Senior Identity Access Management Engineer
$158k - $279kFull-time
Roku
TEAMWORK MAKES THE STREAM WORK.
ROKU IS CHANGING HOW THE WORLD WATCHES TV
Roku is the #1 TV streaming platform in the U.S., Canada, and Mexico, and we've set our sights on powering every television in the world. Roku pioneered streaming to the TV. Our mission is to be the TV streaming platform that connects the entire TV ecosystem. We connect consumers to the content they love, enable content publishers to build and monetize large audiences, and provide advertisers unique capabilities to engage consumers. From your first day at Roku, you'll make a valuable - and valued - contribution. We're a fast-growing public company where no one is a bystander. We offer you the opportunity to delight millions of TV streamers around the world while gaining meaningful experience across a variety of disciplines.ABOUT ROLE
Roku is seeking a senior-level Identity Engineer to enhance its Zero-Trust architecture, drive standardization initiatives, and optimize its Microsoft-centric identity platform for a geographically distributed workforce. The ideal candidate has hands-on experience in identity and access management (IAM) and securing cloud environments within the Microsoft ecosystem, with deep expertise in Azure Entra ID. Equally important is a strong automation mindset—designing, scripting, and building repeatable workflows. The role also requires the ability to communicate complex technical concepts clearly to both technical and non-technical audiences. For New York Only - The estimated annual salary for this position is between $158,000 - $279,000 annually. Compensation packages are based on factors unique to each candidate, including but not limited to skill set, certifications, and specific geographical location. This role is eligible for health insurance, equity awards, life insurance, disability benefits, parental leave, wellness benefits, and paid time off.WHAT YOU'LL BE DOING
* Lead enterprise-wide IAM standardization, including identity lifecycle, access governance, and policy enforcement across global regions. * Drive automation across IAM to streamline administration and deliver a smoother user experience. * Support enterprise applications onboarding into Azure Entra ID, including SSO, Conditional Access, and role-based access control (RBAC). * Enhance privileged access management and implement scalable monitoring, alerting, and auditability solutions to support a secure, geographically distributed workforce. * Collaborate with IT, Networking, and Security teams to troubleshoot identity-related issues and support global infrastructure initiatives. * Advance Zero Trust Identity Fabric principles like continuous verification, least-privilege access, and identity-aware policy enforcement across users, devices, workloads, and non-human identities. * Build identity automation with a DevOps mindset, writing scripts, developing pipelines, and engineering tooling from scratch rather than just configuring them.WE'RE EXCITED IF YOU HAVE
* 8+ years of hands-on experience with identity and access management and automating cloud technologies, particularly within the Microsoft ecosystem. * Strong analytical skills and attention to detail, with the ability to troubleshoot complex infrastructure and identity-related issues. * Excellent communication skills, with the ability to clearly explain technical concepts to both technical and non-technical stakeholders. * Deep experience with Microsoft Entra ID, including Conditional Access, Identity Governance, and Privileged Identity Management. * Familiarity with Microsoft 365 services: Exchange Online, Defender, Purview, Sentinel, Intune, and related platforms. * Automation and scripting skills using PowerShell, Azure CLI, and Microsoft Graph API; working knowledge of Azure services such as Function Apps and Logic Apps. * Experience in onboarding and managing enterprise applications in Azure Entra ID. * Advanced knowledge of Azure Single Sign-On (SSO) login methods, including OAuth2, OpenID Connect, and SAML, and their integration with enterprise applications. * Knowledge of privileged access tools (Azure PIM, CyberArk, etc), secrets management (HashiCorp or Azure Key Vault), and workload identity patternsSPIFEE & SPIRE.
* Familiarity with NHI governance concepts for service accounts and AI agents, and exposure to OPA / Rego or similar policy-as-code frameworks. * Good to have familiarity with Microsoft Purview for DLP and data classification.- Strong understanding of multi-factor authentication and FIDO2.
- Familiarity with IT security frameworks and compliance standards.
- Knowledge of logging, monitoring, and alerting practices for identity and
- Basic understanding of email security and DNS.
- Experience with backup and recovery strategies for identity-related services.
- Understanding of Zero Trust Architecture principles.
- Familiarity with Jira and Confluence.
- B.S. in Computer Science, Information Technology, Engineering, or equivalent
#LI-RN1
OUR HYBRID WORK APPROACH
Roku fosters an inclusive and collaborative environment where teams work in the office Monday through Thursday. Fridays are flexible for remote work except for employees whose roles are required to be in the office five days a week or employees who are in offices with a five day in office policy.BENEFITS
Roku is committed to offering a diverse range of benefits as part of our compensation package to support our employees and their families. Our comprehensive benefits include global access to mental health and financial wellness support and resources. Local benefits include statutory and voluntary benefits which may include healthcare (medical, dental, and vision), life, accident, disability, commuter, and retirement options (401(k)/pension). Employees are supported in taking time off, in accordance with local leave policies and other personal needs to support their evolving work and life needs. It's important to note that not every benefit is available in all locations or for every role. For details specific to your location, please consult with your recruiter.ACCOMMODATIONS
Roku welcomes applicants of all backgrounds and provides reasonable accommodations and adjustments in accordance with applicable law. If you require reasonable accommodation at any point in the hiring process, please direct your inquiries to View email address on click.appcast.io [View email address on click.appcast.io?subject=Job%20Application%20Accommodations].THE ROKU CULTURE
Roku is a great place for people who want to work in a fast-paced environment where everyone is focused on the company's success rather than their own. We try to surround ourselves with people who are great at their jobs, who are easy to work with, and who keep their egos in check. We appreciate a sense of humor. We believe a fewer number of very talented folks can do more for less cost than a larger number of less talented teams. We're independent thinkers with big ideas who act boldly, move fast and accomplish extraordinary things through collaboration and trust. In short, at Roku you'll be part of a company that's changing how the world watches TV. We have a unique culture that we are proud of. We think of ourselves primarily as problem-solvers, which itself is a two-part idea. We come up with the solution, but the solution isn't real until it is built and delivered to the customer. That penchant for action gives us a pragmatic approach to innovation, one that has served us well since 2002. To learn more about Roku, our global footprint, and how we've grown, visit [ By providing your information, you acknowledge that you want Roku to contact you about job roles, that you have read Roku's Applicant Privacy Notice [ and understand that Roku will use your information as described in that notice. If you do not wish to receive any communications from Roku regarding this role or similar roles in the future, you may unsubscribe at any time by emailing View email address on click.appcast.io [View email address on click.appcast.io?subject=Unsubscribe%20Request%20].Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Senior Identity Access Management Engineer in New York, NY vacancy
$158k - $279k
About role Roku is seeking a senior-level Identity Engineer to enhance its Zero‑Trust architecture, drive standardization initiatives, and optimize... ...candidate has hands‑on experience in identity and access management (IAM) and securing cloud environments within the...SeniorWork at officeLocal areaRemote workMonday to ThursdayFlexible hours- ...A technology company in the United States is seeking a SailPoint Subject Matter Expert to implement identity and access management solutions. The role involves developing integrations, ensuring compliance with security standards, and creating technical documentation....Senior
- ...Senior Identity and Access Management Opening for a Senior Identity and Access Management Professional in the NY/NJ area. The successful candidate should have a strong track record of delivering IAM and Entitlements solutions from inception to deployment in the Production...SeniorPermanent employmentFull timeH1b
$55 - $65 per hour
...Description: Job Description: Job Title: Senior Identity Access Management Analyst Location: This is a hybrid role in... ...IGA system. The position will work with key stakeholders, engineers, risk and controls, audit and other business units and serve...SeniorContract workWork experience placementH1bWork at officeWeekend work$124k - $177k
...Identity & Access Management Developer Location Designation: Hybrid - 3 days per quarter As part of Technology, you'll have the... ...The Identity & Access Management (IAM) Developer is a senior, hands-on engineering role responsible for designing, developing, and supporting...Senior- ...having a team of great operators, engineers, and marketers working for... ...depends on secure, reliable access to the right tools at the... ...building the next generation of our identity and access platform, and we... ...over login, session management, permissions, roles, service-...SeniorWork at officeLocal areaRemote work
$148.7k - $240.53k
...About the role: We are looking for a product manager to join the team building out enterprise-grade identity and access management (IAM) product, integrations, and... ..., bridging between our customers and our engineering team. You'll translate the IAM needs of enterprise...SeniorTemporary workRemote work- ...A global cybersecurity company is seeking a Senior Software Development Engineer in Test (SDET) to join their Privileged Access Management team. This role focuses on designing and maintaining automation frameworks for security-sensitive workflows and collaborating closely...SeniorRemote work
- ...A leading technology solutions provider is seeking an InfoSec Engineer IV to define and support identity and access management solutions. This remote role requires expertise in Ping Identity technologies and substantial experience in IT security. The ideal candidate will...SeniorRemote work
$153k - $186k
...You’ll Work With We are seeking a Senior IAM Consultant with deep expertise in Identity Governance & Administration (IGA)... .... Develop and implement access certification campaigns, role-based... ...leadership on identity lifecycle management, provisioning/deprovisioning, and...SeniorTemporary workLocal area$95.86k - $208.27k
..., and have the flexibility and access to constantly find new areas of... ...KPMG is currently seeking a Senior Associate, Privileged Access Management Delivery Engineer to join our Advisory Services... ...solutions as part of enterprise Identity & Access Management (IAM) programs...SeniorFull timeH1bLocal area- ...A leading telehealth solutions provider in the United States seeks a Staff IAM Engineer to lead their Identity & Access Management program. This position involves mentoring a team, designing IAM solutions, and ensuring compliance with healthcare regulations like HIPAA....Senior
- ...application • Collaborate with the Cloud Engineering, Cloud Security, and Identity Teams on the administration and engineering of Role-Based Access Controls and processes • Help design... ...deployment activities, configuration management, supporting systems and business...Senior
$152.4k - $251.6k
...missionat MSK and around the globe. Exciting Opportunity at MSK: Principal Cyber Security Engineer - Identity Access Management (IAM) At MSK, this role serves as a senior technical authority for Identity and Access Management, shaping secure, scalable identity...Live inRemote workMonday to Friday- ...Job Overview The Principal Security Engineer, you will be the principal technical leader... ...will architect scalable solutions to manage the identity lifecycle for a diverse user base (Employees... ...-facing (CIAM) as appropriate. Secure Access & Authentication: Architect secure,...Permanent employmentWork at officeRemote work
- ...Learning Group is seeking a Principal Security Engineer who will architect scalable solutions for managing user identity across our platforms. You will define standards... ...experience in IT/Security with a focus on Identity and Access Management. This opportunity supports a remote-...Remote work
- ...experiences, and have the flexibility and access to constantly find new areas of... ...KPMG is currently seeking a Senior Associate, SailPoint Identity Governance Engineer to join our Advisory Services... ...solution (for example: Oracle Identity Manager, SailPoint Identity (IIQ)) to...SeniorH1bLocal area
$152.4k - $251.6k
...our mission at MSK and around the globe. Exciting Opportunity at MSK: Principal Cyber Security Engineer - Identity Access Management (IAM) At MSK, this role serves as a senior technical authority for Identity and Access Management, shaping secure, scalable identity...Live inRemote workMonday to Friday- DESCRIPTION We are looking for a talented Principal Technical Engineer - Identity & Access Management to join our team specializing in Systems/Information Technology in Atlanta, GA. In this role, you will make an impact in the following ways: Drive Strategic Cybersecurity...For contractorsWork experience placementRelocation package
$118k - $175.23k
...motivated, and goal-oriented Senior Electrical Engineer to join our Northeast... ...communications, SCADA interfaces, CCTV, access control) Coordinate... ..., design, and construction management; including active... .../Sexual Orientation/Gender Identity/National Origin/Disability...SeniorFor contractorsFor subcontractorWork at officeLocal areaFlexible hours- ...Cybermedia Technologies is looking for a Senior Quality Assurance Engineer in the United States. The ideal candidate will have over seven years of experience in software quality assurance, specialized in both manual and automated testing. You'll lead test strategy, ensure...Senior
- ...seeking an IAM Specialist to design and implement lifecycle management processes using Saviynt. The role requires 3+ years of... ...technology. Candidates should have a solid understanding of Identity and Access Management and IT security concepts. Responsibilities include...
- ...Framework Ventures is looking for a Software Engineer to execute on their vision for a modern customer identity and access management system. The successful candidate will design API solutions, develop them using Kong, and integrate CIAM solutions. Requirements include...
- ...The successful candidate will handle the security administration of systems, manage user identities, and ensure adherence to security procedures. A minimum of 1-2 years in identity and access management is required, along with ITIL certification and a working knowledge...SeniorRemote work
$85k - $130k
...Role Matters This is a senior-level position based... ...approaches to energy management, positioning SWA as leaders... ...bachelor’s degree in engineering field or related... ...sustainable, energy-efficient, accessible, healthy, and... ...including pregnancy, gender identity, and sexual...SeniorFull timeH1bLocal areaVisa sponsorshipWork visaFlexible hoursNight shift3 days per week- ...widely deployed renewable energy management suites (REMS) in the market.... ...Degree in Computer Science, Engineering, or similar 3+ years Docker... ...ISO27001), authentication & access (LDAP, PKI) DB... ...sexual orientation, gender identity, national origin, disability...SeniorWork experience placementRemote workWorldwide
$154k - $210k
...Senior Backend Engineer – Identity Security & Agentic Systems Remote, USA At Veza, we’re building the next generation of Access Identity Security and bringing GenAI into the core of that mission. We’re seeking a senior backend engineer who is excited to work on multi‑agent...SeniorLocal areaRemote work- The-Voleon-Group in New York, NY, is seeking an IAM Architect to define and execute our identity and access management strategy. You will work directly with the CISO and be responsible for designing modern identity solutions across hybrid infrastructures. Candidates should...Senior
$209.66k - $220.7k
...end to end, with compliance, identity checks, fraud prevention,... ...consumer app that makes crypto accessible, intuitive, and usable for... ...threat modelling. We actively manage our Bug Bounty program,... ...of security services to our Engineering teams including cloud security...SeniorRemote workWorldwideHome office$252.5k
...Senior Sales Engineer - Data & AI Security Remote, United States Veeam is the Data... ...resilience and data security posture management, built for the convergence of identity, data, security, and AI risk.... ..., Data Discovery, DSPM, Data Access & Governance, and Compliance (GDPR...SeniorRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Identity Access Management Engineer. Be the first to apply!
Related searches
- senior game producer New York, NY
- senior manager process engineering New York, NY
- senior manufacturing engineer New York, NY
- senior director fp&a New York, NY
- senior manager clinical operations New York, NY
- senior community manager New York, NY
- senior lead project manager New York, NY
- senior manager quality engineering New York, NY
- senior device engineer New York, NY
- senior full stack developer New York, NY


