unified IGA frameworks.
  • •Design and scale authentication/authorization foundations using identity federation across cloud, SaaS, and on-prem, including SAML, OAuth2, OpenID Connect, SCIM, Zero Trust, and Adaptive MFA.
  • •Lead identity integration strategy for mergers, acquisitions, and large-scale enterprise transformations, securely incorporating new organizations into the identity ecosystem.
  • •Configure integrations, write RBAC policies, engineer IGA platforms, and untangle access flows hands-on as a senior technical anchor.
  • •Codify governance by building self-service identity workflows, automated controls, and identity KPIs, translating compliance policies into code and shifting ownership to business leaders.

Pay and Benefits

Perks:Annual BonusSocial Budget

Key Requirements

  • •Proven experience designing, building, or scaling Identity and Access programs in fast-paced, complex environments.
  • •Hands-on expertise with workforce identity lifecycle processes (JML, SoD, certifications) and enterprise identity governance platforms (e.g., SailPoint, Saviynt, Okta).
  • •Strong protocol knowledge including SAML, OAuth2, OpenID Connect, and SCIM, plus RBAC/ABAC models.
  • •Pragmatic operator mindset balancing least-privilege security with business usability and velocity.
  • •Ability to multitask between enterprise identity strategy and troubleshooting immediate access escalations.
Experience:Fintech
Skills:MentoringDocumentationPatiencePersistenceNegotiation
Tech Stack:SAMLOAuth2OpenID ConnectSCIMZero TrustAdaptive MFARBACABACSailPointSaviyntOkta

Company Brief

dLocal
Provides cross-border payments and financial infrastructure enabling global merchants to collect payments, manage payouts, and reconcile transactions across emerging markets through a unified payments platform.
Industry: Payments
Company Size: Enterprise (1,001+ employees)
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Montevideo, Uruguay
Founded: 2016
WebsiteLinkedIn