Skip to content

Staff IAM Engineer

170k – 190kSan Francisco, CAHybrid4+ YOE
Summary

Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.

About the role

What you will do

  • Support implementation and operations of our Identity Governance & Administration (IGA) platform to ensure employees gain appropriate access for their role, approvals are captured, and access is revoked efficiently upon separation
  • Access control design as a security control by defining and enforcing RBAC standards for sensitive systems
  • Continuous improvement of identity controls by reducing standing privileges and hardening authentication policies (SSO, MFA)
  • Lead the integration of new SaaS applications into our SSO (Single Sign-On) and MFA (Multi-Factor Authentication) ecosystem, providing security oversight for business systems implementations and operations
  • Evolve our corporate device trust program so only compliant devices can access corporate and production systems
  • Support endpoint security efforts including security policies, controls, and vulnerability management across macOS and Windows
  • Partner with Security Detection & Response to ensure visibility into corporate systems, including development of scripts and integrations as needed
  • Partner with Trust & Compliance to streamline or automate evidence collection to support internal and independent audits (e.g., SOC2)
  • Conduct periodic access reviews and audits; investigate and resolve identity- and access-related security incidents
  • Design, document, and execute plans to identify gaps and continuously improve access management lifecycle and identity architecture

What we are looking for

  • 4+ years of experience in security-focused software engineering, corporate engineering, IT, and/or program management
  • Demonstrated ability to identify risks and vulnerabilities in IT and business systems, balance risk with company priorities, and communicate risk to stakeholders
  • Strong understanding of IAM protocols and standards, including SAML 2.0, OIDC, SCIM, LDAP, OAuth, and familiarity with X.509
  • Experience with IdP and identity tooling (e.g., Okta, Active Directory, Google Workspace), including defining and enforcing Role-Based Access Control (RBAC) policies and Least Privilege principles across enterprise applications
  • Familiarity with endpoint engineering for macOS and Windows
  • SW Eng/Dev engineering and DevOps proficiency: Python and/or Go, Terraform, GAM scripting, Powershell scripting, JSON, Javascript
  • Demonstrated experience deploying new IT systems and processes across the organization with high user satisfaction
  • Strong analytical and problem-solving skills, attention to detail, and ability to operate independently with a high level of ownership
  • Experience with Okta, Salesforce, NetSuite, Workday, GCP, GWP, Microsoft Entra/Azure/Intune, JAMF
  • Backend and API testing/experience is a plus

Compensation and Benefits

  • Base Salary Range: $170,000 - $190,000
  • 100% health coverage for employees (medical, dental, and vision), and 75% coverage for dependents with buy-up plan options available
  • Market-leading leave policies, including gender-neutral parental leave and compassionate leave
  • Family forming support through Maven for you and your partner
  • Paid time off
  • Monthly stipends for wellbeing, hybrid work, and (if applicable) cell phone use
  • Mental health support through Modern Health, including therapy, coaching, and digital tools
  • Pre-tax commuter benefits (US Employees)
  • 401(k) plan with Fidelity with employer match (US Employees)
Skills
IAMSAML 2.0OIDCSCIMLDAPOAuthX.509OktaActive DirectoryGoogle WorkspaceRBACPythonGoTerraformPowershell scripting
Similar roles at this salary range
All Security Engineering jobs →
Upstart

Senior Manager, Technology Risk

Lead second-line technology and information security risk oversight for a de novo national bank, establishing the 2LOD technology risk framework and providing independent oversight of IT, cybersecurity, and cloud infrastructure.

172k – 238kUnited StatesSecurity EngineeringRemoteGRCCISA
Figma

Manager, Security Operations

Lead Figma's security operations program, owning monitoring, incident response, SIEM/SOAR automation, and threat intelligence. Requires 7+ years in security operations or incident response with deep SIEM/SOAR expertise.

185k – 296kSan Francisco, CA +1Security EngineeringRemoteIAMDLP
Nectarsocial

Senior Security Engineer

First security engineer to own application security, compliance programs (SOC 2, ISO 27001), and enterprise customer security reviews for an AI-native social commerce platform.

200k – 400kPalo Alto, CASecurity EngineeringHybridAWSGDPR
Ontic

Senior AI Security Engineer

Lead development of AI security controls, governance frameworks, and risk management practices. Conduct assessments, implement guardrails, and ensure responsible AI deployment across the organization.

140k – 160kUnited StatesSecurity EngineeringRemoteCCSPCISSP
Decagon

Platform Engineer, Security

Lead application security strategy and implementation for Decagon's conversational AI platform. Partner with engineering teams to build security into AI-powered applications and establish testing programs.

200k – 330kSan Francisco, CASecurity EngineeringOn-siteSASTDAST