
Senior Security Engineer – Identity and Access Management
Posted 20 hours ago

Posted 20 hours ago
This is a fully remote position, open to applicants in United States, +7 more locations.
• Take full responsibility for the identity lifecycle from start to finish for individuals, service accounts, and AI agents.
• Develop automation that allocates entitlements based on genuine needs and removes them automatically.
• Create and design access models that are based on data classification.
• Ensure that time-limited access is the standard for critical data.
• Engineer identity as code, incorporating provisioning logic, entitlement policies, and access review rules under version control and testing across Okta, Lumos, and AWS IAM.
• Develop tooling powered by AI and LLM for ongoing access reviews and entitlement anomaly detection.
• Define ownership, purpose, and expiration for service accounts, workload identities, integrations, and AI agents.
• Assess access levels and report opportunities to minimize unnecessary entitlements.
• Collaborate with Engineering, Enterprise IT, and Compliance to integrate identity controls.
• Assist in identity-focused detection and incident response, including access containment, identity access reconstruction, and blameless retrospectives.
• Over 5 years of experience in identity and access management, security engineering, or software engineering with significant responsibility for identity systems.
• Practical experience with enterprise identity providers such as Okta, including SAML, OIDC, SCIM, and lifecycle automation.
• Experience managing identity across an enterprise SaaS landscape like Google Workspace, Salesforce, and Workday, including SCIM provisioning and group-driven entitlements.
• Background in cloud IAM, preferably AWS, including policy design and short-lived credentials.
• Strong software engineering principles with proficiency in Python, Go, or a similar programming language.
• Practical use of AI and LLM tooling and agent-based coding tools in production engineering tasks.
• Preferred experience includes identity work in regulated sectors and producing access control evidence for PCI DSS, HIPAA, SOC 2, or ISO 27001 audits.
• Preferred familiarity with identity infrastructure as code and access request or governance tools such as Terraform and Lumos.
• Preferred experience in mobile device management in conjunction with identity, such as Kandji integrated with Okta.
• Preferred knowledge of non-human, workload, and privileged access, including secrets management and service-to-service authentication.
• Preferred experience in developing AI or LLM-powered tools for security or identity workflows.
• Preferred background in detection and incident response for identity-related incidents.
• Industry certifications in identity or security are preferred, such as IDPro CIDPRO, Okta certifications, AWS Certified Security – Specialty, or CISSP.
• Candidates must reside within approximately 50 miles of Austin, Seattle, Washington, DC, San Francisco, or Boston, or within commuting distance of the London or Netherlands locations.
• Visa/work permit sponsorship is not available.
• Employment is subject to a background check.
• Health insurance (medical, vision, dental), life insurance, and disability coverage.
• Equity stock options.
• Retirement plans.
• Paid public holidays and unlimited paid time off (PTO).
• Paid maternity and parental leave.
• Leaves of absence, including caregiver leave and leave under CO's Healthy Families and Workplaces Act.
• Employee Assistance Program.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.