IT Security & Identity Engineer

Neuralink

Austin (TX)

On-site

USD 120,000 - 180,000

Full time

6 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Neuralink is seeking a Hands-on IT Security & Identity Engineer to own identity, access, and endpoint security for our corporate environment. You will manage our IdP, SSO federation, and lifecycle automation, while driving endpoint protection, detections, and vulnerability management with the IT team.

This build-and-operate role requires practical risk decisions, clear communication with engineers and clinicians, and the ability to run controls in production, including on-call responsibilities.

Qualifications

  • Bachelor's degree or 5+ years of professional enterprise IT security experience.
  • 5+ years securing corporate IT environments (identity/MFA, endpoint security, logging/detection, vulnerability management).
  • Experience administering an enterprise IdP (Google Workspace, Microsoft Entra, or Okta) including SSO federation and SCIM provisioning.
  • Strong knowledge of IAM protocols: SAML, OIDC, OAuth 2.0, SCIM.
  • Hands-on infrastructure/configuration using Terraform and Git-based workflows.

Responsibilities

  • Design, deploy, and operate identity and access management across multiple platforms; own SSO federation and SCIM provisioning.
  • Manage identity infrastructure and access policy as code using Terraform and GitLab CI/CD.
  • Drive identity lifecycle automation from onboarding through offboarding with RBAC and just-in-time access.
  • Design and operate strong authentication (MFA, FIDO2/WebAuthn).
  • Own endpoint security posture across macOS, Windows, and Linux including EDR and device encryption.
  • Build and maintain security logging and detection across identity, endpoint, SaaS, and network logs.
  • Run enterprise vulnerability management including prioritization and remediation workflows.
  • Harden IT services used by engineering, science, and clinical staff; review permissions and access models.
  • Collaborate to design and operate services on the network with strong authentication and least privilege.
  • Lead or support detection, triage, and incident response; participate in on-call rotation.
  • Conduct regular access reviews; produce evidence for HIPAA and SOC 2 compliance.

Skills

IAM security
MFA enforcement
Endpoint security
Logging & detection
Vulnerability management
Email/file services
Scripting (Python/Bash/PowerShell)
Terraform
GitLab CI/CD
SSO federation

Education

Bachelor's degree in computer science, cybersecurity, or another STEM discipline

Tools

Terraform
GitLab CI/CD
SAML
OIDC
OAuth 2.0
SCIM provisioning
Google Workspace
Microsoft Entra

Job description

We are creating devices that enable a bi-directional interface with the brain. These devices allow us to restore movement to the paralyzed, restore sight to the blind, and revolutionize how humans interact with their digital world.

Team Description:

Neuralink's Information Technology team owns the corporate environment that every engineer, scientist, and clinician depends on to do their work. Within IT, the Security & Identity function is responsible for who can access what, from which device, under what conditions. That means running the identity provider and SSO federation, enforcing strong authentication and device trust, securing endpoints across macOS, Windows, and Linux, centralizing logs and detections, and producing the audit evidence that supports HIPAA and SOC 2. We manage this environment as code in Terraform and GitLab, and we hold a high bar for making access both secure and low-friction for a fast-moving company.

Job Description and Responsibilities:

Neuralink is looking for a hands-on IT Security & Identity Engineer to own identity, access, and endpoint security for our corporate environment. You will be the technical owner of our identity provider, SSO federation, and lifecycle automation, and you will drive endpoint protection, detection, and vulnerability management alongside the rest of the IT team. This is a build-and-operate role: you will design controls, implement them in Terraform through GitLab, and then run them in production, including on-call. The ideal candidate has strong opinions grounded in experience, takes full ownership of the systems they build, makes practical risk decisions without slowing the company down, and can explain security tradeoffs clearly to engineers and non-technical staff alike. The job responsibilities will include:

  • Design, deploy, and operate identity and access management across Google Workspace, Microsoft Entra, and integrated SaaS applications; own SSO federation (SAML, OIDC, OAuth 2.0) and SCIM provisioning for business-critical tools.
  • Manage identity infrastructure and access policy as code using Terraform and GitLab CI/CD; treat the IdP, group membership, application assignments, and conditional access as versioned, reviewable state.
  • Drive identity lifecycle automation from onboarding through offboarding, including role-based access control (RBAC), attribute-driven group membership, just-in-time access, and reduction of standing privilege.
  • Design and operate strong authentication: phishing-resistant MFA (FIDO2/WebAuthn, passkeys, hardware tokens), certificate-based authentication (X.509, 802.1x), and device-trust conditions tied to MDM compliance.
  • Own endpoint security posture across macOS, Windows, and Linux alongside the IT team: EDR policy and operations, disk encryption, secure baselines, and compliance enforcement through MDM (Intune, Jamf, or similar).
  • Build and maintain security logging and detection for corporate IT: centralize identity, endpoint, SaaS, and network logs (Grafana/Loki, Prometheus, or a SIEM), write detections for identity abuse and endpoint compromise, and tune alerting.
  • Run enterprise vulnerability management: scanning, prioritization, remediation workflows with system owners, and evidence of closure.
  • Harden traditional IT services used by engineering, science, and clinical staff (email, file shares, directory services, collaboration tools, internal applications); review and improve permissions, group membership, and access models.
  • Partner with systems, network, and application owners to securely design and operate services on the Tailscale and FortiGate-based network: authentication and authorization, logging, patching, and least privilege.
  • Lead or support detection, triage, and incident response for the corporate IT environment; participate in the IT on-call rotation.
  • Conduct regular access reviews and audits; produce evidence supporting HIPAA, PII handling, and SOC 2 or comparable frameworks in partnership with Compliance.
  • Drive scripting and automation (Python, Bash, PowerShell) for repeatable security tasks: baselines, evidence collection, health checks, and remediation.
  • Recommend, justify, and implement improvements through an accepted change control process; define, document, and follow standards for design, testing, and implementation.
  • Serve as the IAM and security subject matter expert for the IT team, providing technical guidance and mentoring teammates.
Required Qualifications:
  • Bachelor's degree in computer science, cybersecurity, or another STEM discipline, or 5+ years of professional experience in enterprise IT security engineering in lieu of a degree.
  • 5+ years of hands‑on experience securing corporate IT environments (identity/MFA, endpoint security, logging and detection, vulnerability management, email or file services).
  • Demonstrated experience administering an enterprise IdP (Google Workspace, Microsoft Entra, or Okta) including SSO federation, SCIM provisioning, MFA enforcement, conditional access, and full user lifecycle management.
  • Strong working knowledge of IAM protocols and standards: SAML, OIDC, OAuth 2.0, SCIM.
  • Hands‑on experience managing infrastructure or identity configuration with Terraform and Git-based workflows.
  • Experience administering or operating at least two of the following: enterprise EDR/AV, centralized logging or SIEM, enterprise vulnerability management platform, enterprise MDM.
  • Scripting proficiency in Python, Bash, or PowerShell for security automation and integrations.
  • Excellent communication skills with IT engineers and a diverse user base including non-technical scientists and clinicians; able to explain security tradeoffs and risk decisions clearly.
Preferred Qualifications:
  • Experience implementing phishing-resistant MFA at scale: FIDO2/WebAuthn, passkeys, hardware tokens, smart cards.
  • Certificate-based authentication and PKI operations: TLS, X.509, 802.1x, internal CA management.
  • Zero-trust architecture experience, including device trust, Tailscale or comparable mesh VPN, and identity-aware access.
  • Detection engineering experience: writing and tuning detections in Grafana/Loki, a SIEM, or comparable tooling.
  • Hardening Windows, macOS, and Linux endpoints and servers; securing file shares, email gateways, and internal applications.
  • Privileged access management, just-in-time access, and reduction of standing privilege.
  • SOC or blue-team incident response experience on enterprise IT estates.
  • Configuration management with Ansible or similar; GitLab CI/CD
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Client Engineer
IT Client Engineer

Figureai • San Jose (CA)

On-site
USD 120,000 - 180,000
IT Client Engineer
IT Client Engineer

Figure • San Jose (CA)

On-site
USD 180,000 - 210,000
IT Client Engineer
IT Client Engineer

Figure- • San Jose (CA)

On-site
USD 120,000 - 180,000
Founding IT Engineer
Founding IT Engineer

Cogent • San Francisco (CA)

On-site
USD 140,000 - 210,000
Founding IT Engineer
Founding IT Engineer

Cogent-Security • San Francisco (CA)

On-site
USD 140,000 - 190,000
Identity & Endpoint Security Engineer
Identity & Endpoint Security Engineer

Neuralink • Austin (TX)

On-site
USD 120,000 - 180,000
Member of Technical Staff, IT
Member of Technical Staff, IT

Genesis AI • San Francisco (CA)

On-site
USD 180,000 - 240,000
Principal Software Engineer (Identity Services)
Principal Software Engineer (Identity Services)

INSPYR Solutions • Beverly Hills (CA)

Hybrid
USD 180,000 - 240,000
Staff Security Engineer, IAM
Staff Security Engineer, IAM

GitLab • United States

On-site
USD 180,000 - 240,000
IT & Security Engineer (Part Time)
IT & Security Engineer (Part Time)

Ultimate Staffing Services • Salt Lake City (UT)

Hybrid
USD 50,000 - 59,000