Senior+ IAM Engineer
Verkada · San Mateo, CA United States
About this role
**Senior IAM Engineer (Security) — Verkada** ## Who We Are Verkada is transforming how organizations protect their people and places with an integrated, privacy-sensitive AI-powered platform. Our solutions include video security, access control, air quality sensors, alarms, intercoms, and visitor management. We’re scaling rapidly—serving 30,000+ customers (including 100+ Fortune 500 companies), with more than $1B in annualized bookings, and backing from CapitalG, Sequoia Capital, General Catalyst, Felicis Ventures, Next47, and more. Today, 2M+ Verkada devices are deployed across 170+ countries. ## About the Role As a **Senior IAM Engineer** on the Security team, you’ll set the standard for identity and access across Verkada. You’ll own how access is defined, granted, reviewed, and revoked across our infrastructure—turning access management from a manual ticket queue into a **self-service system** powered by scripts and agentic workflows. ## What You’ll Do - Manage **identity and access infrastructure as code** in **Terraform**, including peer-reviewed change control, drift detection, and **policy-as-code**. - Advance **zero trust** controls for engineering access: **short-lived credentials**, **just-in-time elevation**, and eliminating standing privilege. - Own the **access lifecycle** for human and non-human identities (joiner/mover/leaver flows, service accounts, and agents). - Operate **access review/certification workflows** that produce audit evidence. - Build tools to surface **over-permissioned identities**, **unused credentials**, and **policy drift**, then drive remediation to completion. - Build **agentic workflows** on a low-code orchestration platform to automate access requests, approvals, risk scoring, and access review campaigns. - Partner with Security, Infrastructure, and Product Engineering to make the secure path the easy path, and consult on IAM design for new services. ## What You’ll Need - **B.S. in Computer Science** (or equivalent practical experience) - **3+ years** hands-on experience with **identity and access management** in a cloud-native engineering environment - Deep **AWS IAM** expertise (policy evaluation logic, permission boundaries, assume-role patterns, SCPs, and how they fail in practice—expressed in Terraform) - Fluency with identity protocols and access models: **SAML, OIDC, OAuth 2.0, SCIM**; **RBAC/ABAC/policy-based access** - Working knowledge of **Okta** administration and APIs (SSO, provisioning, group rules, authentication policies) - Ability to build automation using scripting and/or low-code/no-code orchestration (including **LLM/agent-driven steps**) - Excellent written and verbal communication—able to explain access decisions to engineers, auditors, and executives ## US Employee Benefits (Highlights) - Healthcare programs (premiums covered for employees under at least one plan; family premiums covered under all plans) - Nationwide medical, vision, and dental coverage - **HSA** employer contributions and **FSA** options - Expanded mental health support - Paid parental leave and fertility benefits - Paid holidays, firmwide extended holidays, flexible PTO, and personal sick time - Professional development stipend - Wellness/fitness benefits and healthy lunches daily - Commuter benefits ## Additional Information - Verkada sponsors and takes over sponsorship of employment visas for this role (reasonable efforts to obtain a visa if offered). ## Estimated Annual Pay Range (OTE) **$200,00
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.