Назад
Company hidden
5 часов назад

Senior Security Engineer, IAM (Cybersecurity)

130 000 - 195 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer, IAM (Cybersecurity): Designing and operating enterprise identity architecture across workforce, customer, machine, and agent identities with an accent on adaptive trust, privileged access management, authentication, and identity threat detection. Focus on reducing the identity attack surface, embedding policy-as-code and workload identity into AI-augmented DevSecOps pipelines, and leading identity incident response and governance.

Location: Remote, Illinois

Salary: $130,000–$195,000 annual base salary, plus annual performance bonus and long-term incentives.

Company

hirify.global develops legal technology and e-discovery software for regulated organizations.

What you will do

  • Set the architecture, strategy, and operational maturity of enterprise IAM across workforce, customer, machine, workload, and agent identities.
  • Design continuous adaptive trust, Zero Trust, ZTNA, least-privilege micro-segmentation, MFA/FIDO2, just-in-time access, SSO, federation, and multi-cloud authentication controls.
  • Build identity lifecycle automation, identity governance, access reviews, segregation-of-duties controls, and privileged access management with credential vaulting and session monitoring.
  • Integrate identity telemetry with SIEM, SOAR, and UEBA to detect credential abuse, privilege escalation, lateral movement, and other identity threats.
  • Develop identity incident-response playbooks and lead identity-focused purple-team engagements and exposure remediation.
  • Embed identity controls, secrets scanning, workload identity, and policy-as-code into AI-augmented CI/CD and infrastructure-as-code workflows while mentoring identity engineers.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or equivalent experience; a relevant master’s degree may qualify with 6+ years of experience.
  • 8+ years of hands-on enterprise IAM or security engineering experience, with deep expertise in identity, authentication, and access.
  • Expertise with Okta, Entra ID/Azure AD, Ping, SailPoint, Saviynt, CyberArk, and BeyondTrust, plus SAML, OIDC, OAuth 2.0, SCIM, LDAP, and Kerberos.
  • Experience leading identity threat detection, access investigations, detection engineering, and automation for access enforcement and observability.
  • Knowledge of MITRE, NIST 800-63, Zero Trust, CIS Benchmarks, and DISA STIGs, with the ability to translate frameworks into technical controls.
  • Proficiency in Python, Bash, or PowerShell for containerized services, CLI automation, API-driven provisioning, and policy-as-code, along with proven mentoring and communication skills.

Nice to have

  • Experience with SaaS, cloud-native, globally distributed, or regulated environments and cloud IAM across AWS, Azure, or GCP.
  • Experience with AI-augmented security, agentic identity, UEBA, and ML-based access-risk scoring.
  • Experience with legal technology, e-discovery, litigation holds, digital forensics, and chain-of-custody requirements.
  • Experience leading SOX, SOC 2, ISO 27001, FedRAMP, HIPAA, GDPR, or CCPA audits; relevant security certifications are valued.

Culture & Benefits

  • Flexible work arrangements.
  • Health, dental, and vision plans.
  • Parental leave for primary and secondary caregivers.
  • Two week-long company breaks each year and additional time off.
  • Long-term incentive and training investment programs.
  • Inclusive workplace supporting diverse skills, backgrounds, and identities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →