Staff Security Engineer, IAM (USA)

23 minutes ago
Full-time
Lead
Cybersecurity
GitLab

GitLab

GitLab: The comprehensive DevOps platform revolutionizing software development with automation, AI workflows, and essential tools for efficient collaboration.

Internet Software & Services
1K-5K
Founded 2014

Description

  • Design comprehensive identity and AI access solutions that scale with business growth, including just-in-time privileged access workflows.
  • Lead identity and access engineering for enterprise AI platforms, including administration, SSO and SCIM integration, audit logging, data controls, and policy enforcement.
  • Codify identity platforms in Terraform and lead migrations from click-ops to peer-reviewed infrastructure-as-code.
  • Refactor the authentication framework to implement advanced conditional access controls across the SaaS ecosystem.
  • Design, deploy, and operationalize governance for non-human identities such as service accounts, API keys, certificates, AI agents, and MCP integrations.
  • Lead cross-functional initiatives with Security, IT, Engineering, Enterprise AI, Compliance, and People teams to translate business needs into technical specifications.
  • Write technical proposals that influence the roadmap and help set direction for identity security.
  • Review design and code to raise the technical bar across the team.
  • Mentor senior and intermediate engineers on identity and AI security practices.

Requirements

  • 8+ years of IAM experience designing and implementing enterprise-scale solutions.
  • Demonstrated experience at a Staff or senior individual contributor level.
  • Expert-level Okta experience, including Identity Engine, advanced authentication policies, lifecycle workflows, and API automation.
  • Strong infrastructure-as-code experience with Terraform, including SaaS identity platform providers.
  • Hands-on experience administering or governing enterprise AI platforms; Anthropic Claude preferred, with OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or similar acceptable.
  • Strong automation experience using Python and iPaaS tools such as Tines or Okta Workflows.
  • Experience with IGA platforms such as Lumos, ConductorOne, or similar.
  • Working knowledge of non-human identity tooling such as Token Security, Oasis, Astrix, or similar.
  • Experience in regulated environments with familiarity with FedRAMP, SOC2, and SOX.
  • Strong communication and collaboration skills for proposals, cross-functional leadership, and mentoring.
  • Passion for emerging identity challenges such as AI agent governance, non-human identity management, zero-trust architecture, and behavioral analytics, preferred.
  • Active use of Claude Code, Cursor, or similar agentic development tools, preferred.
  • Must be a United States citizen physically located in the United States due to potential FedRAMP support and government requirements.

Benefits

  • Base salary range of $168,000 to $238,000 USD.
  • Flexible Paid Time Off.
  • Equity compensation and Employee Stock Purchase Plan.
  • Benefits to support health, finances, and well-being.
  • Growth and Development Fund.
  • Parental leave.
  • Team Member Resource Groups.
  • Remote work with roles generally available worldwide, subject to location-based eligibility requirements.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Microsoft 365 Engineer

Your Business Internet Software & Services

NRI North America is hiring a Senior Microsoft 365 Engineer to support managed services clients remotely by resolving escalations and optimizing Microsoft 365 environments, with a primary focus on M365 security.

Active Directory PowerShell
32 minutes ago

Director of IT, Information Security & Data Privacy

Energage 51-250 Professional Services

Energage is seeking a Director of IT, Information Security & Data Privacy to lead its internal technology, cybersecurity, and privacy programs in a fast-growing SaaS environment.

AWS Azure Cybersecurity
1 hour, 8 minutes ago

Security Engineer, DevSecOps - Mexico

JumpCloud 251-1K Internet Software & Services

JumpCloud is hiring a remote Security Engineer for its DevSecOps team in Mexico to design and build cloud security automation, detection, and vulnerability management solutions that protect the company’s data and infrastructure.

AWS DevSecOps GCP GitHub Actions Go Python SIEM Terraform
1 hour, 8 minutes ago

Associate Principal - Security

TEECOM 51-250 Construction & Engineering

TEECOM is hiring a remote Associate Principal - Security to lead mid-scale multidisciplinary project delivery, guide technical design and coordination, and help strengthen team practices, client relationships, and internal standards.

Asana GitHub
1 hour, 23 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers