Назад
Company hidden
6 дней назад

IT Security & Identity Engineer

99 000 - 185 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
IT Security & Identity Engineer (IAM/Endpoint Security): Building and operating identity, access, and endpoint security controls for Neuralink’s corporate environment with an accent on SSO federation, lifecycle automation, phishing-resistant MFA, and device trust. Focus on implementing security infrastructure as code, centralizing detections, managing vulnerabilities, and supporting HIPAA and SOC 2 evidence while participating in incident response and on-call operations.

Location: Austin, Texas, United States

Base salary: $99,000–$185,000 USD per year

Company

hirify.global creates devices for a bidirectional brain-computer interface intended to restore movement and sight and change how people interact with digital systems.

What you will do

  • Own identity and access management across Google Workspace, Microsoft Entra, and integrated SaaS applications, including SSO federation and SCIM provisioning.
  • Manage identity infrastructure, access policies, group membership, application assignments, and conditional access as Terraform code through GitLab workflows.
  • Automate onboarding and offboarding, RBAC, just-in-time access, privilege reduction, strong authentication, and device-trust controls.
  • Operate endpoint security across macOS, Windows, and Linux, including EDR, encryption, secure baselines, and MDM compliance.
  • Centralize identity, endpoint, SaaS, and network logs; develop detections, tune alerting, manage vulnerabilities, and support incident response.
  • Conduct access reviews and audits, harden corporate IT services, produce HIPAA and SOC 2 evidence, and participate in the IT on-call rotation.

Requirements

  • Bachelor’s degree in computer science, cybersecurity, or another STEM discipline, or 5+ years of relevant professional experience in lieu of a degree.
  • 5+ years of hands-on experience securing corporate IT environments, including identity, MFA, endpoint security, logging and detection, vulnerability management, or enterprise services.
  • Enterprise IdP administration experience with Google Workspace, Microsoft Entra, or Okta, including SSO, SCIM, MFA, conditional access, and user lifecycle management.
  • Strong knowledge of SAML, OIDC, OAuth 2.0, and SCIM, plus hands-on Terraform and Git-based infrastructure or identity configuration.
  • Experience with at least two of enterprise EDR/AV, centralized logging or SIEM, vulnerability management platforms, and enterprise MDM.
  • Proficiency in Python, Bash, or PowerShell and the ability to explain security risks and tradeoffs to technical and non-technical users.

Nice to have

  • Experience with FIDO2/WebAuthn, passkeys, hardware tokens, smart cards, PKI, TLS, X.509, or 802.1x.
  • Zero-trust architecture, device trust, Tailscale, identity-aware access, privileged access management, or just-in-time access experience.
  • Detection engineering, enterprise incident response, endpoint and server hardening, Ansible, or GitLab CI/CD experience.
  • Familiarity with NIST 800-53, CIS Controls, ISO 27001, HIPAA, SOC 2, or comparable regulated environments.

Culture & Benefits

  • Full-time employment with medical, dental, and vision insurance through a PPO plan.
  • Equity compensation through RSUs, paid holidays, flexible time off, parental leave, commuter benefits, and provided meals.
  • 401(k) plan and opportunities for professional growth and advancement.
  • Work involving protected health information and PII requires confidentiality, HIPAA compliance, and responsible data handling.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →