IAM Security Engineer

Gala Solutions

Denver (CO)

On-site

USD 150,000 - 210,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Gala Solutions in Denver seeks a Senior Security Engineer to architect and implement identity and access management at scale, including federation with enterprise providers, OAuth2/OIDC internals, and fine-grained access control. You will build production-ready solutions and enforce least-privilege practices.

This role focuses on secure container deployments, cloud IAM, automated rotation of secrets, and integration with SIEM for real-time detection.

Qualifications

  • 8+ years in security engineering, incl. 3+ years IAM at scale.
  • Enterprise identity federation with OIDC/SAML, provisioning, and mapping federated identity.

Responsibilities

  • Architect and implement IAM at scale across multi-cloud environments.
  • Design and enforce access control models (RBAC/ABAC/REBAC).
  • Develop and maintain cloud IAM and automated secret rotation.
  • Deliver container security fundamentals and production-grade code.
  • Integrate security telemetry pipelines and SIEM for detections.

Skills

Security engineering
IAM at scale
Federation protocols (OIDC, SAML)
OAuth2/OIDC internals
RBAC/ABAC/REBAC
Cloud IAM & secrets management
Container security basics
Production-grade code delivery
Least-privilege provisioning

Tools

Kubernetes
SIEM concepts

Job description

- Central identity federated to the priority downstream systems through a canonical role model, with automated provisioning and end-to-end audit in place.

- Baseline continuous vulnerability scanning live across edge nodes and containers, with risk-scored findings flowing to the event bus.

- The edge security-telemetry pipeline designed and piloted on a representative node set — local visibility layer collecting and forwarding to the SIEM, with store-and-forward proven.

By the second half of the engagement

- Just-in-time elevation, the central policy engine, and access recertification running in production; standing administrative access eliminated.

- Agent workload identity, tool-invocation authorization, delegation, and human-approval workflows operational for sensitive actions.

- Vulnerability coverage extended across the full fleet, and identity-correlated SIEM detections live — every alert resolving to a verifiable principal.

- Documentation, runbooks, and standards handed over so the platform remains fully operable beyond the engagement.

Required qualifications

- [8+] years in security engineering, including [3+] years architecting identity and access management at scale.

- Deep, hands-on identity federation: enterprise identity providers, OIDC, SAML, standards-based provisioning, and mapping federated identity into downstream systems' native authorization models.

- Strong command of OAuth2/OIDC internals — scopes, audiences, token exchange, audience restriction — and common failure modes such as confused-deputy and token passthrough.

- Demonstrated implementation of an authorization policy model (RBAC plus at least one of ABAC / ReBAC) using an externalized policy engine.

- Cloud IAM depth and centralized secrets management, including automated rotation.

- Container-orchestration and container security fundamentals; able to deliver production-quality code — this role builds, not only advises.

- A track record of shipping least-privilege, just-in-time, and fully auditable access systems.

Preferred qualifications

- Securing AI agents / LLM-based systems and automated tool-invocation interfaces; prompt-injection and tool-boundary threat modeling.

- Workload identity frameworks and machine-to-machine credentialing.

- Security telemetry pipelines and SIEM integration at scale — collection, normalization, retention, and detection/correlation engineering.

- Vulnerability-management program delivery — continuous scanning, SBOM tooling, CVE correlation, and risk-based prioritization.

- Security observability on edge, IoT, or intermittently connected devices — lightweight host-based telemetry agents, store-and-forward under constrained bandwidth, and tamper-evident delivery.

- Zero-trust infrastructure access architectures; PKI, certificate lifecycle, mutual TLS, and device attestation.

- Event-driven platform security and secure CI/CD (artifact signing, infrastructure-as-code scanning, automated security gates).

- Relevant security-architecture certifications (advantageous, not required).

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Enterprise AI Security & Governance Architect
Staff Enterprise AI Security & Governance Architect

Alexander Chapman • San Francisco (CA)

On-site
USD 180,000 - 260,000
INFORMATION TECHNOLOGY
INFORMATION TECHNOLOGY

Solidigm Inc. • Rancho Cordova (CA)

On-site
USD 140,000 - 190,000
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Germany (OH)

On-site
USD 120,000 - 160,000
Cybersecurity IAM Architect - Staff Engineer
Cybersecurity IAM Architect - Staff Engineer

OneMain Financial • Baltimore (MD)

On-site
USD 150,000 - 190,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Security Engineer
Security Engineer

Enterprise Engineering Inc. (EEI) • New York (NY)

On-site
USD 120,000 - 160,000
Senior Security Engineer 5529
Senior Security Engineer 5529

Tier4 Group • Chicago (IL)

On-site
USD 140,000 - 200,000
Security Engineer
Security Engineer

Eleven Recruiting • San Francisco (CA)

On-site
USD 120,000 - 160,000
Remote Senior Cybersecurity Engineer - Build & Own Controls
Remote Senior Cybersecurity Engineer - Build & Own Controls

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Cyber Security Engineer
Cyber Security Engineer

Qualibar • United States

Hybrid
USD 120,000 - 180,000