Skip to content
GitLabGitLab

Staff Security Engineer, IAM

Staff-level security engineer leading enterprise IAM, cloud identity, AI platform access, and non-human identity governance. The role requires deep Okta, infrastructure-as-code, Python, GCP or AWS, and regulated-environment experience.

About the job

Responsibilities

  • Design scalable identity and AI access solutions, including AI agent governance and just-in-time privileged access workflows.
  • Replace low-code automation with tested, source-controlled Python services deployed on GCP Cloud Run or an equivalent runtime.
  • Codify Okta, Lumos, and non-human identity platforms using Terraform, OpenTofu, or Pulumi.
  • Re-architect identity and access across GCP and AWS organizations, including resource hierarchies, organization policies, SCPs, permission boundaries, and workload identity federation.
  • Lead identity and access engineering for enterprise AI platforms, including administration, SSO, SCIM, audit logging, data controls, and policy enforcement.
  • Develop governance for service accounts, API keys, certificates, AI agents, and MCP integrations; deploy and operationalize a non-human identity platform.
  • Translate ambiguous cross-functional requirements into technical specifications and lead initiatives across Security, IT, Engineering, Enterprise AI, Compliance, and People teams.
  • Mentor engineers on technical implementation and modern identity and AI security practices.

Requirements

  • Extensive enterprise IAM experience, including work at Staff or senior individual-contributor level.
  • Expert Okta experience with Identity Engine, advanced authentication policies, lifecycle workflows, and API automation.
  • Strong infrastructure-as-code experience with Terraform, OpenTofu, or Pulumi, including SaaS identity-platform providers and click-ops migrations.
  • Proficiency writing, testing, reviewing, deploying, and instrumenting modular Python services.
  • Deep cloud identity experience in GCP and/or AWS, including organization design, IAM policy models, workload identity federation, and preventive controls.
  • Experience administering or governing enterprise AI platforms; Anthropic Claude preferred, with OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or similar accepted.
  • Understanding of AI security risks including prompt injection, MCP attack surfaces, agent identity, and data leakage.
  • Regular hands-on use of AI development tools such as Claude Code or Cursor.
  • Experience with IGA platforms such as Lumos or ConductorOne, preferably managed declaratively.
  • Experience in regulated environments and familiarity with FedRAMP, SOC 2, or SOX compliance, change management, evidence collection, and audit support.

Nice to Have

  • Experience with AI agent governance, non-human identity management, zero-trust architecture, or behavioral analytics.
  • Experience completing cloud organization restructuring, including migrations and stakeholder management.

Compensation and Benefits

  • United States base salary: $168,000–$238,000 USD annually.
  • The range excludes bonuses, equity, and benefits.
  • Benefits include flexible paid time off, equity compensation and employee stock purchase plan, a growth and development fund, parental leave, and team member resource groups.

Skills

IAM, Okta, Okta Identity Engine, Terraform, Opentofu, Pulumi, Python, Gcp Cloud Run, GCP, AWS, Workload Identity Federation, Scps, Permission Boundaries, Claude, SCIM

GitLab

GitLab

United States
Staff Security Researcher
$168k+/yrRemote7+ YOESecurity Engineering

Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.

GitLab

GitLab

United States
Staff Corporate Security Engineer
$168k+/yrRemote7+ YOESecurity Engineering

Leads corporate endpoint security architecture and automation, with emphasis on macOS, Terraform, GitOps, and scalable controls across device platforms. The role partners across security and IT, improves detection and auditability, and mentors engineers.

Ironclad

Ironclad

San Francisco, CA

Staff IAM Engineer
$170k+/yrHybrid4+ YOESecurity Engineering

Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.

Chainguard

Chainguard

United States
Staff Vulnerability Management Engineer
$170k+/yrRemote7+ YOESecurity Engineering

Leads vulnerability disclosure operations at scale, including novel vulnerability measurement, CVE assignment, embargo coordination, and industry collaboration. The Staff individual contributor provides technical leadership and requires extensive software security or open source experience.

Okta

Okta

Bellevue, WA
Staff Identity Governance and Access Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.