Senior Identity Access Management Engineer

Segment (Twilio)

Santa Monica (CA)

On-site

USD 158,000 - 279,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health insurance
Equity awards
Life insurance
Disability benefits
Parental leave
Wellness benefits
Paid time off
Global mental health resources

Job summary

Roku seeks a senior Identity Engineer to strengthen its Zero‑Trust architecture and standardize global IAM practices. You will optimize the Microsoft‑centric identity platform and enable a geographically distributed workforce with robust automation and Azure Entra ID integration.

You will lead policy enforcement, access governance, and onboarding of enterprise apps while collaborating across IT, security, and networking teams to deliver secure, scalable solutions.

Qualifications

  • 8+ years hands-on IAM and cloud automation experience.
  • Strong analytical and problem-solving abilities in complex infra.
  • Excellent communication for technical and non-technical stakeholders.
  • Deep experience with Entra ID, CA, Identity Governance, and PIM.
  • Familiar with Microsoft 365 services: Exchange Online, Defender, Purview, Sentinel, Intune.
  • Proficient in PowerShell, Azure CLI, and Graph API.
  • Onboarding and managing enterprise apps in Azure Entra ID.
  • Understanding of MFA and security standards.
  • Experience with policy-as-code concepts (OPA / Rego) is a plus.

Responsibilities

  • Lead enterprise‑wide IAM standardization across global regions.
  • Drive automation across IAM to streamline administration.
  • Support onboarding of enterprise apps into Azure Entra ID (SSO, CA, RBAC).
  • Enhance privileged access management and scalable monitoring.
  • Collaborate with IT, Networking, and Security teams on identity issues.
  • Advance Zero Trust Identity Fabric principles across users, devices, workloads.
  • Build identity automation with a DevOps mindset; create tooling from scratch.

Skills

Identity and access management
Microsoft Entra ID
Azure
PowerShell
Azure CLI
Microsoft Graph API
OAuth2 / OpenID Connect / SAML
Zero Trust Architecture
DevOps scripting
Policy-as-code (OPA / Rego)

Education

B.S. in Computer Science, IT, Engineering, or equivalent

Tools

Jira
Confluence

Job description

Roku is seeking a senior‑level Identity Engineer to enhance its Zero‑Trust architecture, drive standardization initiatives, and optimize its Microsoft‑centric identity platform for a geographically distributed workforce.

For California only: the estimated annual salary for this position is between $158,000 and $279,000 annually. Compensation packages are based on factors such as skill set, certifications, and specific geographical location. This role is eligible for health insurance, equity awards, life insurance, disability benefits, parental leave, wellness benefits, and paid time off.

