[TECH] IAM Support Engineer
HelloFresh
| Company | HelloFresh |
| Category | Uncategorised |
| Location | Warszawa |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 15 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
Work with HelloFresh in Warsaw and its HelloTech organisation, HelloFresh’s global technology backbone with more than 1000 people, building the digital products that power our end-to-end food experience. From meal kits and ready-to-eat meals to specialty offerings like pet food and premium meat & seafood, HelloTech creates the platforms that bring tailored food solutions to millions of customers every month.
Our subscription-based, direct-to-consumer model relies on technology at every step, from customer-facing apps and personalization logic to pricing, forecasting, supply chain optimization, and initiatives that help reduce food waste. While our brands operate independently to serve distinct customer needs, they are united by shared platforms, data, and operational excellence built by HelloTech.
HelloTech works in autonomous, cross-functional alliances, each owning a specific product or domain end to end. By working with our Warsaw office, you will help shape scalable, data-driven products used across our markets, working with a modern tech stack and international teams to continuously improve how people discover, order, and enjoy HelloFresh’s products, today and in the future.
About the role: What's in the Box
Our Identity and Access Management (IAM) team has completed a full transformation of the employee identity lifecycle — replacing manual processes with a fully automated platform spanning 17 countries. As our L2 IAM Support Engineer , you will be the operational backbone of this platform.
You will resolve identity lifecycle issues, own application onboarding end-to-end, administer MFA and Privileged Identity Management, and support identity and access initiatives across the organisation. Working closely with our Senior IAM Engineer, you will also identify patterns in the request queue, propose automation where manual effort is recurring, and contribute to audit and compliance reporting.
This is a hands-on role for someone who takes ownership, thinks beyond the ticket, and consistently looks for ways to improve the systems they operate.
At HelloTech, flexibility and cross-functional collaboration are core to how we work. While this role is aligned to a specific Alliance, strong candidates may also be considered for opportunities across different teams or projects.
What you’ll do: The Recipe
Resolve identity lifecycle issues: diagnosing provisioning failures, attribute sync errors, and access anomalies across our automated Joiner/Mover/Leaver platform.
Own end-to-end application onboarding: configuring SSO (SAML, OIDC), claim mapping, and automated user provisioning via SCIM into Microsoft Entra ID.
Administer MFA and modern authentication: handling resets, Passwordless rollouts, and security key deployments in line with security policy.
Manage Privileged Identity Management (PIM): processing role activation requests, running access reviews, and ensuring least-privilege is maintained.
Investigate sign-in anomalies and access failures: producing compliance reports and identity dashboards to support audit and governance cycles.
Identify recurring manual tasks: surfacing opportunities for automation and working with the Senior IAM Engineer to drive lasting solutions.
Act as the technical bridge between L1 and the Senior IAM Engineer: leaving every process better documented than you found it.
What you’ll bring: The Ingredients
Hands-on experience with Microsoft Entra ID: including user and group management, enterprise application registration, access governance, and Privileged Identity Management (PIM).
A proven ability to troubleshoot identity lifecycle issues: in an automated provisioning environment, including diagnosing sync failures and access anomalies.
Hands-on experience with federation protocols: SAML, OAuth 2.0, and OpenID Connect, with practical experience configuring SSO & SCIM integrations.
Experience administering
You found the opening. Now track it.Tracker, radar and AI drafts in one place.erioun.com →