Principal Security Engineer – Identity & Access

dLocal

São Paulo

Presencial

BRL 300 000 - 420 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Vantagens oferecidas por esta oferta de emprego

Flexible schedules
Fintech environment
Referral bonus
Social budget
dLocal Houses

Resumo da oferta

dLocal is seeking a Principal Security Engineer - Identity & Access to shape a modern, automated identity program. You will own the governance framework, scale JML and SoD, and build an enterprise IGA stack that works across cloud, SaaS, and on‑prem environments.

You will drive federation, Zero Trust, RBAC/ABAC, and design secure, scalable integrations. The role includes M&A identity work, mentoring engineers, and codifying governance into executable policy while keeping velocity and usability

Qualificações

  • Proven track record designing, building, or scaling Identity and Access programs in fast-paced, complex environments.
  • Deep expertise with modern workforce identity systems and lifecycle processes (JML, SoD, Certifications).
  • Hands-on experience with protocols: SAML, OIDC, OAuth2, SCIM.
  • Ability to translate governance policies into code and automate identity workflows.
  • Strong mentoring, leadership, and documentation skills.

Responsabilidades

  • Engineer the Identity Lifecycle (JML & SoD) with automated certifications.
  • Lead federation, Zero Trust, and integration across cloud, SaaS, and on-prem.
  • Drive identity integration for M&A and large enterprise transformations.
  • Execute with hands-on approach, configuring integrations and RBAC policies.
  • Codify governance with self-service workflows and identity KPIs.
  • Be the IAM diplomat, negotiating with engineers while maintaining security.

Conhecimentos

IGA
JML
SoD
RBAC
ABAC
SAML
OIDC
OAuth2
SCIM
Zero Trust
MFA
Federation
Okta
SailPoint
Saviynt

Ferramentas

Okta
SailPoint
Saviynt

Descrição da oferta de emprego

Why should you join dLocal? dLocal enables the biggest companies in the world to collect payments in 40 countries in emerging markets. Global brands rely on us to increase conversion rates and simplify payment expansion effortlessly. As both a payments processor and a merchant of record where we operate, we make it possible for our merchants to make inroads into the world’s fastest-growing, emerging markets. By joining us you will be a part of an amazing global team that makes it all happen. Being a part of dLocal means working with 1000+ teammates from 30+ different nationalities and developing an international career that impacts millions of people’s daily lives. We are builders, we never run from a challenge, we are customer-centric, and if this sounds like you, we know you will thrive in our team.

About Us & The Role

We are not building a traditional, bureaucratic identity and access management function. We are building a modern, highly automated identity security program—and we need a sharp, relentless operator to build it. Identity is the new perimeter, and managing how our global workforce accesses enterprise systems is one of our highest priorities. We are looking for a Principal Security Engineer - Identity & Access to help drive our identity evolution alongside our existing senior engineering team. You will be walking into a rapidly evolving ecosystem that has outgrown its early identity frameworks. Your mandate is to take that complex web of legacy entitlements and build a highly scalable, automated identity governance machine. This is not an 'ivory tower' strategy role. We do not need someone to draw Visio diagrams and hand them off to junior admins. We need a pragmatic, high-agency builder who helps design the strategy but has the zero-ego grit to execute it with their own hands.

What You'll Do
  • Engineer the Identity Lifecycle (JML & SoD): Take on our workforce identity and access ecosystem. You will engineer a highly automated Joiner-Mover-Leaver (JML) machine, implementing robust access certifications, Separation of Duties (SoD), and unified IGA frameworks that scale with our hyper-growth.
  • Federation, Zero Trust & Integration: Design and scale our authentication and authorization foundations across cloud, SaaS, and on-premise environments. You will lead identity federation leveraging SAML, OAuth2, OpenID Connect, and SCIM, while driving the adoption of Zero Trust architecture and Adaptive MFA across the enterprise.
  • M&A & Enterprise Transformation: As a rapidly expanding global fintech, we acquire and scale. You will lead the identity integration strategy for mergers, acquisitions, and massive enterprise transformation initiatives, securely and seamlessly folding new organizations into our identity ecosystem.
  • Zero-Ego Execution: As a senior technical anchor on the team, you lead by example. You will get your hands dirty. You will configure the integrations, write the RBAC policies, engineer the IGA platforms, and untangle access flows yourself.
  • Codify Governance & Shift Left: You will design self-service identity workflows, automated controls, and identity KPIs that force business leaders (the first line of defense) to explicitly own and accept their access risks. You translate written compliance policies into code.
  • Be the IAM Diplomat: When you change how developers and commercial teams authenticate, there is always friction. You will be a key face of our identity transformation. You must have the extreme patience, persistence, and EQ to negotiate with engineering directors, bringing them along and enforcing security without alienating them.
What You Bring
  • Resilient Problem Solver: You don't get stuck. Where others see a messy legacy setup, you see an exciting puzzle. You don't get paralyzed or frustrated by organizational friction; you thrive on using the latest technologies and original thinking to solve long-standing identity problems.
  • Track Record Over Tenure: We do not care about arbitrary 'years of experience.' We care about outcomes. You must have a proven track record of designing, building, or scaling Identity and Access programs in fast-paced, complex environments.
  • Deep IGA & Protocol Expertise: You possess solid, hands-on experience with modern workforce identity systems, lifecycle processes (JML, SoD, Certifications), protocols (SAML, OIDC, OAuth2, SCIM), RBAC/ABAC models, and enterprise identity platforms (e.g., SailPoint, Saviynt, Okta).
  • Pragmatic Operator Mindset: You understand that security cannot kill velocity. You know how to find the critical balance between enforcing strict, least-privilege security and maintaining high usability for the business.
  • Disciplined Multi-Threading: You are ruthlessly organized, capable of driving an enterprise identity strategy while simultaneously troubleshooting an immediate, ground-level access escalation.
  • Force Multiplier: You elevate the engineers around you. You bring strong mentoring, leadership, and documentation capabilities, ensuring that the systems you design are highly scalable, well-understood, and easily maintained by the wider organization.
Nice to Have
  • Experience navigating the identity and access requirements of highly regulated environments (PCI-DSS, SOX, SOC 2).
  • Familiarity with machine identity governance, secrets management, and API access.
  • Relevant industry certifications demonstrating your dedication to the identity domain.
Your Cross-Functional Surface Area

You will not work in a silo. You will partner deeply with Enterprise IT Service Desk, Application owners, Cloud Platform, and Infrastructure teams to govern access across Enterprise and Cloud. You will align with Detection & Response teams to improve identity threat visibility and automated containment, and you will collaborate heavily with HR and Enterprise Applications to ensure identity data flows securely from the ultimate source of truth.

What do we offer?
  • Flexibility: we have flexible schedules and we are driven by performance
  • Fintech industry: work in a dynamic and ever-evolving environment, with plenty to build and boost your creativity
  • Referral bonus program: our internal talents are the best recruiters - refer someone ideal for a role and get rewarded
  • Social budget: you'll get a monthly budget to chill out with your team (in person or remotely) and deepen your connections!
  • dLocal Houses: want to rent a house to spend one week anywhere in the world coworking with your team? We've got your back!
Flexibility in how you work:

We focus on impact and productivity over fixed hours. This means our teams have flexible schedules and, depending on your role and location, you will combine self-managed focus time with moments of in-person connection in our collaboration hubs.

What happens after you apply?

Our Talent Acquisition team is invested in creating the best candidate experience possible, so don’t worry, you will definitely hear from us. We will review your CV and keep you posted by email at every step of the process! Also, you can check out our webpage, Linkedin and Youtube for more about dLocal! We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Senior GRC Partner – Governance, Assurance & Third-Party Risk
Senior GRC Partner – Governance, Assurance & Third-Party Risk

Dlocal • São Paulo

Presencial
BRL 150 000 - 250 000
Flexible schedules
Referral bonus program
Social budget for team bonding
+1
Staff Engineer - Payments Performance
Staff Engineer - Payments Performance

dLocal • São Paulo

Presencial
BRL 350 000 - 520 000
Flexibility in schedules
Fintech industry exposure
Referral bonus program
+2
IT Internal Audit Manager
IT Internal Audit Manager

dLocal • São Paulo

Presencial
BRL 320 000 - 520 000
Flexibility in schedules
Fintech industry environment
Referral bonus program
+2
Data Specialist for Compliance — Transaction Monitoring & Financial Crime
Data Specialist for Compliance — Transaction Monitoring & Financial Crime

dLocal • São Paulo

Híbrido
BRL 180 000 - 240 000
Flexible schedules
Fintech industry environment
Referral bonus program
+2
Fraud Prevention Analyst II
Fraud Prevention Analyst II

Dlocal • São Paulo

Presencial
BRL 120 000 - 180 000
Flexible schedules
Fintech industry environment
Referral bonus program
+2
Ethics & Compliance Officer
Ethics & Compliance Officer

dLocal • São Paulo

Presencial
BRL 240 000 - 360 000
Flexibility
Fintech environment
Referral bonus program
+2
SEC Manager
SEC Manager

Dlocal Corp • São Paulo

Presencial
BRL 250 000 - 420 000
Flexible schedules
Fintech environment
Referral bonus program
+3
Regional Accounting Lead
Regional Accounting Lead

dLocal • Brasil

Híbrido
BRL 200 000 - 320 000
Flexibility
Fintech industry
Referral bonus program
+2
Account Manager
Account Manager

dLocal • São Paulo

Presencial
BRL 180 000 - 260 000
Customer Success Manager - Brazil
Customer Success Manager - Brazil

Dlocal Corp • Brasil

Presencial
BRL 120 000 - 180 000
Flexible schedules
Referral bonus program
Social budget
+2