Responsibilities
  • Lead enterprise‑wide IAM standardization, including identity lifecycle, access governance, and policy enforcement across global regions.
  • Drive automation across IAM to streamline administration and deliver a smoother user experience.
  • Support enterprise applications onboarding into Azure Entra ID, including SSO, Conditional Access, and role‑based access control (RBAC).
  • Enhance privileged access management and implement scalable monitoring, alerting, and auditability solutions to support a secure, geographically distributed workforce.
  • Collaborate with IT, Networking, and Security teams to troubleshoot identity‑related issues and support global infrastructure initiatives.
  • Advance Zero Trust Identity Fabric principles such as continuous verification, least‑privilege access, and identity‑aware policy enforcement across users, devices, workloads, and non‑human identities.
  • Build identity automation with a DevOps mindset, writing scripts, developing pipelines, and engineering tooling from scratch rather than just configuring them.
Qualifications
  • 8+ years of hands‑on experience with identity and access management and automating cloud technologies, particularly within the Microsoft ecosystem.
  • Strong analytical skills and attention to detail, with the ability to troubleshoot complex infrastructure and identity‑related issues.
  • Excellent communication skills, able to clearly explain technical concepts to both technical and non‑technical stakeholders.
  • Deep experience with Microsoft Entra ID, including Conditional Access, Identity Governance, and Privileged Identity Management.
  • Familiarity with Microsoft 365 services: Exchange Online, Defender, Purview, Sentinel, Intune, and related platforms.
  • Automation and scripting skills using PowerShell, Azure CLI, and Microsoft Graph API; working knowledge of Azure services such as Function Apps and Logic Apps.
  • Experience in onboarding and managing enterprise applications in Azure Entra ID.
  • Advanced knowledge of Azure Single Sign‑On (SSO) login methods, including OAuth2, OpenID Connect, and SAML, and their integration with enterprise applications.
  • Knowledge of privileged access tools (Azure PIM, CyberArk, etc.), secrets management (HashiCorp or Azure Key Vault), and workload identity patterns (SPIFFE & SPIRE).
  • Familiarity with NHI governance concepts for service accounts and AI agents, and exposure to OPA / Rego or similar policy‑as‑code frameworks.
  • Good to have familiarity with Microsoft Purview for DLP and data classification.
  • Strong understanding of multi‑factor authentication and FIDO2.
  • Familiarity with IT security frameworks and compliance standards.
  • Knowledge of logging, monitoring, and alerting practices for identity and access events.
  • Basic understanding of email security and DNS.
  • Experience with backup and recovery strategies for identity‑related services.
  • Understanding of Zero Trust Architecture principles.
  • Familiarity with Jira and Confluence.
  • B.S. in Computer Science, Information Technology, Engineering, or equivalent experience.
Benefits
  • Health insurance, life insurance, and disability benefits.
  • Equity awards.
  • Parental leave.
  • Wellness benefits.
  • Paid time off.
  • Global access to mental health and financial wellness support and resources.
  • Statutory and voluntary benefits, including healthcare (medical, dental, vision), commuter, and retirement options such as 401(k) and pension.
  • Other benefits may vary by location and role; consult with a recruiter for details.
EEO and Accessibility

Roku welcomes applicants of all backgrounds and provides reasonable accommodations and adjustments in accordance with applicable law. If you require reasonable accommodation at any point in the hiring process, please direct your inquiries to EmployeeRelations@Roku.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Identity Access Management Engineer
Senior Identity Access Management Engineer

Roku • San Jose (CA)

On-site
USD 158,000 - 279,000
Health insurance
Equity awards
Parental leave
+2
Senior Identity Access Management Engineer
Senior Identity Access Management Engineer

Roku • Santa Monica (CA)

Hybrid
USD 158,000 - 279,000
Health insurance
Equity awards
Life insurance
+4
Senior Identity Access Management Engineer
Senior Identity Access Management Engineer

roku • Austin (TX)

On-site
USD 158,000 - 279,000
Health insurance
Equity awards
Life insurance
+4
Senior Identity Access Management Engineer
Senior Identity Access Management Engineer

Roku, Inc. • New York (NY)

Hybrid
USD 158,000 - 279,000
Health insurance
Equity awards
Life insurance
+4
Senior Identity Access Management Engineer
Senior Identity Access Management Engineer

Roku • New York (NY)

Hybrid
USD 140,000 - 212,000
Health insurance
Equity awards
Life insurance
+4
Senior IAM Engineer: Zero Trust, Entra & Automation
Senior IAM Engineer: Zero Trust, Entra & Automation

Segment (Twilio) • Santa Monica (CA)

On-site
USD 158,000 - 279,000
Health insurance
Equity awards
Life insurance
+5
Senior IAM Engineer - Azure Entra & Zero Trust (Hybrid)
Senior IAM Engineer - Azure Entra & Zero Trust (Hybrid)

Roku, Inc. • New York (NY)

Hybrid
USD 158,000 - 279,000
Health insurance
Equity awards
Life insurance
+4
Senior IAM Engineer: Zero-Trust & Azure Entra
Senior IAM Engineer: Zero-Trust & Azure Entra

Roku • Santa Monica (CA)

Hybrid
USD 158,000 - 279,000
Health insurance
Equity awards
Life insurance
+4
Senior Software Engineer
Senior Software Engineer

Roku • San Jose (CA)

Hybrid
USD 370,000 - 400,000
Health insurance
Equity awards
Life insurance
+4
Senior Software Engineer (Frontend/Client Engineering)
Senior Software Engineer (Frontend/Client Engineering)

Roku, Inc. • San Jose (CA)

Hybrid
USD 246,000 - 487,000
Health insurance
Equity awards
Life insurance
+2