Staff Security Risk & Compliance Program Manager - Access Management

USD 222,100-261,000 per year
SENIOR
✅ Remote

Tech Stack

AI @ 6 AWS @ 7 Audit Azure @ 7 Communication @ 6 GCP @ 7 Kubernetes @ 7 Project Management @ 7 Reporting @ 6 Security @ 6

Details

Confluent is seeking an experienced security program manager to join its Trust & Security team. This senior role owns the internal access management program and leads its evolution toward machine and workload identity, including service-to-service authentication, non-human identity, and access controls for AI agents as part of least-privilege security for the Confluent Cloud platform.

The role is responsible for governing how Confluent manages access, including ownership of the Access Management Standard, access metrics, and executive reporting. Access operations are distributed across partner functions, so this position maintains the policy, risk, and measurement framework for a coherent access posture.

Responsibilities

  • Own the strategic direction and roadmap for the internal access management program.
  • Drive the program's maturity from control-building toward sustained governance and least-privilege outcomes.
  • Lead enforcement of service-to-service authentication across Trust & Security-owned surfaces.
  • Formalize non-human identity, including service accounts, keys, and workload credentials, from pilot to a funded and governed program.
  • Establish access controls for AI agents as agentic workloads gain production access.
  • Own the Access Management Standard and policies covering least privilege, separation of duties, and periodic access reviews for human and machine access.
  • Ensure access standards remain current and audit-ready.
  • Own access metrics and reporting, including just-in-time and unilateral-access volume, broad-privilege usage, and production-access reduction.
  • Define and track program OKRs and lead monthly execution and executive-review cadences.
  • Communicate risk posture and progress to senior leadership.
  • Drive cross-functional delivery with engineering, platform, and identity teams without direct authority.
  • Integrate the access management program with GRC domains and partner teams, including Insider Threat, IT/Identity, Detection & Response, and engineering owners.
  • Establish clear RACI definitions across governance and operations.

Requirements

  • 8+ years of experience in security program management, identity and access management, or a closely related security discipline.
  • At least 3 years running an enterprise- or platform-scale access program in a technology company.
  • Deep expertise in identity and access management concepts, including least privilege, separation of duties, RBAC/ABAC, just-in-time access, privileged access management, and access review or certification.
  • Working knowledge of machine and workload identity, service-to-service authentication, non-human identity, service accounts, secrets and key management, and emerging AI-agent access patterns.
  • Strong security engineering fundamentals across cloud infrastructure security controls in GCP, AWS, and/or Azure, including Kubernetes and cloud control-plane access models.
  • Familiarity with identity platforms and access tooling such as Okta and just-in-time or access-orchestration tooling.
  • Experience integrating access processes, controls, or findings into GRC and access-orchestration platforms.
  • A preference for automating access decisions rather than relying on manual operations.
  • Strong project management and organizational skills.
  • Exceptional analytical and problem-solving skills with a data-driven approach to decision-making.
  • Experience running long-term, complex security programs that deliver iterative and measurable risk reduction.
  • Excellent written and verbal communication skills.
  • Ability to influence and lead without direct authority across engineering and security teams.
  • Ability to communicate complex technical concepts and program status to executive-level audiences and technical teams.

Additional Information

  • Full-time, remote position.
  • Confluent is an equal opportunity workplace.
  • The compensation range is $222,100–$261,000 and includes equity eligibility. Actual pay may vary based on work history, education, professional experience, skills, qualifications, and work location.
  • Confluent is an IBM subsidiary that has been acquired by IBM and will be integrated into the IBM organization.

More jobs at Confluent

Similar jobs