Senior Security Engineer, IAM
Listed on 2026-10-02
-
IT/Tech
Cybersecurity, Systems Engineer
_ Posting Type _
Remote
_ Job Overview _The Senior IAM Engineer is a technically authoritative leader who sets the direction for the enterprise IAM function and anchors identity as the primary control plane in a defense-in-depth program. This engineer owns the architecture, strategy, and operational maturity of AI-enabled identity technologies across the workforce, customer, and non-human (machine and agent) identity domains. Partnering with the Manager of Enterprise Security and leading cross-functional teams, the role reduces Relativity’s identity attack surface, sets the standards others build against, mentors engineers, and elevates the organization’s ability to detect and respond to identity-based threats.
_Job Description and Requirements _Role Responsibilites:
Continuous Adaptive Trust & Identity Architecture
Design identity architecture spanning workforce, machine, and workload identity, mapping layered controls to relevant frameworks as a core tier of defense-in-depth.
Design and advance continuous adaptive trust capabilities (continuous access evaluation (CAE), risk-based and phishing-resistant authentication, and signal-driven session revocation) as the maturation of the enterprise Zero Trust architecture.
Engineer and optimize ZTNA, least-privilege micro-segmentation, MFA/FIDO2, and JIT access across access paths.
Design and optimize SSO, federation, and authentication standards (SAML, OAuth 2.0, OIDC, SCIM, Kerberos, LDAP) across SaaS and multi-cloud environments.
Define and tune hardening standards using CIS Benchmarks/DISA STIGs with automated compliance validation.
Design and optimize identity lifecycle automation (joiner/mover/leaver) integrating HR systems, directories, and downstream applications.
Engineer identity governance and administration (IGA) capabilities: access reviews, certification campaigns, and segregation-of-duties enforcement.
Lead implementation and optimization of privileged access management (PAM) including credential vaulting, JIT elevation, and session monitoring.
Design governance for non-human identities (service accounts, workloads, secrets) with automated drift detection and policy-as-code enforcement.
Lead integration of identity telemetry into the detection stack (SIEM/SOAR, UEBA) to detect credential abuse, privilege escalation, and lateral movement, reducing MTTD and MTTR.
Develop identity-focused IR playbooks covering account takeover, credential compromise, federation abuse, and session hijacking.
Apply threat intelligence context to prioritize identity exposure remediation and lead identity-focused purple team engagements.
Design identity controls embedded in AI-augmented CI/CD pipelines (secret scanning, IaC identity policy, workload identity) with AI-generated fix recommendations surfaced in PR workflows.
Define and track identity KPIs: privileged access coverage, certification completion, authentication anomaly rates, and entitlement drift.
Partner with GRC on identity controls aligned to SOX, SOC 2, ISO 27001, HIPAA, GDPR, and CCPA, and support audits, certifications, e-discovery, and forensic integrity requirements.
Provide technical guidance and mentorship to Advanced and Engineer-level identity engineers.
Bachelor’s in Computer Science, Information Security, or equivalent experience.
8+ years of hands‑on experience in enterprise IAM or security engineering, with deep specialization in identity, authentication, and access domains, or a Master’s degree in Cybersecurity or a relevant field with 6+ years of experience.
Expert, hands‑on experience architecting and operating identity platforms across IdP/SSO (Okta, Entra /Azure…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).