Назад
Company hidden
13 часов назад

Staff Security Engineer (IAM)

168 000 - 238 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Английский
b2
Страна
US/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Security Engineer (IAM): Designing and operating enterprise identity, access, and AI security solutions with an accent on Okta, infrastructure as code, cloud identity, and non-human identity governance. Focus on replacing click-ops with tested Python services and peer-reviewed Terraform/OpenTofu/Pulumi, re-architecting GCP and AWS access controls, and securing enterprise AI platforms and agents.

Location: Remote in Canada or the United States

Base salary for US residents: $168,000–$238,000 USD annually

Company

hirify.global provides an intelligent orchestration platform for DevSecOps, helping organizations improve developer productivity, operational efficiency, security, compliance, and digital transformation.

What you will do

  • Design enterprise-scale identity, access, privileged access, and AI governance solutions.
  • Replace low-code and iPaaS automation with modular, tested Python services running on GCP Cloud Run.
  • Codify Okta, Lumos, and non-human identity platforms using Terraform, OpenTofu, or Pulumi.
  • Re-architect identity and access across GCP and AWS, including organization design, guardrails, workload identity federation, and least-privilege controls.
  • Lead administration, SSO, SCIM, audit logging, data controls, and policy enforcement for enterprise AI platforms including Claude.
  • Drive cross-functional security initiatives, review designs and code, and mentor senior and intermediate engineers.

Requirements

  • Extensive enterprise IAM experience at Staff or senior individual-contributor level.
  • Expertise with Okta Identity Engine, advanced authentication policies, lifecycle workflows, and API automation.
  • Strong infrastructure-as-code experience with Terraform, OpenTofu, or Pulumi, including migration from click-ops to code.
  • Professional Python engineering experience delivering modular, tested, reviewed, observable services.
  • Deep GCP and/or AWS cloud identity knowledge, including organization design, IAM policies, workload identity federation, SCPs, and permission boundaries.
  • Experience governing enterprise AI platforms and understanding risks such as prompt injection, MCP attacks, agent identity, and data leakage.

Nice to have

  • Experience with IGA platforms such as Lumos or ConductorOne.
  • Experience in regulated environments and familiarity with FedRAMP, SOC 2, SOX, change management, evidence collection, and audit support.
  • Experience with AI agent governance, non-human identity management, zero-trust architecture, or behavioral analytics.
  • Experience completing cloud organization restructuring and related stakeholder migrations.

Culture & Benefits

  • Fully remote work with location-based eligibility for Canada or the United States for this role.
  • Flexible paid time off and parental leave.
  • Health, financial, and well-being benefits.
  • Equity compensation and an employee stock purchase plan.
  • Growth and development funding and team member resource groups.
  • AI is used as a core productivity multiplier in daily workflows.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →