IT Security & Identity Engineer
Neuralink · Austin, Texas, United States
About this role
**About Neuralink** We are creating devices that enable a bi-directional interface with the brain—restoring movement to the paralyzed, restoring sight to the blind, and revolutionizing how humans interact with their digital world. **Team Description** Neuralink’s Information Technology team owns the corporate environment every engineer, scientist, and clinician depends on. Within IT, the **Security & Identity** function is responsible for **who can access what, from which device, and under what conditions**. This includes running the identity provider and SSO federation, enforcing strong authentication and device trust, securing endpoints across **macOS, Windows, and Linux**, centralizing logs and detections, and producing audit evidence supporting **HIPAA** and **SOC 2**. We manage this environment as code using **Terraform** and **GitLab**, with a high bar for secure access that remains low-friction. --- ## **IT Security & Identity Engineer** Neuralink is looking for a hands-on **IT Security & Identity Engineer** to own **identity, access, and endpoint security** for the corporate environment. This is a **build-and-operate** role: you will design controls, implement them in **Terraform** through **GitLab**, and then run them in production—including **on-call**. You’ll make practical risk decisions without slowing the company down, and clearly explain security tradeoffs to engineers and non-technical staff. ### **Responsibilities** - Design, deploy, and operate identity and access management across **Google Workspace**, **Microsoft Entra**, and integrated SaaS applications - Own **SSO federation** (SAML, OIDC, OAuth 2.0) and **SCIM provisioning** for business-critical tools - Manage identity infrastructure and access policy as code using **Terraform** and **GitLab CI/CD** (versioned, reviewable state) - Drive identity lifecycle automation (onboarding → offboarding), including **RBAC**, attribute-driven group membership, **just-in-time access**, and reduction of standing privilege - Design and operate strong authentication: - Phishing-resistant MFA (FIDO2/WebAuthn, passkeys, hardware tokens) - Certificate-based authentication (X.509, 802.1x) - Device-trust conditions tied to **MDM compliance** - Own endpoint security posture across **macOS, Windows, and Linux** (EDR policy/operations, disk encryption, secure baselines, compliance enforcement via **MDM** such as Intune/Jamf) - Build and maintain security logging and detection for corporate IT: - Centralize identity, endpoint, SaaS, and network logs (e.g., Grafana/Loki, Prometheus, SIEM) - Write detections for identity abuse and endpoint compromise; tune alerting - Run enterprise vulnerability management (scanning, prioritization, remediation workflows, evidence of closure) - Harden traditional IT services (email, file shares, directory services, collaboration tools, internal applications) by improving permissions, group membership, and access models - Partner with systems/network/application owners to securely design and operate services on **Tailscale** and **FortiGate** (authz/authn, logging, patching, least privilege) - Lead/support detection, triage, and incident response for corporate IT; participate in IT on-call rotation - Conduct regular access reviews and audits; produce evidence supporting **HIPAA**, **PII handling**, and **SOC 2** (with Compliance) - Drive scripting and automation (Python, Bash, PowerShell) for repeatable security tasks (baselines, evidence coll
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.