
Senior Security Engineer, IAM
Posted Aug 21

Posted Aug 21
This is a fully remote position, open to applicants in Alabama, +36 more states.
• Establish the strategic direction for the enterprise IAM function, positioning identity as a key defense-in-depth control plane.
• Oversee the architecture, strategy, and operational maturity of AI-driven identity technologies across workforce, customer, and non-human identity sectors.
• Create an identity architecture that encompasses workforce, machine, and workload identities.
• Enhance continuous adaptive trust capabilities, including ongoing access evaluations, risk-based and phishing-resistant authentication, and signal-driven session revocation.
• Design and refine ZTNA, implement least-privilege micro-segmentation, MFA/FIDO2, and JIT access protocols.
• Develop and optimize SSO, federation, and authentication standards across SaaS and multi-cloud ecosystems.
• Define and calibrate hardening standards utilizing CIS Benchmarks/DISA STIGs with automated compliance validation.
• Design and streamline identity lifecycle automation, integrating HR systems, directories, and downstream applications.
• Engineer IGA capabilities such as access reviews, certification campaigns, and enforcement of segregation-of-duties.
• Direct the implementation and optimization of PAM, including credential vaulting, JIT elevation, and session monitoring.
• Establish governance for non-human identities with automated drift detection and policy-as-code enforcement.
• Integrate identity telemetry into SIEM/SOAR and UEBA detection frameworks.
• Develop incident-response playbooks focused on identity issues.
• Utilize threat intelligence to prioritize remediation of identity exposure and lead identity-centric purple team initiatives.
• Design identity controls embedded within AI-augmented CI/CD pipelines.
• Define and monitor identity KPIs.
• Collaborate with GRC on identity controls that comply with SOX, SOC 2, ISO 27001, HIPAA, GDPR, and CCPA.
• Assist with audits, certifications, e-discovery, and forensic integrity requirements.
• Provide technical guidance and mentorship to Advanced and Engineer-level identity engineers.
• Bachelor's degree in Computer Science, Information Security, or equivalent experience.
• Over 8 years of practical experience in enterprise IAM or security engineering, with a strong focus on identity, authentication, and access domains.
• Alternatively, a Master's degree in Cybersecurity or a related field with at least 6 years of experience.
• Extensive hands-on experience in architecting and managing identity platforms, including IdP/SSO (Okta, Entra ID/Azure AD, Ping), IGA (SailPoint, Saviynt), and PAM (CyberArk, BeyondTrust).
• Advanced understanding of SAML, OIDC, OAuth 2.0, SCIM, LDAP, and Kerberos.
• Proven experience leading identity threat detection, complex access investigations, and detection-engineering initiatives.
• Skilled in designing automation for access enforcement and observability.
• Working knowledge of MITRE, NIST 800-63, and Zero Trust principles.
• Proficient in at least one scripting/automation language: Python, Bash, or PowerShell.
• Experience applying scripting to containerized services, CLI-based commands, and identity-specific scenarios.
• Demonstrated ability to mentor engineers and clearly communicate technical strategies and findings.
• Experience in securing SaaS, cloud-native, or globally distributed regulated environments.
• Cloud IAM experience across AWS, Azure, or GCP.
• Experience securing non-human/workload identities at scale.
• Familiarity with AI-augmented security and governance for AI-assisted and agentic identity workflows.
• Experience embedding identity and access controls into CI/CD pipelines and infrastructure-as-code environments.
• Knowledge of legal technology, e-discovery, litigation holds, and digital forensics chain-of-custody requirements.
• Experience leading compliance and audit engagements from an identity and access control perspective.
• Relevant certifications such as CISSP, CISM, GCIH, GCFA, CCSP, AWS Security Specialty, SC-300, or AZ-500.
• Comprehensive health, dental, and vision insurance plans.
• Parental leave available for both primary and secondary caregivers.
• Flexible work arrangements to promote work-life balance.
• Two week-long company breaks each year.
• Additional time off to support personal needs.
• Long-term incentive program to reward employee contributions.
• Investment in training programs for professional development.
• Annual performance bonuses to recognize individual achievements.
• Long-term incentives to encourage employee retention.
GitLab
GitLab
Cisco
Lovesac
Get handpicked remote jobs straight to your inbox weekly.