# Sr. Staff IAM Engineer

**Company:** [OpenLoop](https://hotfix.jobs/companies/openloop)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 8+ years
**Skills:** IAM, auth0, Okta, sailpoint isc, SAML, OIDC, oauth 2.0, SCIM, webauthn, fido2, Terraform, AWS, GCP, Azure, RBAC
**Posted:** 2026-08-10

> Designs and governs enterprise identity architecture across workforce, customer, partner, non-human, and AI agent identities. The role requires 8+ years in IAM, deep CIAM and Auth0 experience, federation expertise, and the ability to implement secure, auditable controls in regulated environments.

## Job Description

## Responsibilities
- Own target-state identity architecture across workforce, non-employee, external, non-human, and AI agent identities.
- Establish identity standards, reference patterns, and architecture decision records.
- Own Auth0 customer identity architecture, including tenant and organization modeling, MFA, phishing-resistant authentication, machine-to-machine patterns, and external and partner use cases.
- Separate customer and patient identity from workforce identity and define integration interfaces.
- Design external and partner identity models for third-party developers and B2B customers.
- Consolidate authentication paths onto a single workforce identity provider.
- Design SSO, SCIM provisioning, and automated deprovisioning for applications handling sensitive data.
- Define federation and directory architecture across Okta, Entra ID, AWS, and Google Cloud, including subsidiary and acquisition integration patterns.
- Build Identity Security Posture Management capabilities, including posture metrics, warehouse extensions, and remediation workflows.
- Partner with Security Operations and Security Architecture to integrate identity threat detection and response into the SIEM.
- Design access controls supporting HIPAA, HITRUST, and SOC 2 requirements.
- Maintain architecture documentation and control mappings.
- Serve as design authority between identity risk and engineering remediation functions.

## Requirements
- 8+ years in identity and access management, security engineering, or platform architecture, including at least 3 years at staff, principal, or architect level.
- Hands-on experience designing and delivering CIAM platforms end to end, ideally Auth0.
- Strong knowledge of SAML, OIDC, OAuth 2.0, SCIM, WebAuthn, and FIDO2.
- Enterprise workforce identity provider architecture experience, including migration from legacy or fragmented authentication sources.
- Ability to set architectural direction and drive adoption without direct authority.
- Clear written communication, including architecture decision records and reference designs.

## Preferred Qualifications
- Experience designing HIPAA and PHI safeguards or comparable regulated-industry access controls.
- Identity governance experience with joiner-mover-leaver lifecycle, RBAC, access certification, and segregation of duties.
- Experience with SailPoint ISC, NERM, or comparable IGA and non-employee lifecycle platforms.
- Cloud PAM and zero-standing-privilege experience, particularly Britive or similar tooling.
- Cloud-native identity experience across AWS, Google Cloud, and Azure.
- Experience migrating from AWS Cognito, Google Sign-In, or similar identity systems.
- Experience building Identity Security Posture Management or identity threat detection capabilities and integrating identity telemetry with a SIEM.
- Experience with non-human identity, service account governance, secrets management, or AI agent identity.
- Infrastructure as code experience for identity, including Terraform.
- Experience with HITRUST, SOC 2, or SOX access controls.
- Certifications such as CISSP, CISSP-ISSAP, CISM, TOGAF, SABSA, Okta, Auth0, SailPoint, or professional-level cloud architect certifications.
- Experience in digital health, telehealth, or another regulated, high-growth environment.

## Success Measures
- Target-state identity architecture is approved, published, adopted, and supported by decision records.
- Customer identity architecture is complete and interactive login is delivered to production for external and partner use cases.
- Engineering adopts the workforce identity consolidation architecture and application migration progresses measurably.
- Identity Security Posture Management metrics, drift alerting, and remediation are in production, with high-severity findings declining.
- Audit evidence and control mappings are traceable directly to architecture documentation.

## Benefits
- Medical, dental, and vision plans
- Flexible Spending and Health Savings Accounts
- Flexible PTO
- 401(k) with company match
- Life insurance
- Pet insurance and additional benefits

## Similar roles

- [Staff Security Engineer, Walrus](https://hotfix.jobs/jobs/4ba77cb9-dbba-48ea-b5b7-7affe4c71be8) - Mysten Labs - Remote - $180k – $264k/yr
- [Staff AI Security Engineer](https://hotfix.jobs/jobs/5a435093-4e6c-4cca-8f51-861a7b1eee13) - Addepar - Remote
- [Staff Software Engineer, Product Security](https://hotfix.jobs/jobs/cd68f0e2-103b-44f9-b936-c61589852d6e) - Snowflake - Menlo Park, CA - $236k – $339k/yr
- [Staff Security Engineer](https://hotfix.jobs/jobs/e2df08d8-72b2-497f-a46c-a4cf08c27cb7) - Mozilla - Remote - $139k – $218k/yr
- [Staff Security Engineer](https://hotfix.jobs/jobs/8b105bcc-9ee5-437e-ba10-39c400771fe6) - Mozilla - Remote

**Apply:** https://hotfix.jobs/jobs/1ab693f3-0703-4d3c-9e94-c0acbb58fc79
**Canonical:** https://hotfix.jobs/jobs/1ab693f3-0703-4d3c-9e94-c0acbb58fc79