Senior Security Engineer, IAM

5 days ago

houston, texas, United States Relativity Full-time

Posting Type

Remote

Job Overview

The Senior IAM Engineer is a technically authoritative leader who sets the direction for the enterprise IAM function and anchors identity as the primary control plane in a defense-in-depth program. This engineer owns the architecture, strategy, and operational maturity of AI-enabled identity technologies across the workforce, customer, and non-human (machine and agent) identity domains. Partnering with the Manager of Enterprise Security and leading cross-functional teams, the role reduces Relativity's identity attack surface, sets the standards others build against, mentors engineers, and elevates the organization's ability to detect and respond to identity-based threats.

Job Description and Requirements

Role Responsibilites:

Continuous Adaptive Trust & Identity Architecture

  • Design identity architecture spanning workforce, machine, and workload identity, mapping layered controls to relevant frameworks as a core tier of defense-in-depth.

  • Design and advance continuous adaptive trust capabilities (continuous access evaluation (CAE), risk-based and phishing-resistant authentication, and signal-driven session revocation) as the maturation of the enterprise Zero Trust architecture.

  • Engineer and optimize ZTNA, least-privilege micro-segmentation, MFA/FIDO2, and JIT access across access paths.

  • Design and optimize SSO, federation, and authentication standards (SAML, OAuth 2.0, OIDC, SCIM, Kerberos, LDAP) across SaaS and multi-cloud environments.

  • Define and tune hardening standards using CIS Benchmarks/DISA STIGs with automated compliance validation.

Identity Lifecycle, Governance & PAM

  • Design and optimize identity lifecycle automation (joiner/mover/leaver) integrating HR systems, directories, and downstream applications.

  • Engineer identity governance and administration (IGA) capabilities: access reviews, certification campaigns, and segregation-of-duties enforcement.

  • Lead implementation and optimization of privileged access management (PAM) including credential vaulting, JIT elevation, and session monitoring.

  • Design governance for non-human identities (service accounts, workloads, secrets) with automated drift detection and policy-as-code enforcement.

Detection, Response & Threat Context

  • Lead integration of identity telemetry into the detection stack (SIEM/SOAR, UEBA) to detect credential abuse, privilege escalation, and lateral movement, reducing MTTD and MTTR.

  • Develop identity-focused IR playbooks covering