5 months ago
Base Salary
$165k - $242k/yr
Responsibilities
- Design, implement, and operate workforce identity solutions, including SSO, MFA, conditional access, and SCIM-based lifecycle automation.
- Develop and roll out phishing-resistant MFA for high-value accounts and critical access paths.
- Define and maintain RBAC/IAM patterns, role models, groups, entitlements, JIT access, and approvals for enterprise applications.
- Design and deploy zero-trust controls using user identity, device posture, network context, and application sensitivity.
- Integrate mTLS, service identity, and policy-based access into internal services and administrative interfaces.
- Help transition employees, contractors, and third parties from legacy perimeter models to ZTNA patterns.
- Evaluate, onboard, and harden SaaS and collaboration platforms against enterprise security policies.
- Implement SCIM provisioning, data access policies, DLP, sharing controls, and audit logging across the SaaS estate.
- Define and enforce baseline configurations for managed laptops, workstations, and other devices through MDM and EDR.
- Design secure contractor and vendor access patterns with device requirements, identity separation, and time-bound access.
- Support identity, endpoint, and SaaS investigations and incident response.
- Build automation and self-service workflows for access requests, approvals, access reviews, and break-glass processes.
- Develop integrations among identity providers, HRIS, ticketing, and other systems to reduce manual effort and identity-related errors.
- Define and instrument metrics such as MFA coverage, zero-trust policy enforcement, joiner/mover/leaver SLA adherence, and SaaS posture.
- Partner with Security Operations and SIEM teams on visibility and high-signal identity, device, and SaaS detections.
- Contribute to policies, standards, reference architectures, documentation, and operational runbooks.
Requirements
- At least 5 years of experience in enterprise security, identity and access management, or closely related security engineering roles.
- Strong practical knowledge of SSO, federation, RBAC/ABAC, JIT access, least privilege, and separation of duties.
- Hands-on experience implementing and operating workforce identity platforms such as Okta or Entra ID.
- Deep familiarity with SAML, OAuth 2.0/OIDC, and SCIM integrations.
- Experience designing and deploying MFA, preferably phishing-resistant methods such as FIDO2/WebAuthn, hardware security keys, device-bound authenticators, and step-up authentication.
- Experience designing and deploying zero-trust or context-aware access controls, including device trust, network segmentation, mTLS, or ZTNA.
- Proficiency in at least one modern scripting or programming language, such as Python or Go.
- Experience securing and integrating business-critical SaaS applications, including SCIM provisioning, access reviews, and audit log ingestion.
- Familiarity with MDM and endpoint security tooling, including Jamf, Intune, and EDR platforms.
- Exposure to SIEM and detection ecosystems such as Elastic, plus collaboration with detection and response teams.
- Track record of owning cross-functional projects from design through adoption with measurable risk reduction and user experience considerations.
- Preferred experience in high-growth or hyperscale environments.
- Preferred experience with ZTNA, secure web gateways, or identity-aware proxies.
- Preferred familiarity with SOC 2, ISO 27001, NIST 800-53, SSPM, CASB, DLP, insider-risk tooling, and internal security tooling.
- Security community, standards group, or open-source participation in IAM, zero trust, or enterprise security is preferred.
Benefits
- Medical, dental, and vision insurance fully paid by CoreWeave
- Company-paid life insurance, with voluntary supplemental life insurance
- Short- and long-term disability insurance
- Flexible Spending Account and Health Savings Account
- Tuition reimbursement
- Employee Stock Purchase Program participation
- Mental wellness benefits through Spring Health
- Family-forming support through Carrot
- Paid parental leave
- Flexible childcare support through Kinside
- 401(k) with employer match
- Flexible PTO
- Catered lunch at office and data center locations
- Hybrid work environment prioritized; remote work may be considered for candidates more than 30 miles from an office
- Onboarding at a company hub within the first month and quarterly team gatherings
About CoreWeave
CoreWeave provides a GPU-accelerated cloud for AI training and inference, VFX, and rendering, with bare-metal instances, Kubernetes orchestration, and managed services to scale workloads. It sells on-demand and reserved capacity to AI labs, startups, and enterprises, and offers SaaS tools and hands-on support for deployment. Founded in 2017 and headquartered in New York, it is publicly traded on Nasdaq under the ticker CRWV.
