Senior Security Engineer, IAM
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
By continuing, you agree to our Terms & Privacy Policy.
Posting Type
Remote
Job Overview
The Senior IAM Engineer is a technically authoritative leader who sets the direction for the enterprise IAM function and anchors identity as the primary control plane in a defense-in-depth program. This engineer owns the architecture, strategy, and operational maturity of AI-enabled identity technologies across the workforce, customer, and non-human (machine and agent) identity domains. Partnering with the Manager of Enterprise Security and leading cross-functional teams, the role reduces Relativity's identity attack surface, sets the standards others build against, mentors engineers, and elevates the organization's ability to detect and respond to identity-based threats.Job Description and Requirements
Role Responsibilites:
Continuous Adaptive Trust & Identity Architecture
Design identity architecture spanning workforce, machine, and workload identity, mapping layered controls to relevant frameworks as a core tier of defense-in-depth.
Design and advance continuous adaptive trust capabilities (continuous access evaluation (CAE), risk-based and phishing-resistant authentication, and signal-driven session revocation) as the maturation of the enterprise Zero Trust architecture.
Engineer and optimize ZTNA, least-privilege micro-segmentation, MFA/FIDO2, and JIT access across access paths.
Design and optimize SSO, federation, and authentication standards (SAML, OAuth 2.0, OIDC, SCIM, Kerberos, LDAP) across SaaS and multi-cloud environments.
Define and tune hardening standards using CIS Benchmarks/DISA STIGs with automated compliance validation.
Identity Lifecycle, Governance & PAM
Design and optimize identity lifecycle automation (joiner/mover/leaver) integrating HR systems, directories, and downstream applications.
Engineer identity governance and administration (IGA) capabilities: access reviews, certification campaigns, and segregation-of-duties enforcement.
Lead implementation and optimization of privileged access management (PAM) including credential vaulting, JIT elevation, and session monitoring.
Design governance for non-human identities (service accounts, workloads, secrets) with automated drift detection and policy-as-code enforcement.
Detection, Response & Threat Context
Lead integration of identity telemetry into the detection stack (SIEM/SOAR, UEBA) to detect credential abuse, privilege escalation, and lateral movement, reducing MTTD and MTTR.
Develop identity-focused IR playbooks covering