SlipstreamJobsFresh Startup & VC-Backed Jobs

IT Security & Identity Engineer

Neuralink - Austin, TX, United States - In-office - posted 2026-09-25

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 99,000 - 185,000 / annual

Neuralink is seeking a hands-on IT Security & Identity Engineer to own identity, access, and endpoint security for the corporate environment supporting engineers, scientists, and clinicians working on brain-computer interface devices. You will be the technical owner of the identity provider, SSO federation, and lifecycle automation, driving endpoint protection, detection, and vulnerability management. This is a build-and-operate role: you will design controls, implement them in Terraform through GitLab, and run them in production with on-call responsibilities. Key responsibilities include: - Design, deploy, and operate identity and access management across Google Workspace, Microsoft Entra, and integrated SaaS applications; own SSO federation (SAML, OIDC, OAuth 2.0) and SCIM provisioning. - Manage identity infrastructure and access policy as code using Terraform and GitLab CI/CD. - Drive identity lifecycle automation from onboarding through offboarding, including RBAC, attribute-driven group membership, just-in-time access, and privilege reduction. - Design and operate strong authentication: phishing-resistant MFA (FIDO2/WebAuthn, passkeys, hardware tokens), certificate-based authentication (X.509, 802.1x), and device-trust conditions. - Own endpoint security posture across macOS, Windows, and Linux: EDR policy and operations, disk encryption, secure baselines, and compliance enforcement through MDM. - Build and maintain security logging and detection: centralize identity, endpoint, SaaS, and network logs; write detections for identity abuse and endpoint compromise. - Run enterprise vulnerability management: scanning, prioritization, remediation workflows, and evidence of closure. - Harden traditional IT services (email, file shares, directory services, collaboration tools, internal applications). - Partner with systems, network, and application owners to securely design and operate services on Tailscale and FortiGate-based networks. - Lead or support detection, triage, and incident response for the corporate IT environment; participate in IT on-call rotation. - Conduct regular access reviews and audits; produce evidence supporting HIPAA, PII handling, and SOC 2 compliance. - Drive scripting and automation (Python, Bash, PowerShell) for repeatable security tasks. - Recommend and implement improvements through change control processes. - Serve as the IAM and security subject matter expert for the IT team, providing technical guidance and mentoring. The ideal candidate has strong opinions grounded in experience, takes full ownership of systems, makes practical risk decisions without slowing the company down, and can explain security tradeoffs clearly to engineers and non-technical staff. REQUIREMENTS: - Bachelor's degree in computer science, cybersecurity, or another STEM discipline, OR 5+ years of professional experience in enterprise IT security engineering in lieu of a degree. - 5+ years of hands-on experience securing corporate IT environments (identity/MFA, endpoint security, logging and detection, vulnerability management, email or file services). - Demonstrated experience administering an enterprise IdP (Google Workspace, Microsoft Entra, or Okta) including SSO federation, SCIM provisioning, MFA enforcement, conditional access, and full user lifecycle management. - Strong working knowledge of IAM protocols and standards: SAML, OIDC, OAuth 2.0, SCIM. - Hands-on experience managing infrastructure or identity configuration with Terraform and Git-based workflows. - Experience administering or operating at least two of the following: enterprise EDR/AV, centralized logging or SIEM, enterprise vulnerability management platform, enterprise MDM. - Scripting proficiency in Python, Bash, or PowerShell for security automation and integrations. - Excellent communication skills with IT engineers and a diverse user base including non-technical scientists and clinicians; able to explain security tradeoffs and risk decisions clearly. PREFERRED QUALIFICATIONS: - Experience implementing phishing-resistant MFA at scale: FIDO2/WebAuthn, passkeys, hardware tokens, smart cards. - Certificate-based authentication and PKI operations: TLS, X.509, 802.1x, internal CA management. - Zero-trust architecture experience, including device trust, Tailscale or comparable mesh VPN, and identity-aware access. - Detection engineering experience: writing and tuning detections in Grafana/Loki, a SIEM, or comparable tooling. - Hardening Windows, macOS, and Linux endpoints and servers; securing file shares, email gateways, and internal applications. - Privileged access management, just-in-time access, and privilege-escalation reduction. - SOC or blue-team incident response experience on enterprise IT estates. - Configuration management with Ansible or similar; GitLab CI/CD pipelines. - Familiarity with NIST 800-53, CIS Controls, or ISO 27001 control families as implemented by IT security engineering. - Experience in regulated environments (HIPAA, SOC 2, or similar).

Similar roles