
Senior Staff IAM Engineer
Posted 1 hour ago

Posted 1 hour ago
This is a fully remote position, open to applicants in United States.
• Take ownership of the target-state identity architecture across various identity types, including workforce, non-employee, external, non-human, and AI agent identities.
• Establish identity standards, reference patterns, and architecture decision records.
• Manage Auth0 customer identity architecture, encompassing tenant and organization modeling, MFA, phishing-resistant authentication, and machine-to-machine patterns.
• Distinguish customer and patient identity from the workforce domain and design identity models for external partners, developers, and B2B customers.
• Architect the consolidation of authentication paths into a single workforce IdP.
• Develop SSO, SCIM provisioning, and automated deprovisioning patterns for applications handling sensitive data.
• Define federation and directory architecture across Okta, Entra ID, AWS, and GCP, including integration patterns for subsidiaries and acquisitions.
• Build Identity Security Posture Management, enhancing the posture warehouse and remediation engine.
• Specify identity posture metrics and incorporate identity threat detection and response into the current SIEM.
• Design access controls compliant with HIPAA, HITRUST, and SOC 2, while maintaining architecture documentation and control mappings.
• Act as the design authority between identity-risk and engineering functions, offering architectural remediation paths.
• Deliver a validated target-state architecture, customer identity architecture, workforce IdP consolidation architecture, and a production Identity Security Posture Management baseline.
• Minimum of 8 years in identity and access management, security engineering, or platform architecture.
• A minimum of 3 years in a staff, principal, or architect role.
• Extensive hands-on experience with customer identity, specifically in designing and implementing a CIAM platform end to end, preferably with Auth0.
• Proficient in Auth0 tenant and organization modeling, MFA, and machine-to-machine authentication.
• Strong expertise in SAML, OIDC, OAuth 2.0, SCIM, WebAuthn, and FIDO2.
• Experience with enterprise workforce IdP architecture using Okta or a similar solution.
• Familiarity with migrating from legacy or fragmented authentication systems.
• Ability to set architectural direction and achieve engineering buy-in without direct authority.
• Excellent written communication skills, including the creation of architecture decision records and reference designs.
• Preferred: Knowledge of HIPAA/PHI safeguards or similar access requirements in regulated industries.
• Preferred: Experience with identity governance, joiner-mover-leaver lifecycle, RBAC, access certification, segregation of duties, and platforms like SailPoint ISC/NERM.
• Preferred: Understanding of cloud PAM and zero-standing-privilege models, particularly with tools like Britive or similar.
• Preferred: Experience with cloud-native identity solutions across AWS, GCP, and Azure.
• Preferred: Background in Identity Security Posture Management, identity threat detection, and SIEM integration.
• Preferred: Experience with non-human identities, service account governance, secrets management, or AI agent identities.
• Preferred: Familiarity with Terraform for identity infrastructure as code.
• Preferred: Knowledge of HITRUST, SOC 2, or SOX access controls.
• Preferred: Relevant certifications such as CISSP, CISSP-ISSAP, CISM, TOGAF, SABSA, Okta, Auth0, SailPoint, or professional-level cloud architect certification.
• Preferred: Experience in digital health, telehealth, or another regulated high-growth environment.
• Authorization to work in the job posting location.
• Medical, Dental, and Vision plans.
• Flexible Spending/Health Savings Accounts.
• Flexible PTO.
• 401(k) with Company Match.
• Life Insurance.
• Pet insurance.
Databricks
Tailscale
ABB
Get handpicked remote jobs straight to your inbox weekly.