
Staff Security Engineer, IAM
Posted Aug 31

Posted Aug 31
This is a fully remote position, open to applicants in United States, +1 more country.
• Develop comprehensive identity and AI access solutions, encompassing AI agent governance frameworks and privileged access workflows with just-in-time provisioning.
• Transition low-code automation to engineered Python services on GCP Cloud Run, integrating source control, testing, CI, and observability.
• Implement Okta, Lumos, and non-human identity platforms using Terraform/OpenTofu/Pulumi, transitioning click-ops to peer-reviewed infrastructure-as-code.
• Redesign identity and access across GCP and AWS organizations, focusing on resource hierarchy, secure-by-default guardrails, workload identity federation, and least-privilege access.
• Oversee identity and access engineering for enterprise AI platforms, including administration, SSO and SCIM integration, audit logging, data controls, and policy enforcement.
• Create monitoring and management solutions for service accounts, API keys, certificates, AI agents, and MCP integrations; implement and operationalize the NHI platform.
• Propel cross-functional initiatives in collaboration with Security, IT, Engineering, Enterprise AI, and the Office of the CIO.
• Guide senior and intermediate engineers in technical implementation and strategic thinking.
• Extensive experience in IAM, designing and implementing enterprise-scale solutions, with proven time spent at a Staff or senior IC level.
• Advanced expertise in Okta, including Identity Engine, complex authentication policies, lifecycle workflows, and API automation.
• Strong proficiency in infrastructure-as-code practices with Terraform/OpenTofu/Pulumi, including experience with provider integrations for SaaS identity platforms and a history of converting click-ops to code.
• Skilled in writing and delivering Python as a software engineer, designed as modular, tested, code-reviewed, deployed as services (GCP Cloud Run or equivalent serverless runtime) and instrumented for failure.
• Depth of knowledge in cloud identity within GCP and/or AWS, encompassing resource hierarchy and organization design, IAM policy models, workload identity federation, and preventive controls such as org policies, SCPs, and permission boundaries.
• Hands-on experience managing or governing enterprise AI platforms (Anthropic Claude preferred; OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or similar acceptable).
• Understanding of AI-specific risks such as prompt injection, MCP attack surface, agent identity, and data leakage.
• Regular engineering practice with AI tools like Claude Code, Cursor, or similar.
• Experience with IGA platforms such as Lumos, ConductorOne, or similar, with a preference for managing them declaratively.
• Background in regulated environments with knowledge of compliance frameworks (FedRAMP, SOC2, SOX), including change management, evidence collection, and audit support.
• Enthusiasm for tackling emerging identity challenges, including AI agent governance, non-human identity management, zero-trust architecture, and behavioral analytics.
• Proven experience in executing a cloud organization restructuring through to completion, encompassing migration and stakeholder engagement.
• Benefits designed to support your health, financial stability, and overall well-being.
• Flexible Paid Time Off.
• Access to Team Member Resource Groups.
• Equity Compensation & Employee Stock Purchase Plan.
• Growth and Development Fund.
• Parental Leave.
Cisco
RELX
TASQ Staffing Solutions
MRO
Get handpicked remote jobs straight to your inbox weekly.