Назад
обновлено 3 дня назад

Security Software Engineer (IAM)

208 000 - 312 000$
Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Software Engineer (IAM) (Identity Infrastructure): Building self-serve identity and access infrastructure across corporate, production, and product environments with an accent on Terraform-managed IAM, just-in-time access, and automated governance workflows. Focus on connecting employee and production identity planes, designing least-privilege controls, and defining secure identity models for software agents.

Location: Remote within the United States. If based within commuting distance of the San Francisco or New York offices, in-office anchor days are Monday, Tuesday, and Friday.

Base salary in San Francisco: $208,000–$312,000 annually. Compensation outside San Francisco may be adjusted based on employee location.

Company

Vercel builds agentic infrastructure that helps people and software agents ship and run software with speed, security, and developer experience.

What you will do

  • Own IAM strategy across corporate, production, and product environments, including the connection between corporate and production identity systems.
  • Migrate Okta and related IAM configuration to Terraform so identity changes are reviewed, tested, versioned, and deployed as code.
  • Design and ship self-serve access governance tooling, including just-in-time access and time-bound permissions.
  • Build provisioning, deprovisioning, access review, and audit evidence workflows for SOC 2 and similar audits.
  • Design least-privilege controls across cloud, SaaS, and production infrastructure in partnership with platform and engineering teams.
  • Help define and implement identity and access models for agents, including delegation, scoped credentials, and impersonation boundaries.

Requirements

  • 7+ years of experience in identity, access management, or platform security engineering.
  • Experience building internal tools or self-service platforms and operating reliable production services.
  • Proficiency in a production language such as TypeScript/Node.js, Go, or Python, plus REST API design and integration experience.
  • Proficiency in Terraform and experience managing IAM infrastructure as code.
  • Hands-on implementation experience with OAuth2, OIDC, SAML, and SCIM, including identity and access failure modes.
  • Experience designing IAM at scale across corporate systems such as Okta and production environments such as AWS or GCP.

Nice to have

  • Led a Terraform migration for IAM or identity infrastructure at scale.
  • Designed or built just-in-time access systems or access governance platforms.
  • Experience with MDM/MAM tooling, device trust, or identity integrations.
  • Experience with developer tools, infrastructure, or SaaS companies.
  • Certifications such as Okta Certified Professional/Administrator, AWS Security Specialty, or CISSP.

Culture & Benefits

  • Flexible time off and an inclusive healthcare package.
  • Mentorship and support for attending events and developing professional skills.
  • Company-provided equipment and a work-from-home budget.
  • Compensation may include equity, bonus or variable pay, and other benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →