Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
API @ 4
AWS @ 6
Audit @ 4
Change Management @ 4
ChatGPT @ 6
Claude Code @ 4
Compliance @ 4
GCP @ 6
GCP Cloud Run @ 6
IaC
Observability
Python @ 6
Security
Terraform @ 7
iPaaS
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
The Corporate Security Identity Team is transforming how the workforce securely accesses tools, advancing from foundational controls to automated governance across identity platforms and emerging AI tooling.
As a Staff Security Engineer, you will serve as a senior technical leader and strategic anchor for complex identity challenges. You will architect enterprise-scale access solutions, codify identity platform configuration, build governance frameworks for AI agents and non-human identities, own critical systems, write technical proposals, contribute to design and code reviews, and lead cross-functional initiatives across Security, IT, Engineering, Compliance, and People teams.
Configuration is being migrated from click-ops and low-code platforms to peer-reviewed code, with automation implemented as tested Python services running on GCP Cloud Run.
Responsibilities
- Design comprehensive identity and AI access solutions, including AI agent governance frameworks and privileged access workflows using just-in-time provisioning.
- Replace low-code automation by migrating existing iPaaS automation to modular Python services on GCP Cloud Run with source control, tests, CI, and observability.
- Codify Okta, Lumos, and non-human identity platforms using Terraform, OpenTofu, or Pulumi.
- Lead the migration from click-ops to peer-reviewed infrastructure as code, focusing on global critical policies.
- Re-architect identity and access across GCP and AWS organizations, including resource hierarchy design, organization policies, service control policies, permission boundaries, workload identity federation, and least-privilege access for human and workload identities.
- Lead identity and access engineering for enterprise AI platforms, including administration, SSO and SCIM integration, audit logging, data controls, and policy enforcement for Claude Web, Claude Code, Cowork, and adjacent tools.
- Design monitoring and management solutions for service accounts, API keys, certificates, AI agents, and MCP integrations.
- Lead deployment, integration, and operationalization of the non-human identity platform across the SaaS estate.
- Drive cross-functional initiatives by translating ambiguous business requirements into actionable technical specifications.
- Mentor senior and intermediate engineers on technical implementation and modern identity and AI security practices.
Requirements
- Extensive experience designing and implementing enterprise-scale IAM solutions, with demonstrated Staff-level or senior individual contributor experience.
- Expert-level Okta experience, including Identity Engine, advanced authentication policies, lifecycle workflows, and API automation.
- Strong infrastructure-as-code experience with Terraform, OpenTofu, or Pulumi, including SaaS identity platform providers and migrations from click-ops to code.
- Proficiency writing and shipping modular, tested, code-reviewed Python services deployed on GCP Cloud Run or an equivalent serverless runtime and instrumented for failure.
- Cloud identity expertise in GCP and/or AWS, including resource hierarchy and organization design, IAM policy models, workload identity federation, organization policies, service control policies, and permission boundaries.
- Hands-on experience administering or governing enterprise AI platforms. Anthropic Claude is preferred; OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or similar platforms are acceptable.
- Awareness of AI-specific risks, including prompt injection, MCP attack surfaces, agent identity, and data leakage.
- Daily experience building with AI tooling such as Claude Code, Cursor, or similar agentic tools, with the ability to help the team adapt as the tooling evolves.
- Experience with IGA platforms such as Lumos, ConductorOne, or similar platforms, preferably managed declaratively.
- Experience in regulated environments and knowledge of compliance frameworks including FedRAMP, SOC 2, and SOX, as well as change management, evidence collection, and audit support.
Nice-to-have Qualifications
- Passion for emerging identity challenges, including AI agent governance, non-human identity management, zero-trust architecture, and behavioral analytics.
- Experience carrying a cloud organization restructuring through completion, including migration and stakeholder management.
Benefits
- Benefits supporting health, finances, and well-being.
- Flexible paid time off.
- Team member resource groups.
- Equity compensation and employee stock purchase plan.
- Growth and development fund.
- Parental leave.
- GitLab is an equal opportunity workplace and supports accommodations during the recruiting process.
Compensation
The United States base salary range for this role is $168,000–$238,000 USD. The range applies to United States residents and excludes bonuses, equity, and benefits.