HackerOne

Senior Security Engineer, Identity and Access Management

HackerOne
Apply
4 days ago
Washington, DC, USA or Seattle, WA, USASenior

Base Salary

$180k - $220k/yr

Responsibilities

  • Own the identity lifecycle for people, service accounts, workload identities, integrations, and AI agents from onboarding through removal.
  • Design access models based on data classification and implement least-privilege, time-bound access controls.
  • Build and maintain identity-as-code, entitlement policies, provisioning logic, and access-review rules across Okta, Lumos, and AWS IAM.
  • Develop AI- and LLM-powered tooling for continuous access reviews and entitlement anomaly detection.
  • Assign ownership, purpose, and expiration to non-human identities and automate their governance.
  • Measure unnecessary entitlements and prioritize opportunities to reduce access.
  • Partner with Engineering, Enterprise IT, and Compliance to embed identity controls into their systems.
  • Support identity-focused detection and incident response, including access containment and reconstruction of identity activity.

Requirements

  • 5+ years of experience in identity and access management, security engineering, or software engineering with substantial ownership of identity systems.
  • Hands-on experience operating an enterprise identity provider such as Okta, including SAML, OIDC, SCIM, and lifecycle automation.
  • Experience managing identity across enterprise SaaS systems such as Google Workspace, Salesforce, and Workday, including SCIM provisioning and group-driven entitlements.
  • Experience with cloud IAM, ideally AWS, including policy design and short-lived credentials.
  • Strong software engineering fundamentals with proficiency in Python, Go, or a similar language.
  • Hands-on use of AI, LLM, and agentic coding tools in production engineering work.
  • Preferred experience includes regulated-sector identity work, audit evidence for PCI DSS, HIPAA, SOC 2, or ISO 27001, infrastructure-as-code, Terraform, Lumos, MDM, Kandji, secrets management, service-to-service authentication, identity incident response, and security certifications such as IDPro CIDPRO, Okta certifications, AWS Certified Security – Specialty, or CISSP.

Benefits

  • Remote work with the role targeted to candidates near Austin, Seattle, Washington DC, San Francisco, Boston, London, or Netherlands locations, with occasional in-person collaboration.
  • Health, medical, vision, dental, life, and disability insurance, subject to eligibility.
  • Equity stock options.
  • Retirement plans.
  • Paid public holidays and unlimited PTO.
  • Paid maternity and parental leave and other leaves of absence, including caregiver leave.
  • Employee Assistance Program.

Categories

HackerOne

About HackerOne

5,001-10,000 employees

HackerOne builds a platform for offensive security, combining a global community of security researchers with tools for bug bounties, vulnerability disclosure, pentesting, and AI red teaming. Enterprises use it to continuously find and remediate vulnerabilities across code and cloud via subscription software and managed programs. Founded in 2012 and headquartered in San Francisco, customers include the U.S. Department of Defense, General Motors, Goldman Sachs, Uber, and the UK Ministry of Defence.

Contact me