Staff Identity Engineer

United States Digital Space LLC

Washington (District of Columbia)

On-site

USD 161,000 - 221,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Equity
Health insurance
Dental & Vision insurance
401(k)

Job summary

United States Digital Space LLC is seeking a Staff Identity Engineer to own the identity fabric across enterprise IAM. You will drive the architecture, implement security controls, and mentor engineers to uphold high standards.

This role emphasizes Customer Zero adoption, cross-cloud guardrails, and robust identity governance. The position requires expertise in OIDC, SAML, MFA, and Terraform-based IaC, with collaboration across Security, Audit, and Compliance teams to meet SOC 2, ISO 27001, and

Qualifications

  • 4+ years designing and maintaining enterprise IAM solutions.
  • Hands-on with the company Identity Engine (OIE), Directory Integrations, Advanced Policies, Workflows, and Platform APIs.
  • Advanced expertise in OIDC, OAuth 2.0, SAML 2.0 and phishing-resistant MFA paradigms.
  • IaC with Terraform and multi-cloud IAM guardrails across AWS, GCP, Azure.
  • Automation-first mindset with compliance frameworks (SOC 2, ISO 27001, FedRAMP).

Responsibilities

  • Drive Customer Zero execution and act as a technical bridge for internal adoption.
  • Own architecture and hands-on implementation of IAM, MFA, and federation (SAML, OIDC).
  • Mentor engineers and set engineering standards across teams.
  • Collaborate with Security, Audit, and Compliance to ensure controls meet requirements.
  • Govern AI security integration and machine identities within the enterprise identity layer.
  • Define KPIs and translate milestones into actionable leadership updates.

Skills

IAM Architecture
Zero Trust Security
MFA & SSO
Leadership & Mentorship
Policy Design
Automation Mindset

Tools

Terraform
Workflows
APIs & Integrations
SAML/OIDC

Job description

**Secure Every Identity, from AI to Human

**Identity is the key to unlocking the potential of AI. the company secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.

This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

The Identity Team

the company's internal Identity team secures the foundational trust layer for our modern enterprise. As organizations adopt phishing-resistant MFA, attackers have shifted toward session hijacking and cookie theft. Furthermore, with the rise of autonomous AI workloads, we are extending our platform to protect and govern a growing sprawl of non-human, agentic workflows. Our mission is to ensure every person and machine can safely connect to the right technology at the right time.

The Staff Identity Engineer Opportunity

As a Staff Engineer at the company, you will be a technical authority within our internal IAM team, driving the architecture and execution of our identity fabric. You will champion our "Customer Zero" philosophy, partnering with product engineering to deploy the company's newest features internally before they reach global markets. This role requires a technical leader who acts with ownership and urgency, turning action into traction and ruthlessly simplifying complex problems. You will serve as a mentor, influence architectural decisions, and help determine the future of the platform.

What you’ll be doing
  • Drive Customer Zero Execution: Act as a key technical bridge between internal stakeholders, the the company on the company team, and core Product teams. Lead the early adoption of cutting-edge internal capabilities, providing rigorous technical feedback to mature products before global release.
  • Architecture & Hands-On Implementation: Own the lifecycle, policy design, adaptive MFA, and federation (SAML, OIDC) for enterprise the company tenants. Architect and enforce cloud IAM guardrails across AWS, GCP, and Azure, building API-based pipelines to automate complex workflows.
  • Technical Leadership & Mentorship: Serve as a core technical anchor for the engineering team. Mentor engineers, act as a primary review authority for IAM designs, and set technical standards across the organization.
  • Operational & Security Governance: Drive automation-first initiatives to eliminate systemic inefficiencies. Partner directly with Security, Audit, and Compliance teams to ensure identity controls natively meet audit requirements (SOC 2, ISO 27001, FedRAMP).
  • AI Security Integration: Drive the secure adoption of AI technologies by governing AI agents, machine identities, and service-to-service authentication within the enterprise identity layer.
  • Cross-Functional Partnering & Metrics: Collaborate with cross-functional partners to advance identity security, establish operational KPIs, and translate complex technical milestones into actionable leadership updates.
What you’ll bring to the role

To be successful in this role, you should have deep, hands-on architectural experience across the modern identity and cloud infrastructure lifecycle. We are looking for a practitioner who understands both theory and real-world implementation.

