Staff Security Engineer, IAM
$168k - $238kGitLab
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.
The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. *Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role The Corporate Security Identity Team is on a mission to transform how our workforce ecosystem securely accesses the tools they need to do their best work, advancing from foundational controls to sophisticated, automated governance across our identity platforms and our emerging AI tooling. As a Staff Security Engineer, you'll be a senior technical leader and strategic anchor on the team. You're passionate about designing elegant solutions to complex identity challenges, whether that's architecting enterprise-scale conditional access policies, codifying our configuration of our identity platforms, or building governance frameworks for AI agents and non-human identities. You'll be responsible for critical systems, write technical proposals that influence our roadmap, raise the bar through design and code review, and lead cross-functional initiatives that span Security, IT, Engineering, Compliance and People teams. We're deliberately moving off click-ops and low-code platforms. Configuration is becoming peer-reviewed code; automation is becoming tested code running on GCP Cloud Run. Join us to lean in! What you'll do- Design comprehensive identity and AI access solutions that scale with our business growth, from AI agent governance frameworks to privileged access workflows that eliminate standing access through just-in-time provisioning
- Replace low-code automation with engineered services, migrating our existingiPaaS automation to Python services on GCP Cloud Run with source control, tests, CI and observability
- Codify our identity platforms in Terraform/OpenTofu/Pulumi , leading the migration of Okta, Lumos, and our NHI platform from click-ops to peer-reviewed infrastructure-as-code, with a focus on global critical policies
- Help re-architect identity and access across our GCP and AWS organizations, partnering on resource hierarchy design, secure-by-default guardrails (org policies, SCPs, permission boundaries), workload identity federation, and a credible path to least privilege for both human and workload access
- Lead identity and access engineering for our enterprise AI platforms including administration, SSO and SCIM integration, audit logging, data controls, and policy enforcement for Claude (web, Claude Code, Cowork) and adjacent tools
- Pioneer non-human identity governance by designing monitoring and management solutions for service accounts, API keys, certificates, AI agents, and MCP integrations, and leading deployment, integration, and operationalization of our NHI platform across the SaaS estate
- Drive cross-functional initiatives with Security, IT, Engineering, Enterprise AI, and the Office of the CIO to extract requirements from ambiguous business needs and translate them into actionable technical specifications
- Mentor senior and intermediate engineers on technical implementation and strategic thinking, helping them develop expertise in modern identity and AI security practices
- Extensive IAM experience designing and implementing enterprise-scale solutions, with demonstrated time at a Staff or senior IC level
- Expert-level Okta expertise including Identity Engine, advanced authentication policies, lifecycle workflows, and API automation
- Strong infrastructure-as-code practice with Terraform/OpenTofu/Pulumi , including provider experience for SaaS identity platforms and a track record of migrating click-ops to code
- Proficiency writing and shipping Python as a software engineer designed asmodular, tested, code-reviewed, deployed as services (GCP Cloud Run or equivalent serverless runtime) and instrumented for failure
- Cloud identity depth in GCP and/or AWS , including resource hierarchy and organization design, IAM policy models, workload identity federation, and preventive controls such as org policies, SCPs, and permission boundaries
- Hands-on experience administering or governing enterprise AI platforms (Anthropic Claude preferred; OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or similar acceptable), and awareness of AI-specific risks including prompt injection, MCP attack surface, agent identity, and data leakage
- A working practice of building with AI tooling you use agentic tools (Claude Code, Cursor, or similar) in your daily engineering work, iterate on your own workflows as capabilities shift, and can bring the rest of the team along. The tooling landscape changes monthly and identity is at the center of it; we want someone whose instincts stay current because they're a practitioner
- Experience with IGA platforms like Lumos, ConductorOne, or similar, with a preference for managing them declaratively
- Experience in regulated environments with knowledge of compliance frameworks (FedRAMP, SOC2, SOX), including change management, evidence collection, and audit support
- Passion for emerging identity challenges including AI agent governance, non-human identity management, zero-trust architecture, and behavioral analytics
- Experience carrying a cloud org restructuring through to completion , including the migration and stakeholder work, not just the target-state design
- Benefits to support your health, finances, and well-being
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave
Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us. GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab's policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know during the recruiting process.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Staff Security Engineer, IAM in United States vacancy
- Austin, TXTechnology - Security /RemoteThe Staff Security Engineer will be responsible for designing, implementing, and maintaining security identity services... ...environmentsDomain Specific Minimum RequirementsCloud IAM Architecture: Deep knowledge of cloud security...SuggestedTemporary workRemote workFlexible hours
