Security Engineer, IAM

United States Digital Space LLC

Boston (MA)

On-site

USD 130,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity

Job summary

United States Digital Space LLC seeks an IAM Security Engineer to design, implement, and improve identity controls across workforce, SaaS, and cloud environments. You will work with Security, IT, and Engineering to secure authentication and authorization patterns for critical systems.

Responsibilities include configuring SSO/MFA, RBAC/ABAC across clouds, and SCIM provisioning, while partner with Engineering on API access, token management, and privileged access.

Qualifications

  • 3+ years of experience in IAM engineering or identity architecture.
  • Hands-on experience with enterprise identity providers such as Okta, Azure AD, or similar enterprise IAM platforms.
  • Strong understanding of modern authentication and authorization protocols, including SAML, OAuth 2.0, OIDC, SCIM, and JWT.
  • Experience designing and implementing RBAC and/or ABAC models in cloud-native environments.
  • Strong knowledge of AWS IAM, cross-account access models, and cloud identity federation.
  • Experience securing APIs, service accounts, machine identities, and CI/CD authentication workflows.
  • Experience with privileged access management concepts and least privilege enforcement.
  • Experience automating IAM tasks using scripting or infrastructure-as-code tools (i.e., Python, Terraform, or similar).
  • Familiarity with identity threat detection and response methodologies.
  • Bachelor’s degree in Computer Science, Cybersecurity, or related field; relevant certifications or equivalent experience.

Responsibilities

  • Implement authentication and authorization controls across SaaS platforms, cloud infrastructure, and internal applications.
  • Configure and maintain SSO, MFA, conditional access policies, and federation integrations.
  • Assist with evolution of SSO, MFA, conditional access, and zero trust models.
  • Assist in design and enforce RBAC/ABAC across cloud and SaaS systems.
  • Validate identity provider integrations, including onboarding and SCIM provisioning.
  • Partner with Engineering to secure application authentication flows, API access, and token management.
  • Harden and optimize identity provider configurations, including lifecycle management and federation.
  • Support AWS IAM security, including policy implementation, role configuration, cross-account access, and identity federation.
  • Implement privileged access and identity lifecycle controls (provisioning, deprovisioning, access reviews).
  • Secure APIs, service accounts, and non-human identities used in automation/CI/CD workflows.
  • Improve identity monitoring and detection capabilities, including anomaly detection and identity threat response.
  • Support identity-related audits with GRC across ISO27001, SOC2, PCI DSS, GDPR.
  • Contribute to incident response involving identity compromise or credential abuse.

Skills

IAM engineering
Okta/Azure AD
SAML/OAuth/OIDC/SCIM/JWT
RBAC/ABAC
AWS IAM
APIs/service accounts
PAM/least privilege
Scripting/Terraform
Identity threat detection

Education

Bachelor's degree in CS/Cybersecurity
Relevant certifications (CISSP, CISM, GIAC, AWS Security)

Tools

Terraform
Python

Job description

At the company, we're on a mission to unlock human performance and healthspan. Our wearable technology provides personalized insights that help millions of members better understand their bodies and make smarter decisions about training, recovery, and lifestyle.

Identity is foundational to securing modern cloud-native platforms, SaaS ecosystems, and enterprise systems. We are seeking an IAM Security Engineer to support the design, implementation, and continuous improvement of identity and access management controls across workforce identity, SaaS platforms, and production cloud environments.

In this role, you will work closely with Security, IT, and Engineering teams to implement secure authentication and authorization patterns that protect critical systems and data.

