Senior Security Engineer II – IAM
Job Description:
- Design, build, and operate solutions that continuously improve and automate security capabilities
- Leverage data to understand security trends, metrics, and improvement opportunities
- Execute security posture improvements with cross-functional stakeholders
- Lead and enhance incident response, including analysis, containment, mitigation, resolution, and remediation
- Craft and refine security program documentation, including policies, standards, baselines, and standard operating procedures
- Mentor and coach junior engineers or analysts
- Secure enterprise, cloud-native environments, and applications
- Build resilient identity pipelines using Security-as-Code and API-first automation
Requirements:
- BS / BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, or 8 years security domain experience without degree
- 4+ years of experience acting as a trusted advisor in a team setting, solving for short-term and long-term business value
- 4+ years of experience coaching other engineers or analysts
- Experience with federated identity tools such as Okta, Entra ID, or Ping Identity
- Experience with Identity Governance and Administration tools such as Omada, Lumos, SailPoint, or Saviynt
- Deep knowledge of cloud security architectures including AWS IAM, Azure Entra ID, or GCP IAM
- Experience designing and enforcing least-privilege roles, RBAC/ABAC, and permission policies
- Experience with automation using Python, Terraform, and PowerShell
- Prior healthcare industry experience with health-tech systems is preferred
- Experience with tooling, automation, and distributed systems development is preferred
- Experience generating automated metrics to measure service and program effectiveness and consistency
- Strong written and verbal communication skills
- Practical experience managing non-human identities, service accounts, API keys, bots, and automated workload identities across cloud infrastructure is preferred
- Proficiency in SAML, OIDC, OAuth, LDAP/Directory Services, user lifecycle automation, SSO, MFA, and JIT access is preferred
- Experience with IAM systems and practices is preferred
- In-depth knowledge of authentication protocols, authorization mechanisms, and directory services is preferred
- Strong proficiency implementing IAM solutions within complex environments is preferred
- Familiarity with regulatory compliance and security standards is preferred
- Ability to sit for prolonged periods and use computers and keyboards extensively; occasional walking and lifting may be required
Benefits:
- Flexible work schedules and the ability to work remotely are available for many roles
- Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners
- Robust time-off plan (21 days of PTO in your first year)
- Two paid volunteer days and 11 paid holidays
- 12 weeks paid parental leave for all new parents
- Six weeks paid sabbatical after six years of service
- Educational Assistant Program and Clinical Employee Reimbursement Program
- 401(k) with up to 4% match
- Stock options
- Collaborative, inclusive and remote-first culture