Designs and governs enterprise identity architecture across workforce, customer, partner, non-human, and AI agent identities. The role requires 8+ years in IAM, deep CIAM and Auth0 experience, federation expertise, and the ability to implement secure, auditable controls in regulated environments.
Salary not listed
Remote8+ YOESecurity Engineering
About the role
Responsibilities
Own target-state identity architecture across workforce, non-employee, external, non-human, and AI agent identities.
Establish identity standards, reference patterns, and architecture decision records.
Own Auth0 customer identity architecture, including tenant and organization modeling, MFA, phishing-resistant authentication, machine-to-machine patterns, and external and partner use cases.
Separate customer and patient identity from workforce identity and define integration interfaces.
Design external and partner identity models for third-party developers and B2B customers.
Consolidate authentication paths onto a single workforce identity provider.
Design SSO, SCIM provisioning, and automated deprovisioning for applications handling sensitive data.
Define federation and directory architecture across Okta, Entra ID, AWS, and Google Cloud, including subsidiary and acquisition integration patterns.
Build Identity Security Posture Management capabilities, including posture metrics, warehouse extensions, and remediation workflows.
Partner with Security Operations and Security Architecture to integrate identity threat detection and response into the SIEM.
Design access controls supporting HIPAA, HITRUST, and SOC 2 requirements.
Maintain architecture documentation and control mappings.
Serve as design authority between identity risk and engineering remediation functions.
Requirements
8+ years in identity and access management, security engineering, or platform architecture, including at least 3 years at staff, principal, or architect level.
Hands-on experience designing and delivering CIAM platforms end to end, ideally Auth0.
Strong knowledge of SAML, OIDC, OAuth 2.0, SCIM, WebAuthn, and FIDO2.
Enterprise workforce identity provider architecture experience, including migration from legacy or fragmented authentication sources.
Ability to set architectural direction and drive adoption without direct authority.
Clear written communication, including architecture decision records and reference designs.
Preferred Qualifications
Experience designing HIPAA and PHI safeguards or comparable regulated-industry access controls.
Identity governance experience with joiner-mover-leaver lifecycle, RBAC, access certification, and segregation of duties.
Experience with SailPoint ISC, NERM, or comparable IGA and non-employee lifecycle platforms.
Cloud PAM and zero-standing-privilege experience, particularly Britive or similar tooling.
Cloud-native identity experience across AWS, Google Cloud, and Azure.
Experience migrating from AWS Cognito, Google Sign-In, or similar identity systems.
Experience building Identity Security Posture Management or identity threat detection capabilities and integrating identity telemetry with a SIEM.
Experience with non-human identity, service account governance, secrets management, or AI agent identity.
Infrastructure as code experience for identity, including Terraform.
Experience with HITRUST, SOC 2, or SOX access controls.
Certifications such as CISSP, CISSP-ISSAP, CISM, TOGAF, SABSA, Okta, Auth0, SailPoint, or professional-level cloud architect certifications.
Experience in digital health, telehealth, or another regulated, high-growth environment.
Success Measures
Target-state identity architecture is approved, published, adopted, and supported by decision records.
Customer identity architecture is complete and interactive login is delivered to production for external and partner use cases.
Engineering adopts the workforce identity consolidation architecture and application migration progresses measurably.
Identity Security Posture Management metrics, drift alerting, and remediation are in production, with high-severity findings declining.
Audit evidence and control mappings are traceable directly to architecture documentation.
Leads AI security strategy, architecture, governance, and defensive controls across the organization while mentoring security engineers. Requires 9+ years of security engineering experience and deep knowledge of AI, AWS security services, identity protocols, and emerging AI attack frameworks.
Salary not listedRemote9+ YOESecurity Engineering
Staff Software Engineer, Product Security
SnowflakeMenlo Park, CA +1
Leads product security architecture and builds security-critical services, frameworks, and controls across engineering teams. The role requires 10+ years of software engineering experience, deep expertise in secure distributed systems, and strong cross-team technical leadership.
236k – 339k/yrHybrid10+ YOESecurity Engineering
Staff Security Engineer
MozillaUnited States
Leads Mozilla’s security compliance and governance programs, maintaining the ISMS and supporting ISO 27001 and SOC 2 Type 2 audits. The role requires at least five years of information security or GRC experience, strong policy and remediation expertise, and effective cross-functional collaboration.
139k – 218k/yrRemote7+ YOESecurity Engineering
Staff Security Engineer
MozillaUnited States
Maintains Mozilla’s information security management system and leads ISO 27001 and SOC 2 compliance activities, including audit readiness, policy governance, remediation tracking, and stakeholder coordination. Requires at least five years in information security, GRC, or compliance and strong audit experience.
Salary not listedRemote7+ YOESecurity Engineering
Staff+ Software Engineer, Privacy
AnthropicSan Francisco, CA +2
This foundational privacy engineering role designs privacy-preserving architectures, infrastructure, governance systems, and compliance controls for large-scale AI training and inference. It requires substantial software engineering experience, privacy expertise, and technical leadership across engineering, research, legal, and product teams.