Senior Identity Access Management Engineer

roku

Austin (TX)

On-site

USD 158,000 - 279,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Equity awards
Life insurance
Disability benefits
Parental leave
Wellness benefits
Paid time off

Job summary

Roku is seeking a senior Identity Engineer to strengthen Zero‑Trust architecture and standardize its Microsoft‑centric identity platform for a geographically distributed workforce.

You will lead enterprise IAM standardization, drive automation, onboard apps to Azure Entra ID, and enhance privileged access management while collaborating with IT, Networking and Security teams to support global initiatives.

Qualifications

  • 8+ years of hands‑on IAM and automating cloud technologies in the Microsoft ecosystem.
  • Strong analytical skills with the ability to troubleshoot complex infrastructure and identity issues.
  • Excellent communication skills for stakeholders.
  • Deep experience with Microsoft Entra ID, including Conditional Access, Identity Governance, and Privileged Identity Management.
  • Familiarity with Microsoft 365 services: Exchange Online, Defender, Purview, Sentinel, Intune, and related platforms.
  • Automation and scripting using PowerShell, Azure CLI, and Microsoft Graph API; knowledge of Function Apps and Logic Apps.
  • Experience onboarding and managing enterprise applications in Azure Entra ID.
  • Advanced knowledge of Azure SSO methods (OAuth2, OpenID Connect, SAML) and integration with enterprise apps.
  • Knowledge of privileged access tools (AzurePIM, CyberArk), secrets management (HashiCorp or Azure Key Vault), and workload identity (SPIFFE/SPIRE).
  • Familiarity with policy‑as‑code frameworks (OPA/Rego) and IT security governance concepts in service accounts and AI agents.
  • Nice to have familiarity with Microsoft Purview for DLP and data classification.
  • Strong understanding of MFA and FIDO2; familiarity with IT security frameworks and logging/monitoring of identity events.

Responsibilities

  • Lead enterprise‑wide IAM standardization across global regions.
  • Drive automation across IAM to streamline administration and user experience.
  • Onboard enterprise applications into Azure Entra ID with SSO, Conditional Access, and RBAC.
  • Enhance privileged access management and implement scalable monitoring and auditing.
  • Collaborate with IT, Networking, and Security to troubleshoot identity issues across global infrastructure.
  • Advance Zero Trust Identity Fabric principles across users, devices, workloads, and non‑human identities.
  • Build identity automation with a DevOps mindset, writing scripts and engineering tooling from scratch.

Skills

IAM
Automation
Azure
Microsoft Entra ID
Scripting

Education

B.S. in Computer Science / IT / Engineering

Tools

PowerShell
Azure CLI
Microsoft Graph API
Function Apps
Logic Apps
Jira
Confluence

Job description

Role Overview

Roku is seeking a senior-level Identity Engineer to enhance its Zero‑Trust architecture, drive standardization initiatives, and optimize its Microsoft‑centric identity platform for a geographically distributed workforce.

Responsibilities
  • Lead enterprise‑wide IAM standardization, including identity lifecycle, access governance, and policy enforcement across global regions.
  • Drive automation across IAM to streamline administration and deliver a smoother user experience.
  • Support enterprise applications onboarding into AzureEntraID, including SSO, Conditional Access, and role‑based access control (RBAC).
  • Enhance privileged access management and implement scalable monitoring, alerting, and auditability solutions to support a secure, geographically distributed workforce.
  • Collaborate with IT, Networking, and Security teams to troubleshoot identity‑related issues and support global infrastructure initiatives.
  • Advance Zero Trust Identity Fabric principles like continuous verification, least‑privilege access, and identity‑aware policy enforcement across users, devices, workloads, and non‑human identities.
  • Build identity automation with a DevOps mindset, writing scripts, developing pipelines, and engineering tooling from scratch rather than just configuring them.
Qualifications
  • 8+ years of hands‑on experience with identity and access management and automating cloud technologies, particularly within the Microsoft ecosystem.
  • Strong analytical skills and attention to detail, with the ability to troubleshoot complex infrastructure and identity‑related issues.
  • Excellent communication skills, with the ability to clearly explain technical concepts to both technical and non‑technical stakeholders.
  • Deep experience with MicrosoftEntraID, including Conditional Access, Identity Governance, and Privileged Identity Management.
  • Familiarity with Microsoft365 services: Exchange Online, Defender, Purview, Sentinel, Intune, and related platforms.
  • Automation and scripting skills using PowerShell, Azure CLI, and Microsoft Graph API; working knowledge of Azure services such as Function Apps and Logic Apps.
  • Experience in onboarding and managing enterprise applications in AzureEntraID.
  • Advanced knowledge of Azure Single Sign‑On (SSO) login methods, including OAuth2, OpenID Connect, and SAML, and their integration with enterprise applications.
  • Knowledge of privileged access tools (AzurePIM, CyberArk, etc.), secrets management (HashiCorp or AzureKeyVault), and workload identity patterns SPIFEE & SPIRE.
  • Familiarity with NHI governance concepts for service accounts and AI agents, and exposure to OPA/ Rego or similar policy‑as‑code frameworks.
  • Good to have familiarity with MicrosoftPurview for DLP and data classification.
  • Strong understanding of multi‑factor authentication and FIDO2.
  • Familiarity with IT security frameworks and compliance standards.
  • Knowledge of logging, monitoring, and alerting practices for identity and access events.
  • Basic understanding of email security and DNS.
  • Experience with backup and recovery strategies for identity‑related services.
  • Understanding of Zero Trust Architecture principles.
  • Familiarity with Jira and Confluence.
  • B.S. in Computer Science, Information Technology, Engineering, or equivalent experience.
Compensation and Benefits

Estimated annual salary: $158,000 – $279,000 (dependent on experience, certifications, and location). Eligible for health insurance, equity awards, life insurance, disability benefits, parental leave, wellness benefits, and paid time off.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Identity Access Management Engineer
Senior Identity Access Management Engineer

Segment (Twilio) • Santa Monica (CA)

On-site
USD 158,000 - 279,000
Health insurance
Equity awards
Life insurance
+5
Senior Identity Access Management Engineer
Senior Identity Access Management Engineer

Roku • San Jose (CA)

On-site
USD 158,000 - 279,000
Health insurance
Equity awards
Parental leave
+2
Senior Identity Access Management Engineer
Senior Identity Access Management Engineer

Roku • Santa Monica (CA)

Hybrid
USD 158,000 - 279,000
Health insurance
Equity awards
Life insurance
+4
Senior Identity Access Management Engineer
Senior Identity Access Management Engineer

Roku • New York (NY)

Hybrid
USD 140,000 - 212,000
Health insurance
Equity awards
Life insurance
+4
Senior IAM Engineer: Zero Trust, Entra & Automation
Senior IAM Engineer: Zero Trust, Entra & Automation

Segment (Twilio) • Santa Monica (CA)

On-site
USD 158,000 - 279,000
Health insurance
Equity awards
Life insurance
+5
Senior IAM Engineer: Zero-Trust & Azure Entra
Senior IAM Engineer: Zero-Trust & Azure Entra

Roku • Santa Monica (CA)

Hybrid
USD 158,000 - 279,000
Health insurance
Equity awards
Life insurance
+4
Infrastructure Engineer
Infrastructure Engineer

Huxley • Boston (MA)

On-site
USD 120,000 - 150,000
Cybersecurity IAM Engineer
Cybersecurity IAM Engineer

Upbound Field Support Center Rent A Center Texas LP • United States

On-site
USD 100,000 - 130,000
Equal Opportunity Employer
Inclusive environment commitment
Senior Specialist, Lead Zero Trust Identity Security Engineering
Senior Specialist, Lead Zero Trust Identity Security Engineering

Vanguard • Dallas (TX)

On-site
USD 190,000 - 230,000
Sr Security Engineer
Sr Security Engineer

Adobe • Seattle (WA)

On-site
USD 120,000 - 160,000