Senior Security Engineer, Identity and Access Management (IAM)
K2 Space Corporation - Los Angeles, CA
Hiring: Senior Security Engineer, Identity and Access Management (IAM) Company: K2 Space Corporation Location: Los Angeles, CA Job Posted Time: 2026-09-09 23:13:17 Target Skills & Keywords : ABAC, AWS, Azure, C, C++, CDK, CloudFormation, Compliance, Consul, GCP, IAM, Infrastructure as Code, Move, OAuth2, OIDC, Okta, Python, R, RBAC, REST, Rocket, Rust, SAML, SaaS, Segment, Terraform, Vault, Webhooks About the job Experience: •5+ years of experience in identity and access management, security engineering, or infrastructure engineering, preferably in a fast-paced startup or technology environment Required Skills: •Own and mature the enterprise identity platform, including the identity provider, single sign-on, federation, and directory services across corporate, engineering, and mission environments •Design and implement authentication standards using modern protocols such as SAML, OIDC, OAuth 2.0, and SCIM, and drive adoption of phishing-resistant MFA including FIDO2 and WebAuthn •Build and automate identity lifecycle management, including joiner, mover, and leaver workflows, provisioning and deprovisioning, and just-in-time access •Design and maintain role-based and attribute-based access models, entitlement structures, and least-privilege standards for corporate and engineering systems •Implement and operate privileged access management for administrators, service accounts, and break-glass credentials •Manage machine and workload identity, including secrets management, credential rotation, and the non-human accounts used by automated pipelines and mission systems •Onboard SaaS and internal applications to SSO and automated provisioning using SCIM, REST APIs, and webhooks, retiring local accounts and shared credentials as you go •Implement conditional access and risk-based authentication policies, then tune them against real access patterns Qualifications: •5+ years of experience in identity and access management, security engineering, or infrastructure engineering, preferably in a fast-paced startup or technology environment •Hands-on experience administering an enterprise identity provider (e.g., Okta, Microsoft Entra ID, Ping, or Google Identity), including SSO, MFA, and conditional access •Strong working knowledge of identity protocols and standards, including SAML, OIDC, OAuth 2.0, SCIM, LDAP, and Kerberos •Experience designing and implementing identity lifecycle automation, RBAC or ABAC access models, and access review processes •Practical experience utilizing privileged access management and secrets management for both human and machine identities, such as HashiCorp Vault or equivalent •Practical experience utilizing cloud IAM in AWS, Azure, or GCP, including least-privilege role and policy design •2+ years of development experience with any modern programming language (including but not limited to Python, Go, C++, Rust) used to automate identity workflows and integrations, in lieu of a degree; OR a bachelor’s degree in security engineering, cyber security, computer science, engineering, math, or other STEM discipline •Comfortable working with mission critical and sensitive systems, with a sense of urgency appropriate with responsibilities •Due to the high visibility of this position, excellent interpersonal skills, attention to detail, and problem-solving skills •Bachelor’s degree (or equivalent) in computer science or engineering Compensation: •$150,000 - $220,000 / year •Competitive benefits and rewards package •Comprehensive benefits package including paid time off, medical/dental/vision coverage, life insurance, paid parental leave, and many other perks Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!