Your browser does not support javascript! Please enable it, otherwise web will not work for you.

Staff Security Engineer, IAM

Home > Python programming jobs

Staff Security Engineer, IAM in USA

  • Remote

Responsibilities

  • Design enterprise-scale identity, privileged access, AI access, and non-human identity governance solutions.
  • Replace low-code and iPaaS automation with modular, tested, code-reviewed Python services deployed on GCP Cloud Run or an equivalent serverless runtime.
  • Migrate Okta, Lumos, and non-human identity platform configuration from click-ops to peer-reviewed infrastructure-as-code using Terraform, OpenTofu, or Pulumi.
  • Re-architect identity and access across GCP and AWS organizations, including resource hierarchies, organization policies, SCPs, permission boundaries, and workload identity federation.
  • Lead administration, SSO, SCIM integration, audit logging, data controls, and policy enforcement for enterprise AI platforms.
  • Design monitoring and management for service accounts, API keys, certificates, AI agents, and MCP integrations.
  • Lead cross-functional technical initiatives and translate ambiguous business needs into actionable specifications.
  • Write technical proposals, review designs and code, and mentor senior and intermediate engineers.

Requirements

  • Extensive experience designing and implementing enterprise-scale IAM solutions, including experience at a Staff or senior individual-contributor level.
  • Expertise with Okta Identity Engine, advanced authentication policies, lifecycle workflows, and API automation.
  • Strong Terraform, OpenTofu, or Pulumi experience, including SaaS identity platform providers and migration from click-ops to code.
  • Proficiency writing and shipping modular, tested, code-reviewed Python services with deployment and observability practices.
  • Deep cloud identity experience in GCP and/or AWS, including organization design, IAM policy models, workload identity federation, organization policies, SCPs, and permission boundaries.
  • Hands-on experience administering or governing enterprise AI platforms; Anthropic Claude is preferred, while OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or similar platforms are acceptable.
  • Awareness of AI-specific risks including prompt injection, MCP attack surfaces, agent identity, and data leakage.
  • Practical experience using agentic AI tools such as Claude Code, Cursor, or similar tools in daily engineering work.
  • Experience with IGA platforms such as Lumos, ConductorOne, or similar platforms.
  • Experience in regulated environments and knowledge of FedRAMP, SOC 2, or SOX compliance, including change management, evidence collection, and audit support.
  • Knowledge of AI agent governance, non-human identity management, zero-trust architecture, or behavioral analytics is preferred.
  • Experience completing a cloud organization restructuring, including migration and stakeholder work, is preferred.

Benefits

  • Health, financial, and well-being benefits.
  • Flexible paid time off.
  • Team Member Resource Groups.
  • Equity compensation and an Employee Stock Purchase Plan.
  • Growth and Development Fund.
  • Parental leave.
  • Fully remote work, subject to country and location eligibility requirements.

Salary: $168k - $238k/yr

GitLab

GitLab is a comprehensive AI-powered DevSecOps platform. It helps companies manage the growing complexities of developing, securing, and deploying software. Its platform is used to deliver software faster and more efficiently while strengthening security, end-to-end compliance, and auditability. ...

Similar positions

Senior Software Engineer, ML Ops

  • PathAI
  • Full time
  • USA
  • 09/13/2026
  • Salary: $128k - $196k/yr
  • Boston, MA

Staff Backend Engineer - Submission Processing

  • Kalepa
  • Full time
  • Remote
  • 09/13/2026
  • Salary: $100k-$185k
  • Europe

Senior/Staff Full Stack Engineer

  • Workstream
  • Full time
  • Canada
  • 09/13/2026
  • Salary: Competitive
  • Vancouver

Senior Security Engineer

  • GitLab
  • Full time
  • Remote
  • 09/13/2026
  • Israel, Poland

Partner 20, Staff Security Engineer

  • a16z
  • Full time
  • USA
  • 09/13/2026
  • Salary: $243k - $284k/yr
  • San Francisco, CA