13 hours ago
Los Angeles, CA, USAEntry Level / Mid Level
Base Salary
$120k - $150k/yr
Responsibilities
- Administer the enterprise identity platform, including identity provider, single sign-on, and directory services across corporate, engineering, and mission environments.
- Onboard SaaS and internal applications to SSO and automated provisioning using SAML, OIDC, and SCIM while retiring local accounts and shared credentials.
- Operate and improve identity lifecycle workflows, including joiner, mover, leaver, provisioning, deprovisioning, and access requests.
- Support phishing-resistant MFA adoption using FIDO2/WebAuthn and assist users with enrollment and rollout.
- Maintain role-based access groups and entitlements under least-privilege standards.
- Support privileged access management for administrator accounts, service accounts, and break-glass credentials.
- Improve secrets management hygiene through credential rotation for non-human accounts used by automated pipelines.
- Implement and monitor conditional access policies and escalate anomalous authentication patterns.
- Execute access review and certification campaigns and collect audit and customer evidence.
- Write scripts and contribute to infrastructure as code to automate identity operations.
- Triage identity-related tickets and incidents and support investigations involving credential abuse or MFA fatigue attacks.
- Maintain identity documentation, runbooks, and standards.
Requirements
- 1–3 years of experience in identity and access management, security engineering, IT systems administration, or a related technical role; internships and co-ops count.
- Hands-on experience with an enterprise identity provider such as Okta, Microsoft Entra ID, Ping, or Google Identity, including SSO, MFA, and user or group administration.
- Foundational understanding of SAML, OIDC, OAuth 2.0, SCIM, and LDAP.
- Familiarity with least-privilege and role-based access concepts.
- Scripting experience with a modern language such as Python, PowerShell, or Go for automation or system integration.
- Exposure to AWS, Azure, or GCP and its IAM model.
- Bachelor’s degree in cybersecurity, computer science, information systems, engineering, or another STEM discipline, or equivalent hands-on experience.
- Entry-level security or identity certifications such as CompTIA Security+, Okta Certified Professional or Administrator, or Microsoft SC-300 are preferred.
- Experience with Terraform, CloudFormation, CDK, HashiCorp Vault, cloud-native secret stores, Active Directory, Kerberos, hybrid identity environments, ITDR, or SIEM tooling is preferred.
- Personal projects, home labs, CTF participation, or prior defense, aerospace, or ITAR-regulated experience are valued.
Benefits
- Base salary is $120,000–$150,000 plus company equity.
- Benefits include paid time off, medical, dental and vision coverage, life insurance, paid parental leave, and other perks.
About K2 Space
Founded in 2004, K2 Space offers bespoke office design and build services to clients, while also working closely with clients to fulfil all of their furniture needs. Our passionate team are proud to work with leading brands like Netflix, Snapchat, Adobe, Toyota, Beats, Latham & Watkins, Groupon and Wells Fargo to create amazing new workplace. Check out our website to view our latest work | https://k2space.co.uk