Staff Security Engineer - IAM

Aledade - Austin, TX

Hiring: Staff Security Engineer - IAM Company: Aledade Location: Austin, TX Job Posted Time: 2026-09-03 10:44:41 Employment Type: Remote Target Skills & Keywords : ABAC, AWS, Azure, C#, C++, CI/CD, Cloud Native, CloudFormation, Electronic Health Records, GCP, HIPAA, IAM, IaC, Infrastructure as Code, Java, Machine Learning, Microservices, OAuth, OIDC, PowerShell, Python, RBAC, SAML, SIEM, SOC 2, Scala, Terraform, VPC About the job Experience: •AI Identity & Access Management •NHI Architecture: Design secure, scalable, and automated solutions for managing service accounts, machine identities, secrets, certificates, APIs, and cloud-native workloads. •AI/ML Security & Threat Modeling: Hands-on experience with AI/ML tools (e.g., Gemini, Claude, AWS Bedrock), conducting threat modeling for AI systems, or managing automated permission guardrails for AI agents. •Advanced Protocols & Microservice Security: Familiarity with SPIFFE/SPIRE, zero-trust network architectures, or complex containerized identity frameworks. •SIEM & Security Observability Tools: Experience orchestrating VPC flow logs and audit feeds into security analytics tools (e.g., Crowdstrike, Sumo Logic, Wiz, Zscaler). Required Skills: •Lead the development, implementation, and ongoing maintenance of comprehensive security strategies and solutions. •Design and deploy advanced identity security controls to safeguards networks, systems, and applications. •Work across disciplines to shape our security services strategy and execution •Set and uphold the standard for security processes to support high-quality engineering •Mentor and galvanize new engineers to do their best work Qualifications: •BS/BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field •8+ years of experience in software or security engineering within Cloud Native environments •Cloud IAM Architecture: Deep knowledge of cloud security architectures (AWS IAM, Azure Entra ID, or GCP IAM), including designing/enforcing least-privilege roles, RBAC/ABAC, and permission policies. •Identity Protocols & Governance: Proficiency in identity standards and federation protocols (SAML, OIDC, OAuth, LDAP/Directory Services), user lifecycle automation, SSO, MFA, and Just-In-Time (JIT) access. •Automation & IaC: Strong hands-on proficiency with Infrastructure as Code (Terraform or CloudFormation) and scripting (Python or PowerShell) to automate identity provisioning, drift detection, and access workflows. •Non-Human Identity (NHI) Fundamentals: Practical experience managing service accounts, API keys, bots, and automated workload identities across cloud infrastructure. •Operational familiarity with server-side web technologies (eg: Java, Python, Scala, C#, C++, Go) •4+ years of experience acting as a trusted technical decision-maker in a team setting, solving for short-term and long-term business value •Sitting for prolonged periods of time. Extensive use of computers and keyboard. Occasional walking and lifting may be required. •Certifications: CISSP, OSCP, CEH, Certified AI Security Specialist (CAISS), or GIAC Machine Learning Security Engineer (GMSE). Compensation: •Flexible work environment (work from home / hybrid options) •Competitive benefits and rewards package •Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!