Senior Identity Access Management Engineer
$158k - $279kFull-time
Roku, Building C
TEAMWORK MAKES THE STREAM WORK.
ROKU IS CHANGING HOW THE WORLD WATCHES TV
Roku is the #1 TV streaming platform in the U.S., Canada, and Mexico, and we've set our sights on powering every television in the world. Roku pioneered streaming to the TV. Our mission is to be the TV streaming platform that connects the entire TV ecosystem. We connect consumers to the content they love, enable content publishers to build and monetize large audiences, and provide advertisers unique capabilities to engage consumers. From your first day at Roku, you'll make a valuable - and valued - contribution. We're a fast-growing public company where no one is a bystander. We offer you the opportunity to delight millions of TV streamers around the world while gaining meaningful experience across a variety of disciplines.ABOUT ROLE
Roku is seeking a senior-level Identity Engineer to enhance its Zero-Trust architecture, drive standardization initiatives, and optimize its Microsoft-centric identity platform for a geographically distributed workforce. The ideal candidate has hands-on experience in identity and access management (IAM) and securing cloud environments within the Microsoft ecosystem, with deep expertise in Azure Entra ID. Equally important is a strong automation mindset—designing, scripting, and building repeatable workflows. The role also requires the ability to communicate complex technical concepts clearly to both technical and non-technical audiences. For Massachusetts Only - The estimated annual salary for this position is between $158,000 - $279,000 annually. Compensation packages are based on factors unique to each candidate, including but not limited to skill set, certifications, and specific geographical location. This role is eligible for health insurance, equity awards, life insurance, disability benefits, parental leave, wellness benefits, and paid time off.WHAT YOU'LL BE DOING
* Lead enterprise-wide IAM standardization, including identity lifecycle, access governance, and policy enforcement across global regions. * Drive automation across IAM to streamline administration and deliver a smoother user experience. * Support enterprise applications onboarding into Azure Entra ID, including SSO, Conditional Access, and role-based access control (RBAC). * Enhance privileged access management and implement scalable monitoring, alerting, and auditability solutions to support a secure, geographically distributed workforce. * Collaborate with IT, Networking, and Security teams to troubleshoot identity-related issues and support global infrastructure initiatives. * Advance Zero Trust Identity Fabric principles like continuous verification, least-privilege access, and identity-aware policy enforcement across users, devices, workloads, and non-human identities. * Build identity automation with a DevOps mindset, writing scripts, developing pipelines, and engineering tooling from scratch rather than just configuring them.WE'RE EXCITED IF YOU HAVE
* 8+ years of hands-on experience with identity and access management and automating cloud technologies, particularly within the Microsoft ecosystem. * Strong analytical skills and attention to detail, with the ability to troubleshoot complex infrastructure and identity-related issues. * Excellent communication skills, with the ability to clearly explain technical concepts to both technical and non-technical stakeholders. * Deep experience with Microsoft Entra ID, including Conditional Access, Identity Governance, and Privileged Identity Management. * Familiarity with Microsoft 365 services: Exchange Online, Defender, Purview, Sentinel, Intune, and related platforms. * Automation and scripting skills using PowerShell, Azure CLI, and Microsoft Graph API; working knowledge of Azure services such as Function Apps and Logic Apps. * Experience in onboarding and managing enterprise applications in Azure Entra ID. * Advanced knowledge of Azure Single Sign-On (SSO) login methods, including OAuth2, OpenID Connect, and SAML, and their integration with enterprise applications. * Knowledge of privileged access tools (Azure PIM, CyberArk, etc), secrets management (HashiCorp or Azure Key Vault), and workload identity patternsSPIFEE & SPIRE.
* Familiarity with NHI governance concepts for service accounts and AI agents, and exposure to OPA / Rego or similar policy-as-code frameworks. * Good to have familiarity with Microsoft Purview for DLP and data classification.- Strong understanding of multi-factor authentication and FIDO2.
- Familiarity with IT security frameworks and compliance standards.
- Knowledge of logging, monitoring, and alerting practices for identity and
- Basic understanding of email security and DNS.
- Experience with backup and recovery strategies for identity-related services.
- Understanding of Zero Trust Architecture principles.
- Familiarity with Jira and Confluence.
- B.S. in Computer Science, Information Technology, Engineering, or equivalent
#LI-RN1
OUR HYBRID WORK APPROACH
Roku fosters an inclusive and collaborative environment where teams work in the office Monday through Thursday. Fridays are flexible for remote work except for employees whose roles are required to be in the office five days a week or employees who are in offices with a five day in office policy.BENEFITS
Roku is committed to offering a diverse range of benefits as part of our compensation package to support our employees and their families. Our comprehensive benefits include global access to mental health and financial wellness support and resources. Local benefits include statutory and voluntary benefits which may include healthcare (medical, dental, and vision), life, accident, disability, commuter, and retirement options (401(k)/pension). Employees are supported in taking time off, in accordance with local leave policies and other personal needs to support their evolving work and life needs. It's important to note that not every benefit is available in all locations or for every role. For details specific to your location, please consult with your recruiter.ACCOMMODATIONS
Roku welcomes applicants of all backgrounds and provides reasonable accommodations and adjustments in accordance with applicable law. If you require reasonable accommodation at any point in the hiring process, please direct your inquiries to View email address on click.appcast.io [View email address on click.appcast.io?subject=Job%20Application%20Accommodations].THE ROKU CULTURE
Roku is a great place for people who want to work in a fast-paced environment where everyone is focused on the company's success rather than their own. We try to surround ourselves with people who are great at their jobs, who are easy to work with, and who keep their egos in check. We appreciate a sense of humor. We believe a fewer number of very talented folks can do more for less cost than a larger number of less talented teams. We're independent thinkers with big ideas who act boldly, move fast and accomplish extraordinary things through collaboration and trust. In short, at Roku you'll be part of a company that's changing how the world watches TV. We have a unique culture that we are proud of. We think of ourselves primarily as problem-solvers, which itself is a two-part idea. We come up with the solution, but the solution isn't real until it is built and delivered to the customer. That penchant for action gives us a pragmatic approach to innovation, one that has served us well since 2002. To learn more about Roku, our global footprint, and how we've grown, visit [ By providing your information, you acknowledge that you want Roku to contact you about job roles, that you have read Roku's Applicant Privacy Notice [ and understand that Roku will use your information as described in that notice. If you do not wish to receive any communications from Roku regarding this role or similar roles in the future, you may unsubscribe at any time by emailing View email address on click.appcast.io [View email address on click.appcast.io?subject=Unsubscribe%20Request%20].Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Senior Identity Access Management Engineer in Boston, MA vacancy
$113.87k - $165.11k
Job Summary The Senior Identity & Access Manager (IAM) Engineer is responsible for designing, implementing, and managing the identity and access management framework within Northeastern University. The role utilizes deep knowledge of IAM technologies, security protocols...Senior- ...Moderna Therapeutics is seeking a Senior IAM Engineer to lead the design and implementation of identity governance capabilities across the enterprise. This role focuses on access governance, identity lifecycle management, and integrating IAM solutions with enterprise...Senior
$130.8k - $209.4k
...The RoleModerna is seeking a Senior IAM Engineer with expertise in Identity Governance & Administration (IGA) to help design, build,... ...leadership with hands-on engineering, focused on access governance, identity lifecycle management, and provisioning across a complex, highly...SeniorPermanent employmentWork at officeWork from home- MGB Digital is Hiring!Senior IAM EngineerIdentity Governance and AdministrationFull TimeComprehensive benefitsHybrid... ...Working ModelThe OpportunityReporting to the Manager of Identity and Access Management, the Sr IAM Engineer is an integral member of the team responsible for...SeniorFull timeWork at officeLocal areaRemote workFlexible hours
