Staff Security Risk & Compliance Program Manager - Access Management NEW

Confluent Inc

Town of Texas (WI)

On-site

USD 180,000 - 230,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Confluent Inc. is seeking a Staff Security Risk & Compliance Program Manager - Access Management to own the internal access program with a focus on machine and workload identity for the Confluent Cloud platform.

You will govern Access Management standards, metrics, and governance cadence, coordinating with engineering, platform, and identity teams to ensure least privilege and auditable controls across human and machine access.

Qualifications

  • 8+ years in security program management or related field.
  • Experience running an enterprise- or platform-scale access program.
  • Deep IAM concepts: least privilege, separation of duties, RBAC/ABAC, JIT, PAM, access review.
  • Knowledge of machine and workload identity and AI-agent access patterns.
  • Security engineering across GCP/AWS/Azure and cloud control planes.
  • Familiarity with identity platforms and access tooling (Okta, etc.).

Responsibilities

  • Define strategy and roadmap for Confluent's internal access management program, with focus on machine identity.
  • Lead enforcement of service-to-service authentication and non-human identities.
  • Own the Access Management Standard and related policies promoting least privilege and duties separation.
  • Define, track, and report access metrics; manage governance cadence for senior leadership.
  • Drive cross-functional delivery with engineering, platform, and identity teams without direct authority.
  • Ensure tight integration with GRC and partner functions across governance and operations.

Skills

Identity and access management
Security program management
Machine and workload identity
RBAC/ABAC
JIT/PAM
Cloud security
Okta
Kubernetes

Tools

Okta
JIT/access-orchestration
GRC tooling
Kubernetes

Job description

Staff Security Risk & Compliance Program Manager - Access Management

We are seeking a highly motivated and experienced Staff Security Risk & Compliance Program Manager - Access Management to join our Trust & Security team. This senior role owns Confluent's internal access management program and leads its evolution toward machine and workload identity — service-to-service (S2S) authentication, non-human identity (NHI), and access controls for AI agents — as the next frontier of least-privilege security for the Confluent Cloud platform.

You will be the horizontal owner of how Confluent governs access: the Access Management Standard, access metrics, and the executive reporting cadence. As access operations are distributed across partner functions, you will hold the policy, risk, and measurement line so Confluent maintains one coherent access posture rather than fragmented silos.

What You Will Do:

Strategy and Leadership: Own the strategic direction and roadmap for Confluent's internal access management program, with machine and workload identity as the durable center of gravity. Drive the program's maturity model from control-building toward sustained governance and least-privilege outcomes.

Machine & Workload Identity: Lead the program to enforce service-to-service (S2S) authentication across Trust & Security-owned surfaces, taking ownership of the enforcement hand-off from the identity engineering team. Formalize non-human identity (NHI) — service accounts, keys, and workload credentials — from pilot into a funded, governed program. Stand up access controls for AI agents as agentic workloads acquire production access.

Access Governance & Standards: Own the Access Management Standard and the policies that operationalize least privilege, separation of duties, and periodic access review across human and machine access. Ensure the standard keeps pace with the evolving access surface and remains audit-ready.

Metrics, Reporting & Governance Cadence: Own access metrics and reporting (e.g., JIT/unilateral-access volume, broad-privilege usage, prod-access reduction). Define and track program OKRs and run the monthly execution and executive-review cadence, articulating risk posture and progress to senior leadership.

Cross-Functional Execution & Transitions: Drive cross-functional delivery with engineering, platform, and identity teams without direct authority.

Integration with GRC and Partner Functions: Ensure the access management program is tightly integrated with adjacent GRC domains and partner teams (Insider Threat, IT/Identity, Detection & Response, and engineering owners), with clear RACI across governance and operations.

What You Will Bring:

Experience: 8+ years in security program management, identity & access management, or a closely related security discipline, with at least 3 years running an enterprise- or platform-scale access program in a technology company.

Technical Skills: Deep expertise in identity and access management concepts: least privilege, separation of duties, RBAC/ABAC, just-in-time (JIT) and privileged access management (PAM), and access review/certification.

Working knowledge of machine and workload identity — service-to-service authentication, non-human identity, service accounts, secrets/key management, and emerging AI-agent access patterns.

Strong security engineering fundamentals across cloud infrastructure security controls in GCP, AWS, and/or Azure, including Kubernetes and cloud control-plane access models.

Familiarity with identity platforms and access tooling (e.g., Okta, JIT/access‑orchestration tooling) and how access controls are enforced in production.

Tooling and Automation: Experience integrating access processes, controls, or findings into GRC and access-orchestration platforms, and a bias toward automating access decisions over manual operations.

Program Management Skills: Strong project management and organizational skills.

Exceptional analytical and problem-solving skills, with a data-driven approach to decision-making.

Experience running long‑term, complex security programs that deliver iterative, measurable risk reduction.

Communication and Collaboration Skills: Excellent written and verbal communication, with the ability to influence and lead without direct authority across engineering and security teams. Ability to articulate complex technical concepts and program status to executive-level audiences and technical teams alike.

We’re proud to be an equal opportunity workplace. Employment decisions are based on job‑related criteria, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other classification protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Access Management & Security Program Lead
Senior Access Management & Security Program Lead

Confluent • United States

Remote
USD 150,000 - 210,000
Security Access Governance Lead: S2S & AI Identities
Security Access Governance Lead: S2S & AI Identities

Confluent Inc • Town of Texas (WI)

On-site
USD 180,000 - 230,000
Confluent - Staff Security Engineer
Confluent - Staff Security Engineer

IBM • Boston (KY)

On-site
USD 150,000 - 210,000
Confluent - Staff Security Engineer
Confluent - Staff Security Engineer

IBM • Armonk (NY)

On-site
USD 170,000 - 230,000
Confluent - Staff Security Engineer
Confluent - Staff Security Engineer

IBM • Lowell (MA)

On-site
USD 150,000 - 230,000
Confluent - Staff Security Engineer
Confluent - Staff Security Engineer

IBM • Tucson (AZ)

On-site
USD 180,000 - 240,000
Confluent - Staff Security Engineer
Confluent - Staff Security Engineer

IBM • Rochester (MN)

On-site
USD 150,000 - 190,000
Confluent - Staff Security Engineer
Confluent - Staff Security Engineer

IBM • San Diego (CA)

On-site
USD 190,000 - 230,000
Confluent - Staff Security Engineer
Confluent - Staff Security Engineer

IBM • City of Poughkeepsie (NY)

On-site
USD 150,000 - 210,000
Senior Software Engineer II - Confluent, Product Security Access Management
Senior Software Engineer II - Confluent, Product Security Access Management

IBM • Boston (KY)

On-site
USD 140,000 - 190,000