Technical Lead, Identity & Access Management
Hands-on technical lead owning end-to-end identity and access management, from IDP architecture to privileged access, secrets management, and AI agent governance. Drives Zero Trust implementation, IAM strategy, and cross-functional collaboration in cloud environments. Requires 8-12+ years in identity/security engineering.
About the job
Responsibilities
- Define the long-term IAM strategy, roadmap, and operating model across the enterprise and product ecosystem.
- Assess and mature the current-state Identity Provider (IDP) architecture, identifying gaps and driving the path to a resilient, scalable design.
- Drive all identity systems toward Zero Trust principles - secure, scalable, and frictionless by default.
- Automate the full identity lifecycle beyond traditional IGA joiner-mover-leaver (JML) processes.
- Implement and enforce RBAC for human and non-human identities at scale.
- Define and operationalize least-privilege policies across all systems and environments.
- Centralize secrets management - keys, tokens, certificates - across cloud and enterprise environments.
- Design and deliver Privileged Access Management (PAM) for admin accounts spanning enterprise IT and cloud engineering.
- Implement a scalable access management model for AI agents and bots.
- Collaborate with IT Apps and infrastructure teams to enforce and enable SSO across the enterprise.
- Own the implementation and governance of authentication protocols (SAML, OIDC, OAuth 2.0) and modern identity standards.
- Partner with engineering, security, IT, compliance, and product teams to deliver access management capabilities that enable the business and satisfy audit requirements.
- Translate complex identity requirements into clear, executable technical plans and communicate tradeoffs to senior stakeholders.
Requirements
- 8 - 12+ years in identity engineering, security engineering, or a closely related discipline.
- Hands-on architecture or engineering experience in cloud environments (AWS, GCP, or Azure).
- Demonstrated track record of leading complex, cross-functional IAM programs from design through production.
- Deep expertise in modern IAM technologies: directories (LDAP/AD), IDPs, federation, and authentication protocols (SAML, OIDC, OAuth 2.0).
- Practical experience implementing Zero Trust identity models and PAM frameworks.
- Strong understanding of identity governance, IGA tooling, and role lifecycle management.
- Hands-on experience with secrets management platforms (e.g., HashiCorp Vault, AWS Secrets Manager, GCP Secret Manager).
- Experience with non-human identity and machine identity management in large-scale environments.
- Experience building access controls for AI workloads, agents, or service accounts at scale.
- Familiarity with SCIM provisioning and automated IGA workflows.
- Excellent communication and influencing skills.
Nice to Have
- Security certifications such as CISSP, GIAC, or similar.
- Solid grasp of compliance frameworks relevant to identity (SOC 2, ISO 27001, NIST, or similar) and experience supporting audit processes.
Compensation
Base salary range: $180,000 - $230,000 USD annually. Total compensation includes equity, comprehensive health/dental/vision insurance, 401k match, learning/wellness stipends, and paid time off.
Skills
IAM, Zero Trust, RBAC, Pam, SSO, SAML, OIDC, Oauth 2.0, Hashicorp Vault, Aws Secrets Manager, Gcp Secret Manager, SCIM, Iga, Ldap, Active Directory
Similar jobs
Security Engineering jobsOwn and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads offensive security, threat intelligence, security testing, and incident response across applications, infrastructure, and networks. The role requires at least five years of relevant experience, cloud security expertise, AI and automation experience, and a bachelor's degree.
Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.
Own Anyscale’s compliance function end to end, leading SOC 2 and ISO 27001 programs, audit readiness, customer security diligence, and enterprise risk management. The role requires 7+ years in governance, risk, and compliance plus strong cloud and SaaS security-controls expertise.
The Senior Application Security Engineer will build secure-by-default software patterns, supply-chain controls, and developer-facing security tooling across a distributed systems platform. The role requires 5+ years of production software experience, strong application security expertise, and depth in Go or Rust.