  • Domain Experience: 4+ years of hands-on experience designing, implementing, and maintaining enterprise-scale IAM solutions.
  • the company Platform Mastery: Deep expertise in managing complex enterprise the company environments, including hands-on proficiency with the company Identity Engine (OIE), Directory Integrations, Advanced Policies, Workflows, and Platform APIs.
  • Core Identity Protocols: Advanced expertise in modern authentication and authorization standards (OIDC, OAuth 2.0, SAML 2.0) and phishing-resistant MFA paradigms (FIDO2/WebAuthn, Passkeys).
  • Cloud & Infrastructure as Code: Proven experience defining identity controls as code using Terraform and the company Workflows. Practical experience designing cloud IAM guardrails across multi-cloud environments (AWS, GCP, Azure) and M2M/service-to-service authentication.
  • Session & Zero Trust Security: Solid background in session lifecycle security, token management/revocation strategies, and continuous access evaluations (CAEP/eSSO) to mitigate session hijacking.
  • Technical Leadership & Mentorship: Demonstrated experience mentoring engineers, driving design reviews, and establishing engineering best practices across teams.
  • Compliance & Automation Mindset: Strong orientation toward automation-first design, with practical experience building identity controls that align with enterprise frameworks (SOC 2, ISO 27001, FedRAMP).
  • Travel: Occasional travel required as needed.
Additional requirements:
  • U.S. soil status - the employee must be on U.S. soil, which means the 50 states, the District of Columbia, or outlying areas of the United States, as defined in Federal Acquisition Regulation (FAR) 2.101, and be a U.S. person.
  • U.S. person status - the employee must be either a U.S. citizen as defined in 42 U.S. Code § 9102; a natural person who is a lawful permanent resident as defined in 8 U.S.C. 1101(a)(20) or who is a protected individual as defined by 8 U.S.C. 1324b(a)(3); or a U.S. national (i.e. includes citizens and non-citizens born in outlying possessions such as American Samoa and Swains Island), green card holders, refugees, and asylees. Working on a U.S. visa does NOT qualify as a U.S. person.

Below is the annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, the company offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: https://rewards.the company.com/us.

The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between:

$161,000—$221,000 USD

The the company Experience
  • Supporting Your Well-Being
  • Driving Social Impact
  • Developing Talent and Fostering Connection + Community

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboardin

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Identity Engineer
Staff Identity Engineer

Okta • Bellevue (WA)

On-site
USD 161,000 - 221,000
Staff Identity Governance and Access Engineer
Staff Identity Governance and Access Engineer

United States Digital Space LLC • Washington

On-site
USD 180,000 - 230,000
Staff Identity Engineer
Staff Identity Engineer

Triwill Group • Washington (IL), Northern (KY)

Hybrid
USD 161,000 - 221,000
Staff Software Engineer, Resiliency (Federal)
Staff Software Engineer, Resiliency (Federal)

United States Digital Space LLC • United States

Hybrid
USD 194,000 - 243,000
Equity
Bonus
Health benefits
Senior Identity Engineer
Senior Identity Engineer

Talanto • Boston (MA), Northern (KY)

Hybrid
USD 110,000 - 160,000
Manager, Engineering
Manager, Engineering

United States Digital Space LLC • United States

Hybrid
USD 150,000 - 210,000
Staff Fullstack Engineer
Staff Fullstack Engineer

United States Digital Space LLC • United States

Hybrid
USD 120,000 - 170,000
Software Engineer Manager, Okta Developer Foundation
Software Engineer Manager, Okta Developer Foundation

United States Digital Space LLC • United States

Hybrid
USD 140,000 - 190,000
Staff Identity Governance and Access Engineer
Staff Identity Governance and Access Engineer

Okta • Chicago (IL)

On-site
USD 180,000 - 240,000
Sr Manager, Engineering
Sr Manager, Engineering

United States Digital Space LLC • United States

Hybrid
USD 140,000 - 190,000
Well-being programs
Social impact initiatives
Talent development & community