Remotery

Senior Staff IAM Engineer

Posted 1 hour ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Take ownership of the target-state identity architecture across various identity types, including workforce, non-employee, external, non-human, and AI agent identities.

• Establish identity standards, reference patterns, and architecture decision records.

• Manage Auth0 customer identity architecture, encompassing tenant and organization modeling, MFA, phishing-resistant authentication, and machine-to-machine patterns.

• Distinguish customer and patient identity from the workforce domain and design identity models for external partners, developers, and B2B customers.

• Architect the consolidation of authentication paths into a single workforce IdP.

• Develop SSO, SCIM provisioning, and automated deprovisioning patterns for applications handling sensitive data.

• Define federation and directory architecture across Okta, Entra ID, AWS, and GCP, including integration patterns for subsidiaries and acquisitions.

• Build Identity Security Posture Management, enhancing the posture warehouse and remediation engine.

• Specify identity posture metrics and incorporate identity threat detection and response into the current SIEM.

• Design access controls compliant with HIPAA, HITRUST, and SOC 2, while maintaining architecture documentation and control mappings.

• Act as the design authority between identity-risk and engineering functions, offering architectural remediation paths.

• Deliver a validated target-state architecture, customer identity architecture, workforce IdP consolidation architecture, and a production Identity Security Posture Management baseline.


⛳️ Requirements

• Minimum of 8 years in identity and access management, security engineering, or platform architecture.

• A minimum of 3 years in a staff, principal, or architect role.

• Extensive hands-on experience with customer identity, specifically in designing and implementing a CIAM platform end to end, preferably with Auth0.

• Proficient in Auth0 tenant and organization modeling, MFA, and machine-to-machine authentication.

• Strong expertise in SAML, OIDC, OAuth 2.0, SCIM, WebAuthn, and FIDO2.

• Experience with enterprise workforce IdP architecture using Okta or a similar solution.

• Familiarity with migrating from legacy or fragmented authentication systems.

• Ability to set architectural direction and achieve engineering buy-in without direct authority.

• Excellent written communication skills, including the creation of architecture decision records and reference designs.

• Preferred: Knowledge of HIPAA/PHI safeguards or similar access requirements in regulated industries.

• Preferred: Experience with identity governance, joiner-mover-leaver lifecycle, RBAC, access certification, segregation of duties, and platforms like SailPoint ISC/NERM.

• Preferred: Understanding of cloud PAM and zero-standing-privilege models, particularly with tools like Britive or similar.

• Preferred: Experience with cloud-native identity solutions across AWS, GCP, and Azure.

• Preferred: Background in Identity Security Posture Management, identity threat detection, and SIEM integration.

• Preferred: Experience with non-human identities, service account governance, secrets management, or AI agent identities.

• Preferred: Familiarity with Terraform for identity infrastructure as code.

• Preferred: Knowledge of HITRUST, SOC 2, or SOX access controls.

• Preferred: Relevant certifications such as CISSP, CISSP-ISSAP, CISM, TOGAF, SABSA, Okta, Auth0, SailPoint, or professional-level cloud architect certification.

• Preferred: Experience in digital health, telehealth, or another regulated high-growth environment.

• Authorization to work in the job posting location.


🏝️ Benefits

• Medical, Dental, and Vision plans.

• Flexible Spending/Health Savings Accounts.

• Flexible PTO.

• 401(k) with Company Match.

• Life Insurance.

• Pet insurance.

People also viewed

Databricks1 hour ago

Senior Forward Deployed Engineer – Public Sector

US flagWashington OnlyFull-timeEngineer$182k – $250.2k/year
ApplyView job
ClickHouse1 hour ago

Senior Consulting Engineer

AU flagAustralia OnlyFull-timeEngineer
ApplyView job
Tailscale1 hour ago

Windows Engineer

US flagUnited States, +1 more stateFull-timeEngineer$143k – $179k/year
ApplyView job
ABB1 hour ago

Senior Project Engineer, Turbine

US flagPennsylvania OnlyFull-timeEngineer$91.7k – $146.7k/year
ApplyView job
Guidehouse1 hour ago

SailPoint Engineer

US flagUnited States OnlyFull-timeEngineer$113k – $188k/year
ApplyView job
General Dynamics Information Technology1 hour ago

ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services

US flagVirginia OnlyFull-timeEngineer$255k – $345k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers