CronJobs

security jobs

Senior Security Engineer, Identity and Access Management

HackerOne · Seattle

remotesenior$180,000–$220,000Posted Sep 25, 2026PythonGoOktaAWS IAMTerraformOIDCSAMLSCIM

Apply on the employer site

About this role

## Senior Security Engineer, Identity and Access Management **Location:** Remote (Seattle, WA or Washington, DC) — targeted for candidates within ~50 miles of Austin, TX; Seattle, WA; Washington, DC; San Francisco, CA; or Boston, MA, or within commuting distance of London or the Netherlands. --- ### About HackerOne HackerOne is a global leader in **Continuous Threat Exposure Management (CTEM)**, uniting agentic AI with the world’s largest community of security researchers to continuously discover, validate, prioritize, and remediate exposures across **code, cloud, and AI systems**. --- ### Role Summary Identity is at the heart of protecting customer vulnerabilities. In this role, you’ll build an **AI-first Identity and Access Management capability** focused on engineering—not just administration. You will design and deliver **access models and automation** so people and systems can access **only the right data, at the right time, in the right way** across the full identity lifecycle (onboarding, creation, change, and removal) for **people, service accounts, and AI agents**. --- ### What You’ll Do - **Own the identity lifecycle end to end** (onboarding → creation → change → removal) for people, service accounts, and AI agents, building automation to grant and remove entitlements seamlessly. - **Design access models** based on **data classification** so access follows the data—not who requested it. - Make **time-bound access** the default for critical data. - **Engineer identity as code**: keep provisioning logic, entitlement policy, and access review rules in version control and under test across systems such as **Okta, Lumos, and AWS IAM**. - Build **AI/LLM-powered tooling** to make access review and entitlement anomaly detection **continuous** (not periodic), surfacing unusual patterns when they occur. - Apply the same discipline to **non-human identities** (service accounts, workload identities, integrations, AI agents) with clear ownership, purpose, and expiry. - **Measure and report** opportunities to reduce unnecessary entitlements using data-driven decision making. - Partner with Engineering, Enterprise IT, and Compliance to embed identity controls, and act as an **identity responder** for incidents (containment, reconstruction, and blameless retrospectives). --- ### Minimum Qualifications - **5+ years** experience in identity and access management, security engineering, or software engineering with substantial ownership of identity systems. - Hands-on experience operating an enterprise identity provider such as **Okta** (SAML, OIDC, SCIM, lifecycle automation). - Experience managing identity across an enterprise SaaS estate (e.g., **Google Workspace, Salesforce, Workday**) including **SCIM provisioning** and group-driven entitlements. - Experience with **cloud IAM** (ideally **AWS**), including policy design and short-lived credentials. - Strong software engineering fundamentals; proficiency in **Python, Go, or similar**. - Hands-on use of **AI/LLM tooling and agentic coding tools** in production engineering. --- ### Preferred Qualifications - Identity work in a regulated sector (financial services, healthcare, government) and producing access control evidence for audits (e.g., **PCI DSS, HIPAA, SOC 2, ISO 27001**). - Managing identity infrastructure as code and governance tooling (e.g., **Terraform, Lumos**). - Mobile device management (e.g., **Kandji**) alongside identity (device trust policies, platform SSO, endpoi

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord