SecurityEngineer,IAM
Title:SecurityEngineer,IAM
Level:IC-2
Location:LosAngeles,CA
Worksetup:In-office(4daysaweek)
Department:IT
Company
TalentSystems,LLCistheleadingtechnologysolutionproviderforcastingandauditioningtotheentertainmentindustry.CastingdirectorsandagentsworldwideuseTalentSystems’portfolioofproductstosourceandmanagetalentacrossfilm,television,commercials,theateranddigitalprojects,poweringanunparalleled,globalcastingsoftwareecosystem.
WeareheadquarteredinLosAngelesandoperateintheUS,Canada,UK,AustraliaandIndia.OurportfoliobrandsincludeCastingNetworks,Spotlight,CastItSystems,CastItTalent,CastingFrontier,StaffMeUp,CastItReach&Tagmin.
JobDescription
The Security Engineer, IAM will design, implement, and manage Identity and Access Management systems across Talent Systems' global technology stack. This role sits within the Corporate IT team and is critical to ensuring that the right people have the right access to the right resources and that unauthorized access is proactively detected and prevented. You will work cross-functionally with Engineering, Product, Security, and HR teams to build scalable, secure, and compliance-aligned identity infrastructure that supports our global platforms and workforce.
IAM Architecture & Engineering
- Design,deploy,andmaintainIAMsolutionsincludingSSO,MFA,RBAC,andPAMacrosscloudandon-premiseenvironments
- ArchitectandmanageidentityfederationusingprotocolssuchasSAML,OAuth2.0,andOpenIDConnect
- Buildandmaintainlifecyclemanagementprocessesforuserprovisioning,de-provisioning,andaccessreviews
- IntegrateIAMsystemswithSaaSplatforms(GoogleWorkspace,Slack,GitHub,Zendesk,andothers)andinternalapplications
- Developandmaintainautomationforaccessrequestworkflowsandentitlementmanagement
Security Operations & Compliance
- Conductperiodicaccessreviewsandcertificationcampaignstoensureleast-privilegeprinciplesareenforced
- MonitorIAMsystemsforanomalousactivity,accessviolations,andpolicydrift;respondtoandremediateincidents
- SupportauditandcomplianceactivitiesrelatedtoSOC2,PCI-DSS,GDPR,andotherapplicableframeworks
- DefineandenforceIAMpolicies,standards,andproceduresinalignmentwithindustrybestpractices
- CollaboratewiththeInformationSecurityOfficetoevaluateandcloseidentity-relatedvulnerabilities
Cross-Functional Collaboration
- PartnerwithEngineeringandDevOpsteamstoembedIAMcontrolsintoCI/CDpipelinesandcloudinfrastructure
- WorkwithITTeamtoalignidentityprocesseswithendpointandnetworksecuritypolicies
- Supportonboarding,offboarding,androle-changeworkflowsincoordinationwithPeopleOperations
- Participatein cross-functional planning to surface IAM-related risks, roadmap items, and quarterly priorities
- 4+yearsofhands-onexperienceinIAMengineering,identitysecurity,oracloselyrelatedfield
- ProficiencywithIAMprotocols:SAML,OAuth2.0,OpenIDConnect,LDAP,SCIM
- Experienceadministeringanenterpriseidentityprovider(e.g.,Okta,AzureAD/EntraID,GoogleWorkspaceIdentity,orequivalent)
- SolidunderstandingofRBAC,least-privilege,andzero-trustprinciples
- FamiliaritywithcomplianceframeworksincludingSOC2TypeII,GDPR,andISO27001
- Excellentwrittenandverbalcommunicationskills;abletoexplaincomplexidentityconceptstonon-technicalstakeholders
- Preferred:ExperiencewithPrivilegedAccessManagement(PAM)tools(e.g.,CyberArk,BeyondTrust,HashiCorpVault)
- Preferred:DemonstratedabilitytoscriptandautomateIAMworkflowsusingPython,PowerShell,Bash,orsimilar
- Preferred:Hands-onexperiencewithcloudIAM(AWSIAM,GCPIAM,orAzureRBAC)
- Preferred:BackgroundinSaaSormulti-tenantplatformenvironmentswithcomplexuserhierarchymanagement
- Preferred:Exposuretoentertainment,media,ormarketplaceplatformsecurity
- Preferred: Experience working in a globally distributed team across multiple time zones