Staff Security Engineer, IAM
$218.03k - $256.5kCoinbase, Inc.
Ready to be pushed beyond what you think you’re capable of?
At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the future global financial system.
To achieve our mission, we’re seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company’s hardest problems.
Our work culture is intense and isn’t for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there’s no better place to be.
While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported.
At Coinbase, identity and access controls are foundational to protecting customer funds, sensitive data, and the trust that underpins our position as the world's most trusted crypto platform. The Identity and Access Management (IAM) program, housed within Security, is a cross-functional team that designs, builds, and governs workforce identity services, privileged access controls, and automated governance across a complex and rapidly evolving technology ecosystem and regulatory landscape. This role serves as a senior technical leader within the IAM program, partnering with Engineering, IT, Platform, and business teams to architect and deliver identity solutions that balance zero-trust security with workforce enablement, reduce insider risk, and satisfy global regulatory requirements.
What you’ll be doing (ie. job duties):
Lead the architectural vision and security engineering execution for Coinbase’s Identity and Access Management (IAM) and workforce security platforms across our multi-cloud infrastructure, extensive third-party SaaS ecosystem, and internally developed applications.
Evaluate, design, and implement "build, buy, or hybrid" strategies for workforce Identity Governance and Administration (IGA), integrating commercial tools with custom middleware and machine learning or AI models to automate complex access lifecycles and maximize ROI.
Write high-quality code to build scalable automation, custom integrations, and self-service guardrails that embed intelligent identity controls directly into CI/CD pipelines, SaaS provisioning workflows, and internal enterprise tooling.
Conduct comprehensive threat modeling and security architecture reviews for foundational identity systems and critical SaaS integrations, utilizing automated threat intelligence and AI-assisted analysis to proactively identify attack vectors and design resilient mitigations.
Partner with Engineering, IT, HR, AI/ML, and Product teams to align security initiatives with business goals, balancing robust zero-trust security with developer velocity and seamless workforce enablement.
Act as the directly responsible individual (DRI) for complex, cross-team security initiatives, mentoring junior and mid-level engineers, and influencing senior leadership on risk tradeoffs and next-generation workforce security strategies.
What we look for in you (ie. job requirements):
7+ years of proven experience in software engineering, security engineering, or systems architecture, with a deep, Staff-level focus on Identity and Access Management and enterprise workforce security.
Must be proficient in at least one programming language (e.g., Python, Go) and be able to effectively leverage AI-assisted development tools to build security tooling, automate workflows, and accelerate code review.
Demonstrated track record of successfully implementing complex hybrid IAM infrastructures, integrating a massive footprint of third-party SaaS applications alongside internally developed microservices.
Deep operational and architectural understanding of Identity Governance and Administration (IGA) processes, including automated provisioning/deprovisioning (JML workflows), continuous access reviews, and privileged access management (PAM) across a diverse enterprise fleet.
Extensive expertise in modern identity protocols (SAML, OAuth2, OIDC, SCIM), cloud IAM (AWS and GCP), and dynamic access control frameworks (RBAC, ABAC, ReBAC) that adapt based on behavioral context and AI-driven risk scoring.
Strong background in applied risk management, automated threat modeling, and zero-trust architecture principles applied to high-growth distributed systems and globally distributed workforces.
An execution-focused mindset with the ability to navigate ambiguity, drive alignment without direct authority, and communicate highly technical risk concepts to business stakeholders.
Experience driving security and engineering outcomes across decentralized or federated organizational structures, where the ability to build consensus, influence without direct authority, and coordinate delivery across multiple contributing teams is essential to success.
Demonstrates the ability to responsibly use generative AI tools and copilots (e.g., LibreChat, Gemini, Glean) in daily workflows, continuously learn as tools evolve, and apply human-in-the-loop practices to deliver business-ready outputs and drive measurable improvements in efficiency, cost, and quality.
Nice to haves:
Experience operating in a hyper-growth tech, FinTech, or crypto environment, navigating strict regulatory landscapes (e.g., SOX) specifically regarding workforce access, logging, and auditing.
Experience governing non-FTE workforce populations (such as BPO, contractors, and M&A) at scale, including birthright access design, role-based access control for high-risk personas, and timely deprovisioning across complex identity lifecycles.
Hands-on experience with Policy-as-Code paradigms (like Open Policy Agent) and integrating machine learning to automate policy generation, detect permission anomalies, or streamline IGA certification campaigns.
Experience managing identity boundaries for AI/ML workloads, including securing workforce access to large language models, training data pipelines, and inference infrastructure.
Job #: P76467
#LI-Remote
Pay Transparency Notice: * *Depending on your work location, the target annual *base *salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, vision and 401(k)).
Annual base salary range (excluding equity and bonus):
$218,025—$256,500 USD
Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying.
Commitment to Equal Opportunity
Coinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the Employee Rights and the Know Your Rights notices by clicking on their corresponding links. Additionally, Coinbase participates in the E-Verify program in certain locations, as required by law.
Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations[at]coinbase.com to let us know the nature of your request and your contact information. For quick access to screen reading technology compatible with this site click here to download a free compatible screen reader (free step by step tutorial can be found here).
Global Data Privacy Notice for Job Candidates and Applicants
Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required. For US applicants only, by submitting your application you are agreeing to arbitration of disputes as outlined here.
AI Disclosure
For select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description.
For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate.
The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment . To request a reasonable accommodation due to disability, please contact accommodations[at]coinbase.com
$191k - $253k
...not years. ABOUT THE TEAM Anduril's Application and Security Engineering team is looking for a Staff Security Engineer to focus on Identity and Access Management... ..., access reviews, offboarding Collaborate with other IAM engineers and partner teams to define architecture and...SuggestedFull timeWork experience placement$110k - $230k
...Careers. This role is designed for a staff-level security practitioner with deep Cyber Governance... ...capabilities. The Staff Security Engineer owns the end-to-end automated cyber governance... ...governance evidence (e.g., cloud, IAM, logging, asset inventory) Accountability...SuggestedHourly payWork experience placementLocal areaRemote workFlexible hours- ...Senior Security Engineer II For Identity And Access Management (Iam) As a Senior Security Engineer II for Identity and Access Management (IAM) at Aledade, you will play a central role in enhancing the security posture of our enterprise, cloud-native environments, and...SuggestedTemporary workRemote workFlexible hours
$218.03k - $256.5k
...Attendance is expected and fully supported. Coinbase Infrastructure Security (InfraSec) is at the forefront of protecting the foundation of... ...and platform services. This role partners closely with engineering teams to design, implement, and automate cutting-edge security...SuggestedLocal area$180k - $247.5k
...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the... ...'re all in on this mission. If you are too, let's talk. Staff Security Engineer - Vulnerability Management, US Public Sector The Okta...SuggestedPermanent employmentLocal areaWorldwideFlexible hours$210k - $230k
...ll report into the Director, Information Security and build relationships with technology stakeholders... ...our AppSec posture and enable our engineers to code safely. Innovate with AI and... ...administration of AWS Control Tower and IAM provisioning Interact with the security...Full timeWork at officeFlexible hours- As a Staff Security Assurance Engineer within the Security Assurance Team, you will help lead high‑visibility security compliance implementation initiatives. Reporting directly to the Senior Director, you will serve as a strategic catalyst for these programs, ensuring seamless...Relocation
- Databricks Inc. is seeking a Staff Security Assurance Engineer to lead high-visibility security compliance implementation initiatives. You will collaborate across teams to ensure effective project execution and alignment with security objectives. An active Top Secret clearance...
$110k - $230k
...Great Company, Great Culture, Great Rewards, and Great Careers. GEICO's Platform Security Engineering organization has an exciting opportunity for an accomplished Staff Engineer - Platform Security Engineering - Encryption and Tokenization . This individual...Hourly payWork experience placementLocal areaFlexible hours$197k - $266.8k
A leading location services company is seeking a Staff Cloud Security Engineer to join their Security & Compliance team. You will implement and conduct security assessments, improve security protocols across AWS services, and collaborate with various teams to ensure secure...Remote job$205k - $233k
...manufacturing capacity. We’re looking for a Staff Cyber Resilience Engineer to lead our defense against the... ...team, have direct influence on our security architecture, and lead recovery... ...understanding of cloud-native attack patterns: IAM privilege escalation, backup deletion...- ...firm is seeking an experienced Identity and Access Management (IAM) Engineer to support large-scale IAM projects for government clients.... ...analyzing identity lifecycles and implementing solutions that ensure secure access to critical assets. Candidates must have a Secret...Remote job
- Rividium is seeking an IAM Engineer to aid Military Community and Family Policy. This hybrid position demands expertise in IT and cybersecurity... ...include supporting account management and maintaining secure access controls. Applicants should have a Bachelor’s degree and...Remote work
- A prominent IT staffing company in McLean, Virginia is seeking an IAM professional responsible for user provisioning and application account management. Ideal candidates will have 3-5 years of experience with IAM concepts, strong Java/J2EE skills, and database support....
- A technology solutions company is seeking a Staff IT Engineer to manage enterprise device lifecycle management and security tooling. This hybrid role requires over 10 years of IT engineering or systems administration experience. The ideal candidate will have deep knowledge...
$114k - $142k
...across different fields and industries. Are you ready to help us make the future? We are seeking a Cyber Security Architect/Engineer II – Active Directory/IAM to join our team. In this role, you will work remotely and report directly to our Cyber Security Director....Permanent employmentTemporary workWork experience placementRemote workFlexible hours$210k - $230k
Upside is seeking an experienced Security Engineer to identify and mitigate application vulnerabilities. This role requires expertise in application security and a deep understanding of AWS architecture. Responsibilities include innovating security solutions and conducting...Work at office$189k - $274k
...efficient and accessible for all. We're searching for a Staff Security Platform Engineer to join our Enterprise Security Engineering team,... ...security platform stack - including EDR/XDR, MDM, SIEM, DLP, IAM/IGA, DNS security, Email security, and PKI - ensuring each...Full timeWork at officeLocal area3 days per week$98.9k
...What you can expect The Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate... ...permissions and configuration issues within components like IAM and S3. Performing an in-depth security review of new Zoom...Work at officeRemote work- ...Senior Security Engineer The Security Engineering team is responsible for protecting Sift's products, infrastructure, and data while enabling... ...tooling across Sift's infrastructure and applications (e.g., IAM policies, network controls, secrets management, endpoint...
- ...IT Security Engineer At IntraFi, we do more than innovate—we empower. Our services help banks provide vital financial access to small businesses... ...WAF), AWS CloudFormation, AWS Identity and Access Management (IAM), AWS GuardDuty, AWS CloudTrail, Microsoft EntraID, Microsoft...Flexible hoursWeekend work
- ...Senior Security Engineer We are seeking a Senior Security Engineer to strengthen cloud and software environments, ensuring compliance with... ...FedRAMP compliance processes. Security Engineering: Expertise in IAM, encryption, SIEM, vulnerability management, and Python...
- ...Title: Senior Security Engineer Location : Arlington, VA Duration: 12 months Enterprise Security Architecture and Innovation works to... ...Security engineering (hands on experience working with firewalls, IAM solutions, log management, scanning) Python scripting, TCP/...
$95k - $142k
...Senior Identity Security Engineer Palantir builds the world's leading software for data-driven decisions and operations. By bringing the right... ...and unified policy enforcement across workforce and customer IAM. As part of Palantir's best-in-class Information Security...Work experience placementWork at officeRemote workWork from homeRelocation packageShift work$149k - $248k
...with federal and regulated commercial clients to design, engineer, and operate modern security capabilities that enable mission success in an evolving threat... ...Engineer and modernize identity and access management (IAM/ICAM) capabilities, including MFA, SSO, identity...Temporary workRemote workFlexible hours$175k - $195k
...Jito Security Engineer Jito builds the Market Layer of Solana: the execution systems, capital markets, and incentive mechanisms that power... ...and endpoint policy enforcement Familiarity with enterprise IAM systems and SSO - configuration, integration, and audit Experience...- ...Senior Network Security Engineer II As a Senior Network Security Engineer II you will lead the design, implementation, and maintenance of... ...Expertise in securing cloud environments such as AWS (e.g., VPCs, IAM, Security Groups), Azure (e.g., VNets, NSGs, Azure Firewall),...Remote workFlexible hours
- ...Juicebox Security Engineer Opportunity Juicebox is on a mission to help teams win the talent war. In the age of AI, human ingenuity is the... ...on experience with AWS infrastructure and security primitives (IAM, networking, RDS, etc.). Experience with infrastructure-as...Worldwide
$180k - $240k
...Security Lead You'll be the hands-on security lead embedded with core product teams to... ...protected in production. We are looking for engineers who have expertise in cloud/... ...management, key rotation, least-privilege IAM, egress controls What you'll bring:...Work at officeImmediate startFlexible hours- ...strategic business goals of our clients. Position Title: AWS Security Engineer Location: University of Maryland Global Campus 3... ...Design, implement, and manage AWS cloud security controls (IAM, VPC, S3, KMS, GuardDuty, CloudTrail, Security Hub). Conduct...For contractorsLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Engineer, IAM. Be the first to apply!
- assistant engineer Washington DC
- staff engineer Washington DC
- software engineer staff Washington DC
- senior staff systems engineer Washington DC
- senior staff engineer Washington DC
- technology administrator Washington DC
- engineering aide Washington DC
- staff security engineer Washington DC
- endpoint security engineer Washington DC
- senior cloud security engineer Washington DC

