Senior Security Engineer, Identity and Access Management (IAM)
Core
Design, build, and run the end-to-end identity platform governing authentication and authorization across corporate, engineering, and mission environments for a high-growth satellite company.
Role type
Senior Security Engineer (Identity and Access Management)
Builds
Enterprise identity platform, SSO, federation, and automated access workflows for spacecraft development teams.
Domain
Aerospace / Satellite Manufacturing / Cybersecurity
Deliverable
production ML models | product features | infrastructure
Required skills
Identity lifecycle management, RBAC/ABAC design, privileged access management, secrets management, cloud IAM (AWS/Azure/GCP), identity protocols (SAML/OIDC/OAuth/SCIM), infrastructure as code, Python/Go/C++/Rust
Preferred skills
Policy-as-code (OPA/Cedar), identity threat detection, legacy AD modernization, OT/mission environment IAM
Technologies
Okta, Microsoft Entra ID, Ping, Google Identity, HashiCorp Vault, Terraform, CloudFormation, CDK, AWS, Azure, GCP
Responsibilities
Own and mature the enterprise identity platform including SSO and directory services; Design and implement authentication standards and phishing-resistant MFA; Build and automate identity lifecycle management workflows; Design and maintain role-based and attribute-based access models; Implement privileged access management for administrators and service accounts; Manage machine and workload identity including secrets management; Onboard SaaS applications to SSO and automate provisioning; Implement conditional access and risk-based authentication policies; Build and run access review campaigns; Harden cloud IAM roles and trust policies; Write code and IaC to automate identity operations; Partner with security operations on identity threat detection; Serve as identity SME in architecture reviews; Maintain documentation and mentor junior engineers.
Seniority
Senior, hands-on IC