Staff Security Engineer, IAM

Posted 3 hours ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Staff Security Engineer securing identity, cloud access, and AI platforms for GitLab’s DevSecOps platform. Engineering automated governance across Okta, GCP, AWS, and non-human identities.

Responsibilities

  • Design comprehensive identity and AI access solutions, including AI agent governance frameworks and privileged access workflows with just-in-time provisioning
  • Replace low-code automation with engineered Python services on GCP Cloud Run with source control, tests, CI, and observability
  • Codify Okta, Lumos, and non-human identity platforms in Terraform/OpenTofu/Pulumi and migrate click-ops to peer-reviewed infrastructure-as-code
  • Re-architect identity and access across GCP and AWS organizations, including resource hierarchy, secure-by-default guardrails, workload identity federation, and least-privilege access
  • Lead identity and access engineering for enterprise AI platforms, including administration, SSO and SCIM integration, audit logging, data controls, and policy enforcement
  • Design monitoring and management solutions for service accounts, API keys, certificates, AI agents, and MCP integrations; deploy and operationalize the NHI platform
  • Drive cross-functional initiatives with Security, IT, Engineering, Enterprise AI, and the Office of the CIO
  • Mentor senior and intermediate engineers on technical implementation and strategic thinking

Requirements

  • Extensive IAM experience designing and implementing enterprise-scale solutions, with demonstrated time at a Staff or senior IC level
  • Expert-level Okta expertise including Identity Engine, advanced authentication policies, lifecycle workflows, and API automation
  • Strong infrastructure-as-code practice with Terraform/OpenTofu/Pulumi, including provider experience for SaaS identity platforms and a track record of migrating click-ops to code
  • Proficiency writing and shipping Python as a software engineer, designed as modular, tested, code-reviewed, deployed as services (GCP Cloud Run or equivalent serverless runtime) and instrumented for failure
  • Cloud identity depth in GCP and/or AWS, including resource hierarchy and organization design, IAM policy models, workload identity federation, and preventive controls such as org policies, SCPs, and permission boundaries
  • Hands-on experience administering or governing enterprise AI platforms (Anthropic Claude preferred; OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or similar acceptable)
  • Awareness of AI-specific risks including prompt injection, MCP attack surface, agent identity, and data leakage
  • Daily engineering practice with AI tooling such as Claude Code, Cursor, or similar
  • Experience with IGA platforms like Lumos, ConductorOne, or similar, with a preference for managing them declaratively
  • Experience in regulated environments with knowledge of compliance frameworks (FedRAMP, SOC2, SOX), including change management, evidence collection, and audit support
  • Passion for emerging identity challenges including AI agent governance, non-human identity management, zero-trust architecture, and behavioral analytics
  • Experience carrying a cloud org restructuring through to completion, including migration and stakeholder work

Benefits

  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

Job type

Full Time

Experience level

Lead

Salary

$168,000 - $238,000 per year

Degree requirement

No Education Requirement

Tech skills

AWSCloudGoogle Cloud PlatformPythonTerraform

Location requirements

RemoteUnited States

Report this job

Found something wrong with the page? Please let us know by submitting a report below.