обновлено 12 дней назад
Advanced Security Engineer (IAM)
104 000 - 156 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Advanced Security Engineer (IAM) (Identity and Access Management): Designing, deploying, and optimizing AI-enabled identity controls across workforce, customer, machine, and agent identity domains with an accent on adaptive trust, privileged access, and identity lifecycle automation. Focus on implementing phishing-resistant authentication, federation, identity telemetry, incident-response workflows, and policy-as-code across SaaS and multi-cloud environments.
Location: Illinois, United States; remote position
Salary: $104,000–$156,000 annually, plus an annual performance bonus and long-term incentives.
Company
develops software and operates an enterprise environment requiring advanced identity, security, compliance, and access controls.
What you will do
- Design, deploy, and operate identity controls for workforce, customer, machine, workload, and AI-agent identities.
- Implement continuous adaptive trust, continuous access evaluation, risk-based authentication, session revocation, ZTNA, least privilege, FIDO2, and JIT access.
- Integrate SSO, federation, authentication, and lifecycle automation across SaaS and multi-cloud environments.
- Operate IGA and PAM capabilities, including access reviews, segregation-of-duties checks, credential vaulting, session monitoring, and non-human identity governance.
- Integrate identity telemetry with SIEM/SOAR and UEBA, and execute response playbooks for account takeover, credential compromise, and session hijacking.
- Implement identity checks in CI/CD pipelines and track identity hygiene, audit, certification, and compliance activities.
Requirements
- Ability to obtain and maintain the required Public Trust clearance.
- Bachelor’s degree in Computer Science, Information Security, or equivalent experience; a relevant master’s degree may also qualify.
- 5+ years of hands-on enterprise IAM or security engineering experience focused on identity, authentication, and access.
- Experience with IdP/SSO, IGA, PAM, and directory tools such as Okta, Entra ID/Azure AD, Ping, SailPoint, Saviynt, CyberArk, or BeyondTrust.
- Knowledge of SAML, OIDC, OAuth 2.0, SCIM, LDAP, Kerberos, MITRE, NIST 800-63, and Zero Trust principles.
- Proficiency in Python, Bash, or PowerShell for automation, containerized services, CLI workflows, API-driven provisioning, or policy-as-code.
Nice to have
- Experience with AI-enabled identity operations, UEBA, ML-based access-risk scoring, or AI-assisted threat hunting.
- Knowledge of AWS, Azure, GCP, cloud IAM, RBAC, workload identity, secrets management, and machine-to-machine authentication.
- Experience integrating identity controls into software development, infrastructure-as-code, and CI/CD practices.
- Experience supporting SOC 2, ISO 27001, FedRAMP, or HIPAA compliance and relevant security or identity certifications.
Culture & Benefits
- Remote work arrangement for the Illinois-based position.
- Competitive base salary with an annual performance bonus.
- Long-term incentives and compensation determined by experience, qualifications, skills, and internal pay equity.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →