Security Engineer, IAM
Listed on 2026-09-07
-
IT/Tech
Cybersecurity
Security Engineer,IAM
Title:
Security Engineer,IAM
Level:IC-2
Location:
Los Angeles,CA
Worksetup:
In-office(4daysaweek)
Department:
IT
Company
Talent Systems,LLCistheleadingtechnologysolutionproviderforcastingandauditioningtotheentertainmentindustry.
Castingdirectorsandagentsworldwideuse Talent Systems ’portfolioofproductstosourceandmanagetalentacrossfilm,television,commercials,theateranddigitalprojects,poweringanunparalleled,globalcastingsoftwareecosystem.
Weareheadquarteredin Los Angelesandoperateinthe US,Canada,UK,Australia and India.
Ourportfoliobrandsinclude Casting Networks ,Spotlight,Cast It Systems ,Cast It Talent ,Casting Frontier,Staff Me Up ,Cast It Reach &Tagmin.
The Security Engineer, IAM will design, implement, and manage Identity and Access Management systems across Talent Systems' global technology stack. This role sits within the Corporate IT team and is critical to ensuring that the right people have the right access to the right resources and that unauthorized access is proactively detected and prevented. You will work cross-functionally with Engineering, Product, Security, and HR teams to build scalable, secure, and compliance-aligned identity infrastructure that supports our global platforms and workforce.
IAMArchitecture & Engineering
- Design,deploy,andmaintainIAMsolutionsincludingSSO,MFA,RBAC,andPAMacrosscloudandon-premise environments
- ArchitectandmanageidentityfederationusingprotocolssuchasSAML,OAuth
2.0,andOpenIDConnect - Buildandmaintainlifecyclemanagementprocessesforuserprovisioning,de-provisioning,andaccessreviews
- IntegrateIAMsystemswith Saa Splat forms (Google Workspace,Slack,Git Hub,Zendesk,andothers) andinternalapplications
- Developandmaintainautomationforaccessrequestworkflowsandentitlementmanagement
- Conductperiodicaccessreviewsandcertificationcampaignstoensureleast-privilegeprinciplesareenforced
- MonitorIAMsystemsforanomalousactivity,access violations,andpolicydrift;respondtoandremediateincidents
- SupportauditandcomplianceactivitiesrelatedtoSOC2,PCI-DSS,GDPR,andotherapplicableframeworks
- DefineandenforceIAMpolicies,standards,andproceduresinalignmentwithindustrybestpractices
- Collaboratewiththe Information Security Officetoevaluateandcloseidentity -related vulnerabilities
- Partner with Engineering and Dev Opsteamstoembed IAMcontrolsintoCI/CDpipelinesandcloudinfrastructure
- WorkwithITTeamtoalignidentityprocesseswithendpointandnetworksecuritypolicies
- Support onboarding,offboarding,androle-changeworkflowsincoordinationwith
People Operations - Participate in cross-functional planning to surface IAM-related risks, roadmap items, and quarterly priorities
- 4+yearsofhands-onexperienceinIAMengineering,identity security,oracloselyrelatedfield
- ProficiencywithIAMprotocols:
SAML,OAuth
2.0,OpenIDConnect,LDAP,SCIM - Experienceadministeringanenterpriseidentityprovider(e.g.,Okta,AzureAD/EntraID,Google Workspace Identity ,or equivalent)
- SolidunderstandingofRBAC,least-privilege,andzero-trust principles
- FamiliaritywithcomplianceframeworksincludingSOC2
TypeII,GDPR,andISO
27001 - Excellentwrittenandverbalcommunicationskills;abletoexplaincomplexidentityconceptstonon-technical stakeholders
- Preferred:
Experience with Privileged Access Management (PAM) tools(e.g.,Cyber Ark,Beyond Trust,Hashi Corp Vault ) - Preferred:
DemonstratedabilitytoscriptandautomateIAMworkflowsusing
Python,Power Shell,Bash,orsimilar - Preferred:
Hands-onexperiencewithcloudIAM(AWSIAM,GCPIAM,orAzureRBAC) - Preferred:
Background in Saa Sormulti -tenantplatformenvironmentswithcomplexuserhierarchymanagement - Preferred:
Exposuretoentertainment,media,ormarketplaceplatformsecurity - Preferred:
Experience working in a globally distributed team across multiple time zones
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).