Назад
Company hidden
4 дня назад

Senior Identity Engineer

170 000 - 200 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Identity Engineer (Identity and Cloud Security): Building and operating workforce and workload identity systems across corporate, cloud, and factory environments handling export-controlled technical data with an accent on SSO, MFA, access lifecycle automation, and least-privilege authorization. Focus on OAuth 2.0/OIDC/SAML integrations, cloud workload identity, fine-grained access control, and audit-ready identity telemetry.

Location: Los Angeles, CA; on-site. ITAR eligibility is required: U.S. citizenship or nationality, lawful permanent residency, protected-individual status, or eligibility to obtain the necessary U.S. government authorizations. Relocation support may be available in certain situations based on business need.

Salary: $170K–$200K annually, plus equity.

Company

hirify.global builds autonomous factories combining AI, advanced software, robotics, and full-stack manufacturing for aerospace, defense, and other mission-critical industries.

What you will do

  • Design, implement, and operate the identity provider stack, including SSO, SCIM provisioning, and phishing-resistant MFA.
  • Build identity systems using OAuth 2.0, OIDC, SAML, RBAC, and relationship-based access control.
  • Own cloud and workload identity across Azure service principals, AWS IAM, and service identities.
  • Automate joiner-mover-leaver workflows, access reviews, and identity lifecycle management.
  • Partner with Detection & Response and Compliance/FSO to make identity telemetry actionable and audit-ready.

Requirements

  • Strong software engineering fundamentals and experience shipping identity systems at scale.
  • Deep knowledge of OAuth 2.0, OIDC, SAML, RBAC, and relationship-based access control.
  • Hands-on experience with one or more identity providers, such as Okta, Entra, Google Workspace, Auth0, or Zitadel.
  • Practical expertise with Azure service principals, AWS IAM, and infrastructure identity mapping.
  • Ability to own the identity domain end-to-end with minimal direction.
  • Must meet ITAR eligibility requirements and work on-site in Los Angeles.

Nice to have

  • Production experience with OpenFGA, Zanzibar-style authorization, or other fine-grained authorization systems.
  • Identity engineering experience in OT, manufacturing, regulated, or controlled environments.
  • Experience with passkeys/FIDO2, PAM platforms such as CyberArk or Teleport, or HashiCorp Vault.
  • Detection engineering and ITAR-aware access design experience.

Culture & Benefits

  • Hands-on individual-contributor role on a small, high-leverage security team.
  • Medical, dental, vision, and life insurance.
  • 401(k) and equity.
  • Flexible vacation policy.
  • Relocation support may be provided for certain situations based on business need.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →