Unknown Company

IAM Security Engineer

denver, co • Posted 2 days ago
Onsite Full Time IT & Technology

- Central identity federated to the priority downstream systems through a canonical role model, with automated provisioning and end-to-end audit in place.

- Baseline continuous vulnerability scanning live across edge nodes and containers, with risk-scored findings flowing to the event bus.

- The edge security-telemetry pipeline designed and piloted on a representative node set — local visibility layer collecting and forwarding to the SIEM, with store-and-forward proven.

By the second half of the engagement

- Just-in-time elevation, the central policy engine, and access recertification running in production; standing administrative access eliminated.

- Agent workload identity, tool-invocation authorization, delegation, and human-approval workflows operational for sensitive actions.

- Vulnerability coverage extended across the full fleet, and identity-correlated SIEM detections live — every alert resolving to a verifiable principal.

- Documentation, runbooks, and standards handed over so the platform remains fully operable beyond the engagement.

Required qualifications

- (8+) years in security engineering, including (3+) years architecting identity and access management at scale.

- Deep, hands-on identity federation: enterprise identity providers, OIDC, SAML, standards-based provisioning, and mapping federated identity into downstream systems' native authorization models.

- Strong command of OAuth2/OIDC internals — scopes, audiences, token exchange, audience restriction — and common failure modes such as confused-deputy and token passthrough.

- Demonstrated implementation of an authorization policy model (RBAC plus at least one of ABAC / ReBAC) using an externalized policy engine.

- Cloud IAM depth and centralized secrets management, including automated rotation.

- Container-orchestration and container security fundamentals; able to deliver production-quality code — this role builds, not only advises.

- A track record of shipping least-privilege, just-in-time, and fully auditable access systems.

Preferred qualifications

- Securing AI agents / LLM-based systems and automated tool-invocation interfaces; prompt-injection and tool-boundary threat modeling.

- Workload identity frameworks and machine-to-machine credentialing.

- Security telemetry pipelines and SIEM integration at scale — collection, normalization, retention, and detection/correlation engineering.

- Vulnerability-management program delivery — continuous scanning, SBOM tooling, CVE correlation, and risk-based prioritization.

- Security observability on edge, IoT, or intermittently connected devices — lightweight host-based telemetry agents, store-and-forward under constrained bandwidth, and tamper-evident delivery.

- Zero-trust infrastructure access architectures; PKI, certificate lifecycle, mutual TLS, and device attestation.

- Event-driven platform security and secure CI/CD (artifact signing, infrastructure-as-code scanning, automated security gates).

- Relevant security-architecture certifications (advantageous, not required).

#J-18808-Ljbffr

IAM Security Engineer in denver at Unknown Company

This position is listed as full time and onsite.

Back to Job Search