Staff Security Engineer, IAM
Core
Design and implement enterprise-scale identity, privileged access, AI access, and non-human identity governance solutions, replacing low-code automation with modular Python services and migrating configurations to infrastructure-as-code.
Role type
Staff Security Engineer (IAM & AI Governance)
Builds
Enterprise IAM platforms, serverless Python services, IaC pipelines for identity migration, and governance frameworks for AI agents.
Domain
Cloud Security, Identity & Access Management (IAM), Artificial Intelligence Governance
Deliverable
production ML models | infrastructure | product features
Required skills
Enterprise IAM design, Okta Identity Engine, Terraform/OpenTofu/Pulumi, Python service development, GCP/AWS organization design, AI platform administration, IGA platforms, compliance frameworks (FedRAMP/SOC 2/SOX)
Preferred skills
Anthropic Claude/OpenAI ChatGPT Enterprise/Google Gemini Enterprise experience, AI agent governance, zero-trust architecture, cloud organization restructuring
Technologies
GCP, AWS, Okta, Lumos, ConductorOne, Python, Terraform, OpenTofu, Pulumi, Cloud Run, MCP, Claude Code, Cursor
Responsibilities
Design enterprise-scale identity and AI access governance solutions; Migrate identity platform configuration from click-ops to infrastructure-as-code; Re-architect identity and access across GCP and AWS organizations; Lead administration of SSO, SCIM integration, and audit logging for enterprise AI platforms; Mentor senior and intermediate engineers; Write technical proposals and review designs.
Seniority
Staff, hands-on IC with mentorship