
Senior Security Engineer, Identity & Access Management
Valon Tech4 months ago
Remote, WorldwideSenior
Base Salary
$180k - $230k/yr
Responsibilities
- Design and support the full lifecycle of workforce identity systems, including identity automation, access management, and least-privilege enforcement.
- Develop secure identity design patterns for product teams building on ValonOS.
- Manage and evolve the enterprise IdP, including SSO integrations, MFA policies, conditional access, and directory synchronization.
- Define and enforce RBAC and group-based access policies across internal applications, cloud environments, and development tooling.
- Support privileged access management for internal infrastructure with Engineering teams.
- Build AI-assisted workflows to automate and accelerate IAM operations.
- Evaluate AI risks in IAM pipelines, including data exposure and prompt injection, and implement appropriate controls.
- Collaborate across Product, Engineering, Data, Compliance, and Legal to mitigate data security risks.
- Support vulnerability management, regulatory compliance, policy development, incident response, security reviews, and other operational or on-call duties.
Requirements
- At least 5 years of security engineering experience with a core focus on identity and access management.
- Bachelor’s degree in Information Security, Computer Science, Technology, or a related field.
- Relevant security certification such as CISSP, CISM, CCSK, CCSP, or similar.
- Hands-on experience with an enterprise IdP such as Okta, Entra ID, or Google Workspace, including SSO, MFA, and SCIM.
- Deep expertise in SAML 2.0, OIDC/OAuth 2.0, RBAC, ABAC, and API access controls.
- Experience administering and scaling identity platforms, cloud IAM, service accounts, workload identity federation, policy-as-code, PAM solutions, and identity vaults.
- Experience building AI/LLM-powered workflows and understanding the identity and access risks they introduce.
- Familiarity with non-human and agentic identities, AI service accounts, API key governance, and audit logging for automated systems.
- Applied knowledge of OWASP, NIST, CIS, SOC 2, and ISO 27001 concepts.
- Ability to operate autonomously, own enterprise identity solutions, lead complex cross-functional efforts, and communicate security concepts to technical and non-technical stakeholders.
- Experience in a high-growth or startup environment is preferred.
Benefits
- Remote work is fully supported; offices are located in New York City and San Francisco.
- Base compensation for New York City staff is $180K–$230K, with location-based variation; the salary range excludes equity and other benefits.
- Meaningful company equity and a 401(k) plan are offered.
- Comprehensive medical, dental, and vision benefits are provided.
- Pre-tax commuter benefits cover public transportation, rideshare services, and parking expenses.
- Company orientation, learning and development opportunities, and regular 360-degree feedback review cycles are provided.
- Quarterly budgets support team and company outings.
- Flexible paid time off, sick days, and 11 company holidays are offered.
- Fully paid 12-week bonding leave is available for birthing and non-birthing parents.