SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 180,000 - 220,000 / annual
HackerOne is a global leader in Continuous Threat Exposure Management (CTEM), combining AI-powered solutions with the world's largest security researcher community to discover, validate, prioritize, and remediate exposures across code, cloud, and AI systems. The company is trusted by industry leaders including Anthropic, Goldman Sachs, Uber, and the U.S. Department of Defense.
As a Senior Security Engineer in Identity and Access Management, you will own the complete identity lifecycle—from onboarding and creation through change and removal—for people, service accounts, and AI agents. You will design and deliver access models and the automation behind them, ensuring identities can access only the right data, at the right time, in the right way.
Key responsibilities include:
- Owning the identity lifecycle end-to-end, building automation that grants entitlements based on legitimate need and removes them seamlessly
- Designing access models on top of data classification so access follows from data sensitivity rather than who requested it
- Making time-bound access the default for critical data, embedding the secure path as the easy path
- Engineering identity as code, keeping provisioning logic, entitlement policy, and access review rules in version control and under test across systems like Okta, Lumos, and AWS IAM
- Building AI and LLM-powered tooling for continuous access review and entitlement anomaly detection, deciding where AI can carry access decisions autonomously versus where human sign-off is required
- Bringing non-human identities (service accounts, workload identities, integrations, AI agents) under the same discipline as human identities, with owners, purposes, and expiry dates
- Continuously measuring access and reporting opportunities to reduce unnecessary entitlements using data-driven decision-making
- Partnering with Engineering, Enterprise IT, and Compliance to embed identity controls, and supporting detection and incident response as the identity responder
This is a remote role targeted for candidates within ~50 miles of Austin TX, Seattle WA, Washington DC, San Francisco CA, or Boston MA, or within commuting distance of London or Netherlands locations. HackerOne embraces a flexible work approach that balances remote work with occasional in-person collaboration.
Minimum Qualifications:
- 5+ years of experience in identity and access management, security engineering, or software engineering with substantial ownership of identity systems
- Hands-on experience operating an enterprise identity provider such as Okta, including SAML, OIDC, SCIM, and lifecycle automation
- Experience managing identity across an enterprise SaaS estate (e.g., Google Workspace, Salesforce, Workday), including SCIM provisioning and group-driven entitlements
- Experience with cloud IAM, ideally AWS, including policy design and short-lived credentials
- Strong software engineering fundamentals with proficiency in Python, Go, or similar language, and hands-on use of AI and LLM tooling and agentic coding tools in production engineering work
Preferred Qualifications:
- Identity work in regulated sectors (financial services, healthcare, government) with audit evidence production against PCI DSS, HIPAA, SOC 2, or ISO 27001
- Managing identity infrastructure as code and access governance tooling (e.g., Terraform, Lumos)
- Mobile device management (MDM) alongside identity (e.g., Kandji with Okta)
- Non-human, workload, and privileged access management (secrets, short-lived credentials, service-to-service authentication)
- Building AI or LLM-powered tooling for security or identity workflows
- Detection and incident response for identity-centered incidents (credential compromise, session abuse, entitlement misuse)
- Industry certifications: IDPro CIDPRO, Okta certifications, AWS Certified Security – Specialty, or CISSP