Назад
Company hidden
6 дней назад

Senior IAM Engineer

200 000 - 300 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior IAM Engineer (AWS/Terraform): Building and operating identity and access infrastructure for a cloud-native security platform with an accent on least privilege, zero trust, and automated access lifecycle management. Focus on codifying AWS and Okta policies, eliminating standing privilege, detecting access risks, and designing agentic workflows for access requests and reviews.

Location: San Mateo, California, United States

Annual OTE: $200,000–$300,000 USD

Company

hirify.global develops a privacy-sensitive, AI-powered physical security platform covering video security, access control, air quality sensors, alarms, intercoms, and visitor management.

What you will do

  • Manage identity and access infrastructure as code with Terraform, peer-reviewed change control, drift detection, and policy-as-code.
  • Advance zero trust controls, including short-lived credentials, just-in-time elevation, and elimination of standing privilege.
  • Own joiner, mover, leaver, service account, agent, and other human and non-human identity lifecycle flows.
  • Operate access review and certification workflows that produce audit evidence.
  • Build tools to identify over-permissioned identities, unused credentials, and policy drift, and drive remediation.
  • Build agentic workflows to automate access requests, approvals, risk scoring, and access review campaigns.

Requirements

  • Bachelor of Science in Computer Science or equivalent practical experience.
  • 3+ years of hands-on identity and access management experience in a cloud-native engineering environment.
  • Deep AWS IAM expertise, including policy evaluation, permission boundaries, assume-role patterns, SCPs, and Terraform implementation.
  • Fluency with SAML, OIDC, OAuth 2.0, SCIM, RBAC, ABAC, and policy-based access models.
  • Working knowledge of Okta administration and APIs, including SSO, provisioning, group rules, and authentication policies.
  • Ability to build automation with scripting or low-code/no-code orchestration platforms, including LLM- or agent-driven steps, and communicate access decisions to engineers, auditors, and executives.

Culture & Benefits

  • US employment visa sponsorship and continued sponsorship are available.
  • Employee healthcare premiums are fully covered under at least one plan, with family premium coverage under all plans.
  • Medical, vision, dental, HSA, FSA, mental health, parental leave, and fertility benefits are provided.
  • Paid holidays, extended firmwide holidays, flexible PTO, and personal sick time.
  • Professional development stipend, wellness and fitness benefits, daily healthy lunches, and commuter benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →