K2 Space

Senior Security Engineer, Identity and Access Management (IAM)

K2 Space
Apply
5 hours ago

Base Salary

$150k - $220k/yr

Responsibilities

  • Own and mature the enterprise identity platform, including identity providers, SSO, federation, and directory services.
  • Implement authentication standards including SAML, OIDC, OAuth 2.0, SCIM, FIDO2, and WebAuthn, along with phishing-resistant MFA.
  • Build identity lifecycle automation for joiner, mover, leaver, provisioning, deprovisioning, and just-in-time access workflows.
  • Design and maintain RBAC and ABAC access models, entitlement structures, and least-privilege standards.
  • Implement and operate privileged access management and secrets management for administrators, service accounts, and machine identities.
  • Manage workload identities, credential rotation, automated pipeline accounts, and mission-system identities.
  • Onboard SaaS and internal applications to SSO and automated provisioning using SCIM, REST APIs, and webhooks.
  • Implement conditional access and risk-based authentication policies and tune them against access patterns.
  • Build access review and certification campaigns and produce audit and customer evidence.
  • Harden cloud IAM across AWS, Azure, and GCP, including roles, trust policies, and permission boundaries.
  • Write code and infrastructure as code to automate identity operations.
  • Partner with security operations on identity threat detection, response, and investigations.
  • Serve as the identity subject matter expert in architecture and design reviews and liaise with engineering.
  • Maintain identity documentation, runbooks, and standards and mentor junior team members.

Requirements

  • 5+ years of experience in identity and access management, security engineering, or infrastructure engineering.
  • Hands-on administration of an enterprise identity provider such as Okta, Microsoft Entra ID, Ping, or Google Identity, including SSO, MFA, and conditional access.
  • Strong knowledge of SAML, OIDC, OAuth 2.0, SCIM, LDAP, and Kerberos.
  • Experience designing identity lifecycle automation, RBAC or ABAC models, and access review processes.
  • Experience with privileged access management and secrets management for human and machine identities, such as HashiCorp Vault.
  • Experience with cloud IAM in AWS, Azure, or GCP and least-privilege role and policy design.
  • At least 2 years of development experience in a modern programming language, including Python, Go, C++, or Rust, in lieu of a degree; alternatively, a bachelor’s degree in security engineering, cybersecurity, computer science, engineering, math, or another STEM discipline.
  • Ability to work with mission-critical and sensitive systems and demonstrate strong interpersonal, attention-to-detail, and problem-solving skills.
  • Preferred qualifications include a bachelor’s degree or equivalent, identity certifications such as Okta Certified Administrator, Microsoft SC-300, or CISSP, and experience with Terraform, CloudFormation, CDK, OPA, or Cedar.
  • Preferred experience includes ITDR, identity-focused detections, Active Directory modernization, engineering or mission environments, and defense, aerospace, or ITAR-regulated organizations.

Benefits

  • Base salary range is $150,000–$220,000 plus company equity.
  • Comprehensive benefits include paid time off, medical, dental, and vision coverage, life insurance, and paid parental leave.
  • The role requires eligibility as a U.S. Person under ITAR or eligibility for a federally issued export control license.
K2 Space

About K2 Space

11-50 employees

Founded in 2004, K2 Space offers bespoke office design and build services to clients, while also working closely with clients to fulfil all of their furniture needs. Our passionate team are proud to work with leading brands like Netflix, Snapchat, Adobe, Toyota, Beats, Latham & Watkins, Groupon and Wells Fargo to create amazing new workplace. Check out our website to view our latest work | https://k2space.co.uk