Staff Security Risk & Compliance Program Manager - Access Management
at Confluent
USD 222,100-261,000 per year
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 6
AWS @ 7
Audit
Azure @ 7
Communication @ 6
GCP @ 7
Kubernetes @ 7
Project Management @ 7
Reporting @ 6
Security @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Confluent is seeking an experienced security program manager to join its Trust & Security team. This senior role owns the internal access management program and leads its evolution toward machine and workload identity, including service-to-service authentication, non-human identity, and access controls for AI agents as part of least-privilege security for the Confluent Cloud platform.
The role is responsible for governing how Confluent manages access, including ownership of the Access Management Standard, access metrics, and executive reporting. Access operations are distributed across partner functions, so this position maintains the policy, risk, and measurement framework for a coherent access posture.
Responsibilities
- Own the strategic direction and roadmap for the internal access management program.
- Drive the program's maturity from control-building toward sustained governance and least-privilege outcomes.
- Lead enforcement of service-to-service authentication across Trust & Security-owned surfaces.
- Formalize non-human identity, including service accounts, keys, and workload credentials, from pilot to a funded and governed program.
- Establish access controls for AI agents as agentic workloads gain production access.
- Own the Access Management Standard and policies covering least privilege, separation of duties, and periodic access reviews for human and machine access.
- Ensure access standards remain current and audit-ready.
- Own access metrics and reporting, including just-in-time and unilateral-access volume, broad-privilege usage, and production-access reduction.
- Define and track program OKRs and lead monthly execution and executive-review cadences.
- Communicate risk posture and progress to senior leadership.
- Drive cross-functional delivery with engineering, platform, and identity teams without direct authority.
- Integrate the access management program with GRC domains and partner teams, including Insider Threat, IT/Identity, Detection & Response, and engineering owners.
- Establish clear RACI definitions across governance and operations.
Requirements
- 8+ years of experience in security program management, identity and access management, or a closely related security discipline.
- At least 3 years running an enterprise- or platform-scale access program in a technology company.
- Deep expertise in identity and access management concepts, including least privilege, separation of duties, RBAC/ABAC, just-in-time access, privileged access management, and access review or certification.
- Working knowledge of machine and workload identity, service-to-service authentication, non-human identity, service accounts, secrets and key management, and emerging AI-agent access patterns.
- Strong security engineering fundamentals across cloud infrastructure security controls in GCP, AWS, and/or Azure, including Kubernetes and cloud control-plane access models.
- Familiarity with identity platforms and access tooling such as Okta and just-in-time or access-orchestration tooling.
- Experience integrating access processes, controls, or findings into GRC and access-orchestration platforms.
- A preference for automating access decisions rather than relying on manual operations.
- Strong project management and organizational skills.
- Exceptional analytical and problem-solving skills with a data-driven approach to decision-making.
- Experience running long-term, complex security programs that deliver iterative and measurable risk reduction.
- Excellent written and verbal communication skills.
- Ability to influence and lead without direct authority across engineering and security teams.
- Ability to communicate complex technical concepts and program status to executive-level audiences and technical teams.
Additional Information
- Full-time, remote position.
- Confluent is an equal opportunity workplace.
- The compensation range is $222,100–$261,000 and includes equity eligibility. Actual pay may vary based on work history, education, professional experience, skills, qualifications, and work location.
- Confluent is an IBM subsidiary that has been acquired by IBM and will be integrated into the IBM organization.
More jobs at Confluent
Senior Manager, Detection & Response (Security Engineering)
Confluent · United States
USD 241,700-319,000 per year
Staff Software Engineer
Confluent · Mountain View, United States, New York City, United States
USD 235,700-277,000 per year
Distributed Systems Software Engineer - WarpStream
Confluent · United States
USD 197,400-271,200 per year
Senior Software Engineer - Streaming AI
Confluent · Canada
CAD 144,200-169,400 per year
Staff Software Engineer I
Confluent · United States
USD 261,300-307,000 per year
Similar jobs
Sr. Security Engineer - GRC Fintech & Financial Services
SpaceXAI · Washington, United States, New York City, United States, Palo Alto, United States
USD 152,000-258,000 per year
Senior Security Engineer - GRC Frameworks & AI Governance
SpaceXAI · Washington, United States, New York City, United States, Palo Alto, United States
USD 152,000-258,000 per year
Senior Field Engineer
Teleport · United States
USD 173,700-235,000 per year
Security Engineer, Detection and Response
OpenAI · San Francisco, United States, New York City, United States, Seattle, United States, United States
USD 293,000-385,000 per year
Software Engineer, Infrastructure Security
OpenAI · United States, San Francisco, United States, New York City, United States, Seattle, United States
USD 230,000-385,000 per year
Staff Engineer, Datacenter Server Lifecycle
Anthropic · San Francisco, United States, New York City, United States, Seattle, United States
USD 320,000-405,000 per year
Member of Technical Staff (Offensive Security Engineer)
Perplexity AI · Serbia, New York City, United States, United States, San Francisco, United States, London, United Kingdom
USD 220,000-405,000 per year
Technical Program Manager, Infrastructure
Anthropic · San Francisco, United States, New York City, United States, Seattle, United States
USD 290,000-365,000 per year