Staff Security Engineer, IAM
New
G
GitLabDevSecOps
Remote, Canada; Remote, United StatesFull-TimeStaff
Salary168,000 - 238,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Required Skills
- AWSPythonGCPTerraformCompliance
Requirements
- Extensive IAM experience at a Staff or senior IC level.
- Expert-level Okta expertise including Identity Engine and lifecycle workflows.
- Strong infrastructure-as-code practice with Terraform, OpenTofu, or Pulumi.
- Proficiency writing and shipping modular, tested Python code deployed as services.
- Cloud identity depth in GCP and/or AWS (resource hierarchy, workload identity federation, IAM policies).
- Hands-on experience administering or governing enterprise AI platforms.
- Experience building with AI tooling such as Claude Code or Cursor.
- Experience with IGA platforms like Lumos or ConductorOne.
- Knowledge of compliance frameworks such as FedRAMP, SOC2, or SOX.
Responsibilities
- Design comprehensive identity and AI access solutions that scale, including governance frameworks and just-in-time provisioning.
- Migrate existing iPaaS automation to engineered Python services running on GCP Cloud Run.
- Codify identity platforms such as Okta and Lumos using Terraform, OpenTofu, or Pulumi.
- Re-architect identity and access across GCP and AWS, implementing workload identity federation and least-privilege models.
- Lead identity and access engineering for enterprise AI platforms, including SSO, SCIM, and policy enforcement.
- Pioneer non-human identity (NHI) governance by designing monitoring and management solutions for API keys, AI agents, and service accounts.
- Mentor senior and intermediate engineers on technical implementation and strategic security practices.
View Full Description & ApplyYou'll be redirected to the employer's site