- Job type
- Full-time
- Work mode
- On-site
- Level
- Senior
- Department
- Information Technology
- Experience
- Not listed
- Posted
- Sep 28, 2026
About the role
The Role
As our Senior Identity Engineer, you will own workforce and workload identity end-to-end — SSO, MFA, the joiner-mover-leaver lifecycle, privileged access, secrets, and service/machine identity — across corporate, cloud, and factory systems that handle export-controlled technical data. You will build an automation-first, least-privilege identity program that shrinks our largest attack surface while keeping engineers fast. This is a hands-on individual-contributor role on a small, high-leverage security team in Los Angeles.
What You’ll Do
- Design, implement, and operate our IdP stack (e.g., Okta, Entra, Google Workspace, Auth0, or Zitadel) — SSO, SCIM provisioning, and phishing-resistant MFA — and build the systems around it.
- Build identity systems at scale that put OAuth 2.0 / OIDC / SAML and modern authorization models (RBAC and relationship-based access control) to work in production.
- Own cloud identity end-to-end — Azure service principals, AWS IAM, and workload/service identity — and tie those identities cleanly to the underlying infrastructure.
- Work cross-functionally to help other teams meet their identity needs, and automate the access lifecycle (joiner-mover-leaver) and reviews.
- Partner with Detection & Response and Compliance/FSO so identity telemetry is detectable, actionable, and audit-ready.
What We’re Looking For
- You can build. Strong software engineering fundamentals and a track record of shipping identity systems at scale — not just configuring a vendor tool or leaning on AI-assisted coding.
- Real command of core identity concepts — OAuth 2.0 flows, OIDC, SAML, RBAC, and relationship-based access control (ReBAC) — and the ability to design systems that exploit these protocols well.
- Hands-on depth with one or more IdPs (Okta / Entra / Google Workspace / Auth0 / Zitadel), since day-to-day is implementing, designing, and integrating these platforms.
- Cloud identity depth — Azure service principals, AWS IAM — and a clear grasp of how those identities map to real infrastructure.
- The autonomy and urgency to own the identity domain end-to-end on a small, high-leverage team with minimal direction.
What Will Set You Apart
- Fine-grained authorization at scale (ReBAC with OpenFGA / Zanzibar-style systems) built and run in production.
- Identity engineering for OT/manufacturing or other regulated, controlled environments.
- Large-scale passkey/FIDO2 or PAM (CyberArk/Teleport) rollouts, and secrets management with HashiCorp Vault.
- Experience building on a small, high-automation team where output-per-engineer is the measure; detection-engineering and ITAR-aware access design.
ITAR Requirements
To conform to U.S. Government export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen or national, lawful permanent resident, protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.