Responsibilities
  • Implement authentication and authorization controls across SaaS platforms, cloud infrastructure, and internal applications
  • Configure and maintain SSO, MFA, conditional access policies, and federation integrations
  • Assist with the evolution of single sign-on (SSO), multi-factor authentication (MFA), conditional access, and zero trust access models
  • Assist in design and enforce role-based and attribute-based access control models (RBAC/ABAC) across cloud and SaaS systems
  • Validate identity provider integrations, including application onboarding and SCIM provisioning
  • Partner with Engineering to secure application authentication flows, API access, service-to-service authentication, and token management
  • Harden and optimize identity provider configurations, including lifecycle management, federation, and SCIM provisioning
  • Support AWS IAM security, including policy implementation, role configuration, cross-account access management, and identity federation
  • Implement privileged access and identity lifecycle controls, including provisioning, deprovisioning, access reviews, entitlement governance, least privilege enforcement, and just-in-time access mechanisms
  • Secure APIs, service accounts, and non-human identities used in automation and CI/CD workflows
  • Implement and improve identity monitoring and detection capabilities, including anomaly detection, session risk analysis, and identity threat response
  • Partner with GRC to support identity-related audits, evidence collection, and control validation across frameworks such as ISO 27001, SOC 2, PCI DSS, and GDPR
  • Contribute to incident response efforts involving identity compromise, credential abuse, or unauthorized access events
Qualifications
  • 3+ years of experience in IAM engineering or identity architecture
  • Hands-on experience with enterprise identity providers such as Okta, Azure AD, or similar enterprise IAM platforms
  • Strong understanding of modern authentication and authorization protocols, including SAML, OAuth 2.0, OIDC, SCIM, and JWT
  • Experience designing and implementing RBAC and/or ABAC models in cloud-native environments
  • Strong knowledge of AWS IAM, cross-account access models, and cloud identity federation
  • Experience securing APIs, service accounts, machine identities, and CI/CD authentication workflows
  • Experience with privileged access management concepts and least privilege enforcement
  • Experience automating IAM tasks using scripting or infrastructure-as-code tools (i.e., Python, Terraform, or similar infrastructure-as-code tooling)
  • Familiarity with identity threat detection and response methodologies
  • Bachelor's degree in Computer Science, Cybersecurity, or related field; relevant certifications (i.e., CISSP, CISM, GIAC, AWS Security Specialty, Okta Certified Professional) or equivalent practical experience will also be considered

This role is based in the the company office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.

the company is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility

The the company compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values.

At the company, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of the company and share in the company’s long-term growth and success.

The U.S. base salary range for this full-time position is $130,000 - $170,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training.

In addition to the base salary, the successful candidate will also receive benefits and a generous equity package.

These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate’s specific qualifications, expertise, and alignment with the role’s requirements.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Engineer, IAM
Sr Engineer, IAM

Altice USA • Bethpage (NY)

On-site
USD 100,000 - 165,000
Sr Engineer, IAM
Sr Engineer, IAM

Altice USA • Plano (TX)

On-site
USD 100,000 - 165,000
Lead IAM Engineer
Lead IAM Engineer

Blue Cross and Blue Shield of Massachusetts, Inc. • Boston (MA)

On-site
USD 163,000 - 200,000
Paid time off
Medical insurance
Dental insurance
+2
Sr. IT Systems Engineer
Sr. IT Systems Engineer

United States Digital Space LLC • San Mateo (CA)

On-site
USD 150,000 - 230,000
Healthcare programs (employee 100%, 80
Vision, dental
HSA with employer contributions
+7
Identity and Access Management (IAM) Solutions Architect
Identity and Access Management (IAM) Solutions Architect

Clearpath • Arlington (VA)

On-site
USD 175,000 - 205,000
6% 401(k) match
Flexible time off
Health and dental plans
+1
Engineer, IAM & Endpoint Platform
Engineer, IAM & Endpoint Platform

1P284 THE CARLYLE GROUP EMPLOYEE CO., LLC • Washington

On-site
USD 160,000 - 180,000
Senior Systems Engineer - IAM
Senior Systems Engineer - IAM

Berkley Technology Services • Coppell (TX)

Hybrid
USD 107,000 - 198,000
Staff Software Engineer - IAM (Platform Engineering)
Staff Software Engineer - IAM (Platform Engineering)

Geli • United States

On-site
USD 180,000 - 220,000
Senior Systems Engineer - IAM
Senior Systems Engineer - IAM

Berkley Technology Services • Chicago (IL)

On-site
USD 121,000 - 137,000
Health insurance
Dental insurance
Vision insurance
+2
Senior Systems Engineer - IAM
Senior Systems Engineer - IAM

Berkley Technology Services • United States

On-site
USD 110,000 - 190,000
Base salary range: $107,000–$198,000
Comprehensive benefits package