$113.87k - $165.11k
The Chronicle Of Higher Education, Inc. is seeking a Senior Identity & Access Management Engineer to oversee IAM system design and management at Northeastern University. The role requires extensive experience in IAM technologies and security protocols to protect sensitive...Senior- ...financial institution in Boston is seeking a Senior IAM Information Security Controls Lead to manage and enhance identity management systems. The ideal candidate will have... ...of experience in Identity Governance and Access Management, be proficient in tools such as Active...Senior
- ...Identity & Access Management Analyst/ Consultant/ Engineer Location: Below mentioned locations (80-100% travel - expenses will be covered by client) Duration: Full Time Client: Client (Travel within New York, Florham Park/NJ, Boston MA, Hartford CT, Philly PA...Full time
$139.3k - $250.7k
...Senior Product Manager Do you enjoy building experiences that just work?... ...define how users securely access and manage a cloud services... ...and defining the complete identity and account management strategy... ...Ensuring collaboration among engineering, architecture, operations,...SeniorWork experience placementRemote work$125k - $205k
...the right creators, execute fully managed campaigns, and drive meaningful growth... ...[ ABOUT THIS POSITION: As a Senior Security Engineer at Later, you will play a critical role... ..., with a particular focus on identity and access management, authentication systems,...SeniorPermanent employmentLocal areaRemote work- A global leader in energy management seeks a Principal, Digital Accessibility Engineer to enhance its accessibility program. This full-time position in Boston involves auditing and guiding product teams on accessibility practices, ensuring compliance with WCAG standards...SeniorFull time
$148.7k - $240.53k
...About the role: We are looking for a product manager to join the team building out enterprise-grade identity and access management (IAM) product, integrations, and... ..., bridging between our customers and our engineering team. You'll translate the IAM needs of enterprise...SeniorTemporary workRemote work$135k - $182.1k
Bank of America is looking for a Senior IAM Information Security Controls Lead in Boston. This role will enhance security for IAM systems and manage identity lifecycle for the bank. Candidates should have 10+ years in IAM and finance, with deep knowledge in Active Directory...Senior- ...Identity and Access Management Senior Consultant Boston, Massachusetts;Washington, District of Columbia To proceed with your application, you... ...frameworks. Collaborate with partner cybersecurity, engineering, and compliance teams to develop and align controls with...SeniorWork at officeShift workDay shift
$95.86k - $208.27k
..., and have the flexibility and access to constantly find new areas of... ...KPMG is currently seeking a Senior Associate, Privileged Access Management Delivery Engineer to join our Advisory Services... ...solutions as part of enterprise Identity & Access Management (IAM) programs...SeniorFull timeH1bLocal area$135k - $182.1k
Senior Identity and Access Management Specialist Bank of America’s Global Information Security (GIS) is seeking a highly experienced Senior Identity and Access Management (IAM) Specialist to lead access provisioning initiatives across a complex enterprise environment. The...SeniorShift workDay shift$140.8k - $176k
...difference for the dreamers and builders in the world. We are seeking a Senior Software Engineer (IC3) to join our Customer Trust & Engineering team working on Identity and Access Management. IAM is the bedrock of trust at DigitalOcean; our services sit in the...SeniorFull timeWork experience placementLocal areaRemote workWorldwideFlexible hours$1,000 per month
...exceptional team as our Senior Electrical Engineer! WHO WE ARE We're... ...engineering, construction management, and CQV firm and a leader... ...based on inclusion, where all identities, backgrounds, and... ...Landing Medford with easy access to Cambridge & Boston....SeniorFor contractorsImmediate startWorldwideFlexible hours$113.87k - $165.11k
Northeastern University in Boston is hiring a Senior Identity & Access Manager (IAM) Engineer to oversee the design and implementation of IAM frameworks. The role requires strong expertise in security protocols like SAML and OAuth, along with tools such as Microsoft Active...Senior- The Senior Systems Engineers (SE) serves as the technical authority within a project... ...other engineers, program management, quality, external partners... ...and this position requires access to export-controlled... ...sexual orientation, gender identity or expression, or any other...SeniorFor contractorsWork at officeLocal area
- ...Senior IAM Automation & DevOps Engineer The Senior IAM Automation & DevOps Engineer will design, develop, and automate enterprise identity and access management solutions using an engineering-first approach. The role focuses on identity as code, Zero Trust architecture...Senior
$126.65k - $182.85k
...Real Time Software Engineer–Vehicle Management Systems (Mid Level or Senior) The Boeing Company is looking for several... ...requires ability to obtain program access, for which the U.S. Government... ..., sexual orientation, gender identity, age, physical or mental disability...SeniorPermanent employmentWork experience placementInterim roleCurrently hiringRelocationVisa sponsorshipWork visaRelocation packageFlexible hoursShift work$109.2k - $223.4k
...coordination, service request management, change/process support, and... ...events. ~ Degree in Engineering, Facilities Management, Operations... ...process. If you require accessibility assistance or accommodation... ...sexual orientation, gender identity, disability and protected veterans...SeniorTemporary workWork at officeFlexible hoursNight shift$78.2k - $137.7k
Bank of America is seeking a Senior Privileged Access Management Specialist in Boston to safeguard information systems and enhance security controls... ...This role requires deep expertise in PAM methodologies, identity management, and collaboration with stakeholders to manage...Senior- ...Mac Endpoint Engineer The client is seeking a seasoned Mac Endpoint... ...contribute to the enterprise management and support of macOS devices.... ...the Endpoint Engineering Senior Technologist, supporting broader... ...Experience with cloud-based identity management (Azure AD, Okta)....SeniorFor contractors
$135k - $182.1k
Bank of America is seeking a Senior Identity and Access Management Specialist to oversee access provisioning initiatives within a complex enterprise setting. This role emphasizes securing access to systems while adhering to regulatory standards. Candidates should have over...Senior$124k - $280k
...people in data and analytics engineering focus on leveraging advanced... ...for health systems. As a Senior Manager, you will serve as a strategic... ...sexual orientation, and gender identity); age; disability; genetic... ...to responsibilities such as accessing sensitive company or...SeniorFull timeH1b- Base One Technologies is seeking an Identity Governance Developer for a remote role focusing on SailPoint ISC. The position requires over 8 years of experience with API-first IAM solutions and lifecycle workflows in a large-scale identity environment. Responsibilities...SeniorRemote job
- ...Summary The DevTestOps engineer handles daily requests from the... ...support questions, granting tool access, and customizing Azure DevOps... ...infrastructure issues, manage VMs, explore new AI Tools and... ..., sexual orientation, gender identity, national origin, age, pregnancy...SeniorTemporary workWork at officeLocal areaRemote workWorldwideShift work
$86.5k - $142.7k
...proofs‑of‑concept, and guiding engineering teams through complex... ...engagements in Digital Engineering Managed Services. Your key responsibilities... ...products and platforms. • Access to modern engineering stacks,... ..., sexual orientation, gender identity/expression, pregnancy,...SeniorSummer holidayFlexible hours- ...across configuration, security, device management, and compliance and implement... ...endpoint management tools Manage identity and access systems including Microsoft Entra, Active... ...efficiency Experience in IT, systems engineering, or Microsoft focused roles Strong...SeniorWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Identity Access Management Engineer. Be the first to apply!
Related searches
- senior game producer Boston, MA
- senior manager process engineering Boston, MA
- senior manufacturing engineer Boston, MA
- senior manager clinical operations Boston, MA
- senior lead project manager Boston, MA
- senior manager quality engineering Boston, MA
- senior device engineer Boston, MA
- senior full stack developer Boston, MA
- senior research manager Boston, MA
- senior marketer Boston, MA



