FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Tech Stack
Tools & technologiesAWSCloudPythonTerraformGo
About the role
Key responsibilities & impact- Own the identity lifecycle end to end for people, service accounts, and AI agents
- Build automation that grants entitlements based on legitimate need and removes them automatically
- Design and build access models based on data classification
- Make time-bound access the default for critical data
- Engineer identity as code with provisioning logic, entitlement policy, and access review rules under version control and testing across Okta, Lumos, and AWS IAM
- Build AI and LLM-powered tooling for continuous access review and entitlement anomaly detection
- Establish ownership, purpose, and expiry for service accounts, workload identities, integrations, and AI agents
- Measure access and report opportunities to reduce unnecessary entitlements
- Partner with Engineering, Enterprise IT, and Compliance to embed identity controls
- Support identity-focused detection and incident response, including access containment, identity access reconstruction, and blameless retrospectives
Requirements
What you’ll need- 5+ years of experience in identity and access management, security engineering, or software engineering with substantial ownership of identity systems
- Hands-on experience operating an enterprise identity provider such as Okta, including SAML, OIDC, SCIM, and lifecycle automation
- Experience managing identity across an enterprise SaaS estate such as Google Workspace, Salesforce and Workday, including SCIM provisioning and group-driven entitlements
- Experience with cloud IAM, ideally AWS, including policy design and short-lived credentials
- Strong software engineering fundamentals with proficiency in Python, Go, or a similar language
- Hands-on use of AI and LLM tooling and agentic coding tools in production engineering work
- Preferred: identity work in a regulated sector and producing access control evidence for PCI DSS, HIPAA, SOC 2, or ISO 27001 audits
- Preferred: identity infrastructure as code and access request or governance tooling such as Terraform and Lumos
- Preferred: mobile device management alongside identity, such as Kandji integrated with Okta
- Preferred: non-human, workload, and privileged access, including secrets management and service-to-service authentication
- Preferred: building AI or LLM-powered tooling for security or identity workflows
- Preferred: detection and incident response for identity-centered incidents
- Industry certification in identity or security is preferred, such as IDPro CIDPRO, Okta certifications, AWS Certified Security – Specialty, or CISSP
- Candidates must be located within approximately 50 miles of Austin, Seattle, Washington, DC, San Francisco, or Boston, or within commuting distance of the London or Netherlands locations
- Visa/work permit sponsorship is not available
- Employment is contingent on a background check
Benefits
Comp & perks- Health (medical, vision, dental), life, and disability insurance
- Equity stock options
- Retirement plans
- Paid public holidays and unlimited PTO
- Paid maternity and parental leave
- Leaves of absence, including caregiver leave and leave under CO's Healthy Families and Workplaces Act
- Employee Assistance Program
