CareerPlanSign in

Staff Security Engineer (IAM) - BR - 2026

São Paulo💼 Full-time🗓 2026-07-20 → 2026-09-26

Core

Define and execute a multi-year Identity and Access Management (IAM) security strategy for a global fintech organization serving over 100 million customers.

Role type

Staff Security Engineer (IAM)

Builds

Enterprise Identity Provider, PKI, X.509 certificate lifecycle automation, mutual TLS, and credential management systems.

Domain

Financial Technology / Cybersecurity

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

IAM and authentication protocols (OIDC, OAuth 2.0, SAML 2.0, FIDO2/WebAuthn, mTLS, PKI), software engineering, threat modeling, strategic communication, incident response leadership, technical mentorship

Preferred skills

Financial services regulatory experience, enterprise Identity Provider administration (Okta, Keycloak), Zero Trust architecture design, third-party security controls, security community contributions

Technologies

OIDC, OAuth 2.0, SAML 2.0, FIDO2, WebAuthn, mTLS, PKI, Okta, Keycloak

Responsibilities

Define multi-year IAM security strategy aligned with risk posture and regulations; lead organization-wide authentication migrations across heterogeneous surfaces; design and maintain core identity infrastructure; translate least-privilege access into measurable programs; design security engineering frameworks; lead technical incident response for identity events; facilitate large-scale preparedness exercises; provide technical mentorship to senior engineers; serve as technical authority for regulators and internal audit.

Seniority

Staff, organizational-level technical influence

Sourced via ashby · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.