CareerPlanGet AI match score →
Onsite or remote • Noida+1💼 Full-time🗓 2026-06-25

Core

Build the security and policy layer for a regulated enterprise platform, implementing fail-closed controls, least privilege access, audit evidence, and defensible compliance posture.

Role type

Senior IC Security & Policy Engineer

Builds

Security controls, policy enforcement mechanisms, audit trails, and secure integrations for enterprise buyers

Domain

Cybersecurity, Identity & Access Management (IAM), Compliance Engineering

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

policy decision points, policy enforcement points, RBAC/ABAC workflows, threat modeling, secure design reviews, tenant isolation, mTLS, certificate lifecycle, key management, secure APIs, encryption, secrets management, audit logging, identity federation

Preferred skills

OPA, Rego, Keycloak, SPIFFE/SPIRE, service mesh security, SIEM integrations, cloud KMS/HSM patterns, SOC 2, ISO 27001, financial services security reviews, AI governance, model risk management, data loss prevention, privacy engineering

Technologies

OPA, Rego, Keycloak, SPIFFE, SPIRE, mTLS, SIEM, KMS, HSM

Responsibilities

Implement policy decision points, policy enforcement points, audit trails, and RBAC/ABAC workflows; Integrate external IAM and policy systems through provider abstractions; Own threat models, secure design reviews, abuse cases, data-flow analysis, and security test requirements; Build controls for tenant isolation, service authentication, mTLS, certificate lifecycle, and key management; Create secure-by-default engineering patterns and partner with QA on negative tests and regression suites; Support enterprise due diligence, security questionnaires, audit requests, and compliance evidence collection

Seniority

Senior, hands-on IC

Rewrite
## About the Role Build the security and policy layer that makes Federis credible for regulated enterprise buyers: fail-closed controls, least privilege access, audit evidence, policy-as-code, secure integrations, and defensible compliance posture. ## Key Responsibilities - Implement policy decision points, policy enforcement points, audit trails, RBAC/ABAC workflows, approvals, and evidence capture. - Integrate external IAM and policy systems through provider abstractions rather than product-specific tight coupling. - Own threat models, secure design reviews, abuse cases, data-flow analysis, secrets handling, and security test requirements. - Build controls for tenant isolation, service authentication, mTLS, certificate lifecycle, key management, and privileged operation review. - Create secure-by-default engineering patterns and partner with QA on negative tests, access-control tests, and regression suites. - Support enterprise due diligence, security questionnaires, audit requests, and compliance evidence collection. ## Required Experience - 5+ years in product security, platform security, IAM, policy engineering, compliance engineering, or secure backend development. - Practical experience with authorization models, identity federation, audit logging, encryption, secrets management, and secure APIs. - Strong ability to translate policy requirements into enforceable code, tests, and operational controls. - Comfort reviewing architecture, code, infrastructure, dependencies, and deployment practices for security and licensing risk. - Clear written communication for security findings, control descriptions, and customer-facing evidence. ## Useful Differentiators - Hands-on experience with OPA, Rego, Keycloak, SPIFFE/SPIRE, service mesh security, SIEM integrations, or cloud KMS/HSM patterns. - Experience with SOC 2, ISO 27001, financial services security reviews, public sector procurement, or air-gapped deployments. - Background in AI governance, model risk management, data loss prevention, or privacy engineering. ## First 90 Days - Publish security architecture principles, threat model templates, policy design patterns, and access-control test strategy. - Implement or harden at least one critical policy/audit workflow end to end. - Create the first customer security evidence packet with product, platform, and process owners. ## Success Scorecard - High-risk workflows fail closed and produce complete audit evidence. - Security review is integrated into design and release flow without becoming a late-stage bottleneck. - Identity and policy integrations remain provider-neutral and replaceable. - Enterprise security questionnaires become repeatable rather than bespoke engineering projects.
Sourced via wellfound · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Wellfound ↗