Security Software Engineer, IAM
Own IAM strategy and architecture across corporate and production environments. Migrate Okta to Terraform, enforce least-privilege access, and drive automation for provisioning and device management.
About the job
What You Will Do
- Own the full IAM strategy for both corporate and production environments - defining the roadmap, standards, and architecture end to end
- Migrate Okta and all related IAM configuration to Terraform, driving infrastructure-as-code adoption and leveling up engineering teams in its use
- Lead Vercel-on-Vercel and Vercel infrastructure cleanup initiatives, ensuring our internal systems reflect the same standards we sell to customers
- Design and enforce least-privilege access controls across cloud, SaaS, and production infrastructure
- Partner with platform and engineering teams to embed IAM best practices early in the design process
- Build and manage MDM/MAM tooling to secure endpoint and mobile device access across the organization
- Drive automation across provisioning, deprovisioning, and access review workflows
- Serve as the IAM subject matter expert across Security, IT, and Engineering
About You
- 7+ years of experience in identity, access management, or platform security engineering
- Deep expertise with Okta - including SSO, MFA, lifecycle management, and API-driven automation
- Proficient in Terraform and committed to managing IAM infrastructure as code
- Experience designing IAM strategy at scale - across both corporate (IT/SaaS) and production (cloud infrastructure) environments
- Hands-on experience with AWS or GCP IAM - service accounts, roles, workload identity federation
- Background in MDM/MAM solutions (Jamf, Intune, or equivalent)
- Strong collaborator who can drive alignment across Engineering, IT, Compliance, and Security teams
- Comfortable operating with autonomy and owning decisions in a fast-moving environment
Bonus If You
- Experience leading Terraform migrations for IAM or identity infrastructure at scale
- Background in SCIM, SAML, OIDC, and directory services (e.g., Google Workspace, Azure AD)
- Contributions to internal developer platforms or security tooling
- Experience at a developer tools, infrastructure, or SaaS company
- Certifications such as Okta Certified Professional/Administrator, AWS Security Specialty, or CISSP
Benefits
- Competitive compensation package, including equity
- Inclusive Healthcare Package
- Learn and Grow - we provide mentorship and send you to events that help you build your network and skills
- Flexible Time Off
- We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed
Skills
Okta, Terraform, Aws Iam, Gcp Iam, SSO, MFA, SCIM, SAML, OIDC, Jamf, Intune, MDM, Mam
Similar jobs
Security Engineering jobsOwns production-edge security for enterprise financial-institution connectivity, including PKI, mTLS, AWS networking, webhook security, and vulnerability remediation. Requires 6+ years of hands-on platform, infrastructure, or network security engineering experience.
Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.
Own and advance the security of Anyscale’s production and multi-cloud infrastructure, including hardening, segmentation, Kubernetes runtime protection, and access controls. Requires 8+ years of security engineering experience and hands-on expertise with AWS, Azure, Kubernetes, and cloud security tooling.