CSS
Luzern / hybrid
Senior Identity and Access Management Engineer (m/f) 80-100%
- 30 June 2026
- 80 – 100%
- Permanent position
- 6002 Luzern / hybrid
About the job
Stability and change - do they fit together? At CSS, they do. We give our all for the best IT solutions - and the special thing: we do almost everything ourselves. We are building a central IAM platform that enables employees, customers, partners and systems secure and uniform access to our services. Our IAM is evolving from a reactive administrator to a proactive business enabler and directly supports the strategic goals of CSS.
As an IAM Engineer, you put "one login for everything" into practice: You implement seamless Single Sign-on, improve the user experience with modern, smooth login processes and actively support our transformation to a Zero Trust Enterprise. You can expect a heterogeneous system landscape of enterprise applications and modern cloud solutions, plenty of creative freedom with a generous home office share and room for your development. When do we meet?
As an IAM Engineer, you put "one login for everything" into practice: You implement seamless Single Sign-on, improve the user experience with modern, smooth login processes and actively support our transformation to a Zero Trust Enterprise. You can expect a heterogeneous system landscape of enterprise applications and modern cloud solutions, plenty of creative freedom with a generous home office share and room for your development. When do we meet?
Senior Identity and Access Management Engineer (m/f) 80-100%
This is what your day looks like
- Build & Run of the core IAM platforms: You develop, operate and optimise our IAM platform focusing on Okta, Auth0, Entra ID and Keycloak. The central identity broker becomes the hub that unifies login procedures and consistently serves identities across all channels.
- Orchestrate multiple IdPs: You know the strengths of various identity providers (Entra ID for the Microsoft and cloud ecosystem, Okta and Auth0 for SaaS as well as B2C/B2B scenarios, Keycloak for specific applications and self-hosting) and orchestrate them into a consistent overall solution - including federation, SSO and standardised flows (SAML, OIDC, OAuth).
- Modern authentication & federation: The new platform fundamentally supports modern authentication methods (MFA, app-based procedures, e-ID) and identity federations. You design and implement these procedures, thereby consistently securing both our cloud strategy and the services on the integration platform.
- Living CI/CD & automation: You automate deployments with Terraform, build and maintain CI/CD pipelines and ensure that our IAM services are deployed reproducibly, scalably and auditable.
- Shaping IAM as a business enabler: You think of IAM not only technically but also from a business perspective: You support digital initiatives, reduce friction losses in access and help position our IAM as an enabler for new services and business models.
- Shaping the IAM team: We are establishing a central IAM team with clear responsibility for EIAM, CIAM, PIAM and PAM. You contribute your engineering expertise and help establish a unified strategy, architecture and efficient governance.
What you bring with you
- Experience in identity & access management: You have at least 5 years of experience in the IAM field, ideally in complex, hybrid environments.
- Know-how in modern IAM tools & IdPs: You know Okta and Auth0 from practice and have experience with Entra ID (including Conditional Access, MFA, app registrations) and Keycloak or comparable IdP/IAM solutions. Experience with NetIQ and NEXIS is a plus.
- Automation & engineering skills: You are confident in handling Terraform and CI/CD pipelines as well as scripting (e.g. PowerShell, Python). APIs and integrations are naturally part of your engineering routine.
- Understanding of IAM disciplines: You have profound knowledge in authentication, authorisation as well as role and permission models. PAM and common security standards / Zero Trust are well known to you.
- Working style & mindset: You enjoy driving things forward, sharing your knowledge and taking responsibility. Structured, independent working and high initiative are among your strengths.
CSS Insurance
6002 Lucerne / hybrid
6002 Lucerne / hybrid