Назад
Company hidden
1 день назад

Principal Cloud Security Engineer, Identity & Access (IAM)

184 800 - 277 200$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Cloud Security Engineer, Identity & Access (IAM) (AWS/IAM/AI): Owns the multi-year IAM architecture and roadmap across human and non-human identities, cloud authorization, federation, and secrets management with an accent on AWS identity at scale, workforce identity, and AI-agent security. Focus on designing zero-trust access patterns, embedding identity guardrails into Terraform and CI/CD, governing agent and workload identities, and driving architecture decisions across engineering, security, and Risk.

Location: Reston, Virginia, USA. Hybrid Flex Work requires spending at least 50% of each quarter in the office or in the field.

Base salary: $184,800–$277,200 USD annually for the primary location; additional US locations: $167,200–$300,000 USD annually.

Company

hirify.global is a Fortune 500 company and AI platform for managing people, money, and agents.

What you will do

  • Own the multi-year IAM architecture and roadmap across human and non-human identity, cloud authorization, federation, and secrets management.
  • Design AWS identity architecture across hundreds of accounts using Organizations, SCPs, IAM Identity Center, ABAC, and least-privilege patterns.
  • Architect workforce identity capabilities including SSO, adaptive MFA, SCIM provisioning, and lifecycle automation.
  • Define authentication, authorization, observability, and governance patterns for AI agents and service-to-service workloads.
  • Embed identity guardrails into Terraform and CI/CD while advancing Zero Trust access controls.
  • Partner with Risk and GRC, influence cross-functional decisions, and mentor IAM engineers.

Requirements

  • Experience in cloud security or IAM, including at least 3 years in a staff or architect role owning technical direction.
  • Deep AWS IAM expertise covering multi-account Organizations, SCPs, IAM Identity Center, ABAC, and secrets management.
  • Enterprise workforce identity experience with Okta, Entra ID, Ping, or an equivalent platform, including SSO, MFA, SCIM, and lifecycle management.
  • Strong knowledge of SAML, OIDC, and OAuth2, including debugging complex environments.
  • Fluency with Terraform and identity controls enforced through CI/CD.
  • Track record of aligning engineering, security, and business teams without positional authority.

Nice to have

  • Hands-on experience with AI or agentic identity, non-human identity lifecycle, workload identity, and least privilege for agents.
  • Experience with identity-aware proxies, agent observability, or LLM access governance tooling.
  • GCP or multi-cloud identity experience.
  • AWS Certified Security – Specialty certification.

Culture & Benefits

  • Flexible hybrid work model combining office, field, and remote home-office work.
  • Annual bonus or role-specific commission/bonus eligibility.
  • Annual refresh stock grant eligibility.
  • Comprehensive benefits and reasonable accommodation support.
  • Security-focused environment protecting personal and financial data at enterprise scale.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →