Staff Security Engineer (IAM) - BR - 2026
Core
Define and execute a multi-year Identity and Access Management (IAM) security strategy for a global fintech organization serving over 100 million customers.
Role type
Staff Security Engineer (IAM)
Builds
Enterprise Identity Provider, PKI, X.509 certificate lifecycle automation, mutual TLS, and credential management systems.
Domain
Financial Technology / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
IAM and authentication protocols (OIDC, OAuth 2.0, SAML 2.0, FIDO2/WebAuthn, mTLS, PKI), software engineering, threat modeling, strategic communication, incident response leadership, technical mentorship
Preferred skills
Financial services regulatory experience, enterprise Identity Provider administration (Okta, Keycloak), Zero Trust architecture design, third-party security controls, security community contributions
Technologies
OIDC, OAuth 2.0, SAML 2.0, FIDO2, WebAuthn, mTLS, PKI, Okta, Keycloak
Responsibilities
Define multi-year IAM security strategy aligned with risk posture and regulations; lead organization-wide authentication migrations across heterogeneous surfaces; design and maintain core identity infrastructure; translate least-privilege access into measurable programs; design security engineering frameworks; lead technical incident response for identity events; facilitate large-scale preparedness exercises; provide technical mentorship to senior engineers; serve as technical authority for regulators and internal audit.
Seniority
Staff, organizational-level technical influence