- ...proposals, review designs and code, and mentor senior and intermediate engineers. Requirements Extensive experience designing and implementing enterprise-scale IAM solutions, including experience at a Staff or senior individual-contributor level. Expertise with Okta...SuggestedFull timeRemote workFlexible hours
$168k - $238k
...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Security Engineer, IAM based in United States. As a Staff Security Engineer, IAM, you’ll serve as a senior technical leader shaping how a...SuggestedFull timeRemote workFlexible hours- GEICO seeks an experienced Staff Engineer to solve complex Identity and Access Management challenges. You will lead a technical IAM roadmap to increase delivery speed and unlock security capabilities across the organization. You will collaborate with product managers, engineers...Suggested
- GEICO is seeking a Staff Engineer to work with Distinguished Engineers to innovate and build systems... ..., improve existing solutions, and apply security expertise to protect our identity... ...with product teams to drive the technical IAM roadmap and ensure secure authentication...Suggested
$232k - $290k
...opportunities, join us, and build real world value.THE WORK:As a Senior Staff Security Engineer focused on AI Security, you will be Ripple's deepest... ...CI/CD pipeline security, container and Kubernetes security, IAM, and API security, with the ability to reason about how...Full timeWork at officeLocal area- ...breaking speeds.About You and The Role Product security at Zipline protects systems that... ...embedded, and field-ops teams. Expect hands-on engineering work, prioritized ownership of specific... ...and implement production controls: IAM/least-privilege policies, service-to-service...Local area
$232k - $310k
...opportunities, join us, and build real world value.THE WORK:As a Senior Staff Security Engineer, you will be one of Ripple's most senior technical security... ...architecture for Treasury across Azure and AWS, including IAM, network segmentation, encryption, zero trust controls,...Full timeWork at officeLocal area- ...problems to help creatives do their best work.As our first Principal Security Engineer, you will own the security posture for the entire organization... ...-on generalist. You are just as comfortable configuring an IAM policy in AWS as you are setting up a switch in a colocation...Full timeWork at officeRelocation
$165k - $200k
Atlanta (Remote Friendly)Security /Full Time /RemoteGreenlight is a family technology... ...morning.Greenlight is looking for a Staff Offensive Security Engineer for our Security team. This... ...AWS security architecture, including IAM bypass techniques, container escapes...Full timeWork at officeLocal areaRemote workWork from homeDay shift$156k - $255k
...information every day and we take their security seriously. Our core value of putting our... ...enterprise Identity and Access Management (IAM) platforms and services, enabling secure... ...scalable access across the organization.Engineer and deliver new identity capabilities that...For contractorsWork at officeFlexible hours$168.56k - $231.77k
We’re looking for a Staff Security Engineer to join Procore’s Security Engineering team as a foundational technical leader. In this role, you won... ...Identity—designing how autonomous agents authenticate (IAM/OIDC), manage secrets, and operate within least-privilege guardrails...Full timeContract workWork at officeLocal areaShift work$245k - $280k
...manage the entire content lifecycle, secure critical content, and transform business... ...the globe. We are looking for a Staff Enterprise Security Engineer who will be a part of our Enterprise... ...deploymentsIdentity and access management (IAM/PAM/passwordless authentication)CASB/...Live inWork at officeImmediate startShift work3 days per week$171k - $247k
...Staff Security Engineer Aurora's mission is to deliver the benefits of self-driving technology safely, quickly, and broadly. The Aurora Driver... ...platform capabilities across domains such as EDR/XDR, MDM, IAM/IGA, DLP, SaaS security, cloud security, or PKI. ~ Experience...Work at officeLocal area3 days per weekEarly shift- ...Staff Security Engineer Location: Hybrid in one of these places 2 days a week: Orange County, CA, Seattle, WA, Columbus, OH, or DC (So must... ..., access reviews, and offboarding Collaborate with other IAM engineers and partner teams to define architecture and ship...2 days per week
- ...Responsibilities: - Own the end-to-end security posture across application, cloud,... ...Continuously audit cloud infrastructure, IAM configurations, access policies, and security... ...risks and trade-offs clearly to both engineering teams and executive stakeholders - High...Full timeH1bVisa sponsorshipMonday to Friday
- ...Responsibilities Own security outcomes for two to four named production areas and serve... ...readiness. Design and implement IAM, least-privilege, service-to-service trust... ...test and red-team findings into tracked engineering changes with measurable closure criteria...Full time
- ...We are seeking a Staff Security Engineer who operates at the nexus of high-level strategy and multi-tenant operational excellence. While a traditional... ...AWS/Azure security; Zero Trust Architecture (ZTA); Advanced IAM/Entra ID. SecOps & Intelligence Advanced SOAR/SIEM...Full time
- ...Responsibilities Drive Ripple’s AI Security technical strategy and roadmap across AI... ...Requirements ~10+ years of Security Engineering experience with depth in at least two domains... ...; container and Kubernetes security; IAM; and API security. ~ Experience with threat...Full timeWork at office
- GEICO is seeking an experienced Cyber Security Identity Staff Engineer in Bethesda, MD / other locations to lead IAM initiatives, design secure identity systems, and drive a technical roadmap. You will work with Distinguished Engineers to implement scalable authentication...
- GEICO seeks a Staff Engineer to innovate and build security systems focusing on identity and access management. You will lead the technical roadmap for secure... ...with peers and stakeholders to deliver robust IAM solutions. The ideal candidate has 4+ years in identity...
$156k - $255k
...the TeamLinkedIn’s Information Security organization protects our... ...early, and partnering across engineering to reduce risk at scale.The Detection... ...precision.About the roleAs a Staff Security Engineer on the... ...with IR/Threat Intel/Cloud/IAM to turn hypotheses and TTPs into...For contractorsWork experience placementWork at officeRemote workWork from homeFlexible hours- ...connectivity provider, is looking for a skilled and experienced Staff Information Security Engineer to join their technology team. Information security plays... ...operations.Platform EnvironmentIdentity & Access: IAM, SSO, RADIUS, TACACS+, AD/LDAP/Kerberos, Entra, PIM, Identity...Full timeWork at officeRemote workFlexible hours2 days per week
$132.1k - $220.1k
The primary responsibility of the Staff/Lead Security Engineer position will be the continued evolution and advancement of our Privileged Account Management... ..., the position will be involved in the support of other IAM-related technologies such as directory services, federation...Full timeWorldwide- At SRS, the Identity & Access Management (IAM) team plays a pivotal role in our cybersecurity program by enabling secure, scalable, and compliant access to enterprise... ...facing systems.We are seeking a Cybersecurity Staff Engineer - IAM to design, implement, support, and...Bi-weekly payWeekly payFull timeContract workTemporary workLocal areaFlexible hours
$168.2k - $310.1k
Position summary:The Senior Security Engineer position will be part of the Enterprise Security organization consisting of IAM professionals across several technologies. This specific position will have a specialized role in directory services and SaaS applications! It will...Full timeTemporary workLocal areaWorldwide- We are seeking an IAM / Security Engineer to join an Identity and Security Engineering team. This role is primarily focused on Identity and Access Management (IAM) with an opportunity to contribute to broader security engineering initiatives.The ideal candidate will have...
- Job ID: 25634493Reference Number: 25-00572Title: IAM Security EngineerLocation: Iselin, NJ, 08830Posted Date: 2025-06-03Contact: Deepak KumarContact... ...795-0621Company: HAN Staffing Job Title: Senior IAM Security Engineer Location: Jersey City, NJ (1 Pershing Plaza, Jersey City, NJ)...
- Job ID: 25649979Reference Number: 25-00584Title: Senior IAM Security EngineerLocation: Jersey City, NJJob Type: Full Time/ContractPosted... ...of learning, innovating, and continuous improvementPromote engineering best practices to deliver software via rapid iterations and frequent...Full time
$95k - $115k
DescriptionKforce has a client that is seeking a Security Engineer -IAM/SailPoint in Fort Worth, TX. The candidate will be instrumental in ensuring a successful migration and future-state implementation.Day-to-Day Responsibilities:SailPoint administration:* User access...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Engineer, IAM. Be the first to apply!
Related searches
- project engineer assistant project manager United States
- senior staff systems engineer United States
- information technology administrative assistant United States
- staff data engineer United States
- staff devops engineer United States
- staff process engineer United States
- assistant chief engineer United States
- assistant engineer United States
- information technology support assistant United States
- assistant electrical engineer United States


