Senior Security Engineer, IAM

Posted Aug 21

This is a fully remote position, open to applicants in Alabama, +36 more states.

📋 Description

• Establish the strategic direction for the enterprise IAM function, positioning identity as a key defense-in-depth control plane.

• Oversee the architecture, strategy, and operational maturity of AI-driven identity technologies across workforce, customer, and non-human identity sectors.

• Create an identity architecture that encompasses workforce, machine, and workload identities.

• Enhance continuous adaptive trust capabilities, including ongoing access evaluations, risk-based and phishing-resistant authentication, and signal-driven session revocation.

• Design and refine ZTNA, implement least-privilege micro-segmentation, MFA/FIDO2, and JIT access protocols.

• Develop and optimize SSO, federation, and authentication standards across SaaS and multi-cloud ecosystems.

• Define and calibrate hardening standards utilizing CIS Benchmarks/DISA STIGs with automated compliance validation.

• Design and streamline identity lifecycle automation, integrating HR systems, directories, and downstream applications.

• Engineer IGA capabilities such as access reviews, certification campaigns, and enforcement of segregation-of-duties.

• Direct the implementation and optimization of PAM, including credential vaulting, JIT elevation, and session monitoring.

• Establish governance for non-human identities with automated drift detection and policy-as-code enforcement.

• Integrate identity telemetry into SIEM/SOAR and UEBA detection frameworks.

• Develop incident-response playbooks focused on identity issues.

• Utilize threat intelligence to prioritize remediation of identity exposure and lead identity-centric purple team initiatives.

• Design identity controls embedded within AI-augmented CI/CD pipelines.

• Define and monitor identity KPIs.

• Collaborate with GRC on identity controls that comply with SOX, SOC 2, ISO 27001, HIPAA, GDPR, and CCPA.

• Assist with audits, certifications, e-discovery, and forensic integrity requirements.

• Provide technical guidance and mentorship to Advanced and Engineer-level identity engineers.


⛳️ Requirements

• Bachelor's degree in Computer Science, Information Security, or equivalent experience.

• Over 8 years of practical experience in enterprise IAM or security engineering, with a strong focus on identity, authentication, and access domains.

• Alternatively, a Master's degree in Cybersecurity or a related field with at least 6 years of experience.

• Extensive hands-on experience in architecting and managing identity platforms, including IdP/SSO (Okta, Entra ID/Azure AD, Ping), IGA (SailPoint, Saviynt), and PAM (CyberArk, BeyondTrust).

• Advanced understanding of SAML, OIDC, OAuth 2.0, SCIM, LDAP, and Kerberos.

• Proven experience leading identity threat detection, complex access investigations, and detection-engineering initiatives.

• Skilled in designing automation for access enforcement and observability.

• Working knowledge of MITRE, NIST 800-63, and Zero Trust principles.

• Proficient in at least one scripting/automation language: Python, Bash, or PowerShell.

• Experience applying scripting to containerized services, CLI-based commands, and identity-specific scenarios.

• Demonstrated ability to mentor engineers and clearly communicate technical strategies and findings.

• Experience in securing SaaS, cloud-native, or globally distributed regulated environments.

• Cloud IAM experience across AWS, Azure, or GCP.

• Experience securing non-human/workload identities at scale.

• Familiarity with AI-augmented security and governance for AI-assisted and agentic identity workflows.

• Experience embedding identity and access controls into CI/CD pipelines and infrastructure-as-code environments.

• Knowledge of legal technology, e-discovery, litigation holds, and digital forensics chain-of-custody requirements.

• Experience leading compliance and audit engagements from an identity and access control perspective.

• Relevant certifications such as CISSP, CISM, GCIH, GCFA, CCSP, AWS Security Specialty, SC-300, or AZ-500.


🏝️ Benefits

• Comprehensive health, dental, and vision insurance plans.

• Parental leave available for both primary and secondary caregivers.

• Flexible work arrangements to promote work-life balance.

• Two week-long company breaks each year.

• Additional time off to support personal needs.

• Long-term incentive program to reward employee contributions.

• Investment in training programs for professional development.

• Annual performance bonuses to recognize individual achievements.

• Long-term incentives to encourage employee retention.

People also viewed

GitLab20 hours ago

Staff Security Researcher

US flagUnited States, +2 more countriesFull-timeCybersecurity / Security Engineer$168k – $238k/year
ApplyView job
GitLab20 hours ago

Principal Security Researcher

US flagUnited States, +2 more countriesFull-timeCybersecurity / Security Engineer$203.2k – $275k/year
ApplyView job
Cisco20 hours ago

Software Security Lead

US flagNorth Carolina OnlyFull-timeCybersecurity / Security Engineer$151.6k – $222.4k/year
ApplyView job
Lovesac20 hours ago

Senior Engineer, Information Security Architect

US flagConnecticut OnlyFull-timeCybersecurity / Security Engineer$95k – $125k/year
ApplyView job
General Dynamics Information Technology1 day ago

Cybersecurity Architect

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$149.5k – $184k/year
ApplyView job
PGTEK1 day ago

Senior Security Agent / AI Red Team Engineer

US flagVirginia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers