Staff Security Engineer, IAM
$218.03k - $256.5kCoinbase, Inc.
Ready to be pushed beyond what you think you’re capable of?
At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the future global financial system.
To achieve our mission, we’re seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company’s hardest problems.
Our work culture is intense and isn’t for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there’s no better place to be.
While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported.
At Coinbase, identity and access controls are foundational to protecting customer funds, sensitive data, and the trust that underpins our position as the world's most trusted crypto platform. The Identity and Access Management (IAM) program, housed within Security, is a cross-functional team that designs, builds, and governs workforce identity services, privileged access controls, and automated governance across a complex and rapidly evolving technology ecosystem and regulatory landscape. This role serves as a senior technical leader within the IAM program, partnering with Engineering, IT, Platform, and business teams to architect and deliver identity solutions that balance zero-trust security with workforce enablement, reduce insider risk, and satisfy global regulatory requirements.
What you’ll be doing (ie. job duties):
Lead the architectural vision and security engineering execution for Coinbase’s Identity and Access Management (IAM) and workforce security platforms across our multi-cloud infrastructure, extensive third-party SaaS ecosystem, and internally developed applications.
Evaluate, design, and implement "build, buy, or hybrid" strategies for workforce Identity Governance and Administration (IGA), integrating commercial tools with custom middleware and machine learning or AI models to automate complex access lifecycles and maximize ROI.
Write high-quality code to build scalable automation, custom integrations, and self-service guardrails that embed intelligent identity controls directly into CI/CD pipelines, SaaS provisioning workflows, and internal enterprise tooling.
Conduct comprehensive threat modeling and security architecture reviews for foundational identity systems and critical SaaS integrations, utilizing automated threat intelligence and AI-assisted analysis to proactively identify attack vectors and design resilient mitigations.
Partner with Engineering, IT, HR, AI/ML, and Product teams to align security initiatives with business goals, balancing robust zero-trust security with developer velocity and seamless workforce enablement.
Act as the directly responsible individual (DRI) for complex, cross-team security initiatives, mentoring junior and mid-level engineers, and influencing senior leadership on risk tradeoffs and next-generation workforce security strategies.
What we look for in you (ie. job requirements):
7+ years of proven experience in software engineering, security engineering, or systems architecture, with a deep, Staff-level focus on Identity and Access Management and enterprise workforce security.
Must be proficient in at least one programming language (e.g., Python, Go) and be able to effectively leverage AI-assisted development tools to build security tooling, automate workflows, and accelerate code review.
Demonstrated track record of successfully implementing complex hybrid IAM infrastructures, integrating a massive footprint of third-party SaaS applications alongside internally developed microservices.
Deep operational and architectural understanding of Identity Governance and Administration (IGA) processes, including automated provisioning/deprovisioning (JML workflows), continuous access reviews, and privileged access management (PAM) across a diverse enterprise fleet.
Extensive expertise in modern identity protocols (SAML, OAuth2, OIDC, SCIM), cloud IAM (AWS and GCP), and dynamic access control frameworks (RBAC, ABAC, ReBAC) that adapt based on behavioral context and AI-driven risk scoring.
Strong background in applied risk management, automated threat modeling, and zero-trust architecture principles applied to high-growth distributed systems and globally distributed workforces.
An execution-focused mindset with the ability to navigate ambiguity, drive alignment without direct authority, and communicate highly technical risk concepts to business stakeholders.
Experience driving security and engineering outcomes across decentralized or federated organizational structures, where the ability to build consensus, influence without direct authority, and coordinate delivery across multiple contributing teams is essential to success.
Demonstrates the ability to responsibly use generative AI tools and copilots (e.g., LibreChat, Gemini, Glean) in daily workflows, continuously learn as tools evolve, and apply human-in-the-loop practices to deliver business-ready outputs and drive measurable improvements in efficiency, cost, and quality.
Nice to haves:
Experience operating in a hyper-growth tech, FinTech, or crypto environment, navigating strict regulatory landscapes (e.g., SOX) specifically regarding workforce access, logging, and auditing.
Experience governing non-FTE workforce populations (such as BPO, contractors, and M&A) at scale, including birthright access design, role-based access control for high-risk personas, and timely deprovisioning across complex identity lifecycles.
Hands-on experience with Policy-as-Code paradigms (like Open Policy Agent) and integrating machine learning to automate policy generation, detect permission anomalies, or streamline IGA certification campaigns.
Experience managing identity boundaries for AI/ML workloads, including securing workforce access to large language models, training data pipelines, and inference infrastructure.
Job #: P76467
#LI-Remote
Pay Transparency Notice: * *Depending on your work location, the target annual *base *salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, vision and 401(k)).
Annual base salary range (excluding equity and bonus):
$218,025—$256,500 USD
Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying.
Commitment to Equal Opportunity
Coinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the Employee Rights and the Know Your Rights notices by clicking on their corresponding links. Additionally, Coinbase participates in the E-Verify program in certain locations, as required by law.
Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations[at]coinbase.com to let us know the nature of your request and your contact information. For quick access to screen reading technology compatible with this site click here to download a free compatible screen reader (free step by step tutorial can be found here).
Global Data Privacy Notice for Job Candidates and Applicants
Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required. For US applicants only, by submitting your application you are agreeing to arbitration of disputes as outlined here.
AI Disclosure
For select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description.
For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate.
The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment . To request a reasonable accommodation due to disability, please contact accommodations[at]coinbase.com
$200k - $350k
...Senior / Staff Network Security Engineer Fluidstack is looking for a seasoned Senior / Staff Network Security Engineer to spearhead our security... ...WAF rules and traffic-scrubbing tactics. Zero-Trust & IAM: Hands-on design of Zero-Trust networks, including IAM, SSO...SuggestedLocal area- ...% high availability with mission critical capabilities built in such as security, compliance controls, and observability. For more information, visit Job Summary As a Staff Security Engineer at EDB, you will be a technical leader with a developer-centric background...SuggestedRemote work
- ...that operate safely in the real world. We move fast, ship often, and rely on pragmatic engineering to make high-risk systems trustworthy. We're hiring a Staff TLM, Security Engineering - a hands-on leader who both manages a small team and executes high-impact...Suggested
$189k - $330.75k
...aware that all official communication will only be sent from @Rippling.com addresses. About the role We are seeking a Staff Security Engineer to join our Detection and Response team (DART). This role is for a security engineer with deep threat hunting instincts and...SuggestedWork at office3 days per week$225k - $275k
...giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. Affirm values information security as a critical part of the company’s continued success. Our mission is to make information security programmatic and cultural in...SuggestedWork at officeRemote workFlexible hours$194k - $270k
...metro area. Please ensure you can realistically commit to this structure before applying. Position Summary The Staff AI Security Engineer is a strategic individual contributor role responsible for advancing BetterUp's product and application security posture...Work experience placementSummer holidayLive outWork at officeLocal areaFlexible hours2 days per week$255k - $285k
...Staff Application Security Engineer At Bumble, we're redefining how security scales across global engineering organizations. We're looking for a Staff Application Security Engineer to design and implement developer-focused security solutions that make secure development...Live inWork at officeLocal area- ...expertise, capable of driving enterprise security initiatives and influencing organizational... .... As a Senior Security Software Engineer, you will design, lead, and deliver secure... ...connect our cyber ecosystem (SIEM, EDR, IAM, SSPM, CSPM, ITSM, cloud) and activate AI...Local areaWork from homeRelocation package
$98.9k
...What you can expect The Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate... ...permissions and configuration issues within components like IAM and S3. Performing an in-depth security review of new Zoom...Work at officeRemote work$79.1k - $129.95k
...Senior Security Engineer Headquarters CGM - Austin, TX Overview Salary Range $79,100.00 - $129,950.00 Salary/year Position Type Full... ...across Security Hub, GuardDuty, Inspector, Macie, CloudTrail, and IAM. Collaborate with cloud engineering and DevOps teams on...Full timeWork experience placementWork at office- ...Job Description Looking for a Security Engineer to join an Access Security operations team. This role will provide critical support across... ...engineering using Ping Identity, and Identity & Access Management (IAM) compliance operations including quarterly access...
$150k - $175k
...fully on-chain. In this environment, security is viewed as a primary client-facing... ...negotiations. Our client is seeking a Security Engineer to serve as the hands-on execution layer... ...& Cloud: Demonstrated experience with IAM platforms and AWS security services (IAM,...Full timeContract work- ...Soni's client is looking for a hands-on Security Engineer to help advance security platforms, detections, automation, and cloud security capabilities... ...(Security Hub, GuardDuty, Inspector, Macie, CloudTrail, IAM) • Expand observability, telemetry, and detection...
- ...expertise, capable of driving enterprise security initiatives and influencing organizational resilience. As a Staff Security Software Engineer on GM's Security Operations... ...cross-org programs that unify SIEM/EDR/IAM/SSPM/CSPM/ITSM/cloud data models and establish...Contract workLocal areaWork from homeRelocation package
- ...through autonomous and intelligent platforms. Security at Saronic is a force multiplier. We're seeking a Security Engineer at the senior-level or above to own the design,... ..., layered security model Design and enforce IAM patterns across AWS accounts, services, and...Permanent employmentTemporary workWork at office
$159.3k - $202.4k
...Amazon Healthcare Security's (HealthSec) AI team is hiring a Security Engineer II to secure GenAI applications and enable secure AI adoption across Amazon Health Services (AHS). You will work at the intersection of AI for Security and Security for AI-securing AHS GenAI...Flexible hours- ...Team We are looking for an enthusiastic Offensive Application Security Intern to join our team, where you'll conduct simulated... ...more of: C, C++, PHP, Go,x86, ARM, CAN, cryptography, reverse engineering, wireless networks Strong understanding of common web vulnerabilities...Full timeTemporary workPart timeInternshipFlexible hours
- ...must be able to work 40 hours per week on-site. Many students will be limited to part-time during the academic year. Tesla Security Engineering is responsible for the digital and physical security systems that protect Tesla's people, places, and intellectual property....Full timeTemporary workPart timeInternshipRelocationFlexible hours
$159.3k - $202.4k
...creating a family of new Generative AI models and applications that are efficient and capable. Key job responsibilities As a Security Engineer within the AGI/AI Security team, you will play a crucial role in ensuring that large language models and applications across...InternshipFlexible hours$159.3k - $202.4k
...Description Are you passionate about delivering innovative security solutions and protecting millions of customers through a blend... ...Security team is looking for a talented and results-driven Security Engineer to help shape how Amazon protects customer data through secure-...Flexible hours- ...art solutions that enhance maritime operations through autonomous and intelligent platforms. Security at Saronic is a force multiplier. We're seeking a Security Engineer at the senior-level or above focused on hardware, embedded systems, and firmware security to own...Permanent employmentTemporary workWork at officeRemote work
$159.3k - $202.4k
...maintaining their trust. To earn that trust in an environment as vast and varied as Amazon's requires the applied skills of smart security engineers and experienced, innovative security leaders willing to tackle challenges at dizzying scales. We are seeking Security...Flexible hours- ...Sr Security Engineer -Endpoint Security Location: Austin, TX (Onsite/Remote) Duration: Contract/Fulltime Job Description: Qualification Minimum five years of full-time experience in cybersecurity experience Experience managing Endpoint Security technologies...Full timeContract workRemote work
- ...Senior Physical Security Systems Engineer Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of... ...and firewall configurations Identity & Access Management (IAM) Experience with SAML, SCIM, OAuth, or similar...Permanent employmentTemporary workWork at office
$155.8k - $262.55k
...unified view. This is a Senior Staff role: you will design and... ...closely with product and UI engineering to deliver low-latency experiences... ...product, infrastructure, security, and analytics teams to define... .... Familiarity with IAM/IGA, compliance, security, or...Temporary workRemote workFlexible hours- ...Security Operations Engineer II The Security Operations Engineer II is responsible for monitoring, supporting and improving the company’s security... ...operations while helping mature vulnerability management, IAM practices, incident response and overall security readiness...
- ...developers or autonomous agents is reliable, secure, and maintainable. Integrating... ...In this role, you will: Be a pivotal engineering contributor to the design, implementation... ...Practical experience operating IdPs and IAM systems at scale (e.g., Okta, Azure AD, or...Relocation
- ...Security Engineer Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms. Security at Saronic is a force multiplier. We'...Permanent employmentContract workTemporary workWork at office
- ...Security Service Enablement/Systems Engineer Location: Austin, TX Duration: Long term contract Skills: Hands-on knowledge of IaaS and PaaS... ...Clouds such as AWS, GCP, AliCloud Strong competency with IAM policies such as Resource Policy, Service Control...Long term contract
$168.56k - $231.77k
...We're looking for a Manager, Security Engineering to lead and build alongside Procore's innovative... ..., secure, and resilient. If you are a Staff-level engineer who has found a passion... ...automated remediation workflows, and agentic IAM guardrails. Orchestrate the...Contract workWork at officeLocal areaImmediate startShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Engineer, IAM. Be the first to apply!
- staff design engineer Austin, TX
- engineering aide Austin, TX
- software engineer staff Austin, TX
- technology administrator Austin, TX
- staff engineer Austin, TX
- research assistant engineering Austin, TX
- senior staff engineer Austin, TX
- assistant engineer Austin, TX
- senior staff systems engineer Austin, TX
- sr information security engineer Austin, TX


