Skip to content
ConfluentConfluent

Staff Security Risk & Compliance Program Manager

Own and evolve Confluent's internal access management program with focus on machine/workload identity, S2S auth, non-human identities, and AI agent controls. Set the Access Management Standard, own metrics/reporting/OKRs, and drive governance, risk reduction, and cross-functional execution for least-privilege outcomes.

About the job

What You Will Do

Strategy and Leadership

  • Own the strategic direction and roadmap for Confluent's internal access management program, with machine and workload identity as the durable center of gravity.
  • Drive the program's maturity model from control-building toward sustained governance and least-privilege outcomes.

Machine & Workload Identity

  • Lead the program to enforce service-to-service (S2S) authentication across Trust & Security-owned surfaces, taking ownership of the enforcement hand-off from the identity engineering team.
  • Formalize non-human identity (NHI) — service accounts, keys, and workload credentials — from pilot into a funded, governed program.
  • Stand up access controls for AI agents as agentic workloads acquire production access.

Access Governance & Standards

  • Own the Access Management Standard and the policies that operationalize least privilege, separation of duties, and periodic access review across human and machine access.
  • Ensure the standard keeps pace with the evolving access surface and remains audit-ready.

Metrics, Reporting & Governance Cadence

  • Own access metrics and reporting (e.g., JIT/unilateral-access volume, broad-privilege usage, prod-access reduction).
  • Define and track program OKRs and run the monthly execution and executive-review cadence, articulating risk posture and progress to senior leadership.

Cross-Functional Execution & Transitions

  • Drive cross-functional delivery with engineering, platform, and identity teams without direct authority.

Integration with GRC and Partner Functions

  • Ensure the access management program is tightly integrated with adjacent GRC domains and partner teams (Insider Threat, IT/Identity, Detection & Response, and engineering owners), with clear RACI across governance and operations.

What You Will Bring

Experience

  • 8+ years in security program management, identity & access management, or a closely related security discipline.
  • At least 3 years running an enterprise- or platform-scale access program in a technology company.

Technical Skills

  • Deep expertise in identity and access management concepts: least privilege, separation of duties, RBAC/ABAC, just-in-time (JIT) and privileged access management (PAM), and access review/certification.
  • Working knowledge of machine and workload identity — service-to-service authentication, non-human identity, service accounts, secrets/key management, and emerging AI-agent access patterns.
  • Strong security engineering fundamentals across cloud infrastructure security controls in GCP, AWS, and/or Azure, including Kubernetes and cloud control-plane access models.
  • Familiarity with identity platforms and access tooling (e.g., Okta, JIT/access-orchestration tooling) and how access controls are enforced in production.

Tooling and Automation

  • Experience integrating access processes, controls, or findings into GRC and access-orchestration platforms.
  • Bias toward automating access decisions over manual operations.

Program Management Skills

  • Strong project management and organizational skills.
  • Exceptional analytical and problem-solving skills, with a data-driven approach to decision-making.
  • Experience running long-term, complex security programs that deliver iterative, measurable risk reduction.

Communication and Collaboration Skills

  • Excellent written and verbal communication, with the ability to influence and lead without direct authority across engineering and security teams.
  • Ability to articulate complex technical concepts and program status to executive-level audiences and technical teams alike.

Skills

Identity And Access Management, Least Privilege, RBAC, Abac, Jit Access, Pam, Non-Human Identity, Service-To-Service Authentication, Secrets Management, GCP, AWS, Azure, Kubernetes, Okta

Reddit

Reddit

United States

Staff Software Engineer - Site Defense
$217k+/yrRemote7+ YOESecurity Engineering

Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.

Harvey

Harvey

San Francisco, CA

Staff Security Software Engineer, IAM
$231k+/yrHybrid10+ YOESecurity Engineering

Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.

Upside

Upside

Washington, DC
Staff Application Security Engineer
$210k+/yrRemote6+ YOESecurity Engineering

Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.

Gusto

Gusto

San Francisco, CA

Senior Staff IT Controls, Enterprise Applications
$245k+/yrHybrid10+ YOESecurity Engineering

Own and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.

Lob

Lob

United States

Staff Security Engineer, Cloud and Product Security
$198k+/yrRemote8+ YOESecurity Engineering

Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.