DevOps/CloudSecurityAround since 2010

IAM

Also written as Identity and Access Management

The system cloud providers use to control who (which users, or which services) can access which resources, and what they're allowed to do with them.

Think of it like

Like a building's keycard system — each card (user or service) is programmed to open only the specific doors it's been granted, nothing more.

Junior or senior?

Junior sounds like

Grants broad admin access for convenience.

Senior sounds like

Follows least privilege and can describe a time overly broad permissions caused a real problem.

Ask them

“Tell me about a time overly broad permissions caused a problem, or a time you had to lock down access that was too wide.”