Skip to main content
Aledade PBC

Staff Security Engineer - IAM

RemoteUnited States only
Published
Role
Security
Experience
Staff
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Staff-level security engineer for IAM with 8+ years in software or security engineering in cloud-native environments. Needs deep cloud IAM architecture, identity protocols, Terraform or CloudFormation, and Python or PowerShell. Austin, TX job location.

Core skills

Terraform/CloudFormationIAMCloud IAM

Required skills

AWS IAM/Azure Entra ID/GCP IAMRBACABACSAMLOIDCOAuthLDAPSSOMFAPython/PowerShell

Optional skills

AWSAzureGCPCI/CDJavaPythonScalaC#

What you'll do

  • Lead the development, implementation, and ongoing maintenance of comprehensive security strategies and solutions.
  • Design and deploy advanced identity security controls to safeguards networks, systems, and applications.
  • Work across disciplines to shape our security services strategy and execution.
  • Set and uphold the standard for security processes to support high-quality engineering.
  • Mentor and galvanize new engineers to do their best work.
  • Design secure, scalable, and automated solutions for managing service accounts, machine identities, secrets, certificates, APIs, and cloud-native workloads.

What they require

  • BS/BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field.
  • 8+ years of experience in software or security engineering within Cloud Native environments.
  • Cloud IAM Architecture: Deep knowledge of cloud security architectures (AWS IAM, Azure Entra ID, or GCP IAM), including designing/enforcing least-privilege roles, RBAC/ABAC, and permission policies.
  • Identity Protocols & Governance: Proficiency in identity standards and federation protocols (SAML, OIDC, OAuth, LDAP/Directory Services), user lifecycle automation, SSO, MFA, and Just-In-Time (JIT) access.
  • Automation & IaC: Strong hands-on proficiency with Infrastructure as Code (Terraform or CloudFormation) and scripting (Python or PowerShell) to automate identity provisioning, drift detection, and access workflows.
  • Non-Human Identity (NHI) Fundamentals: Practical experience managing service accounts, API keys, bots, and automated workload identities across cloud infrastructure.
  • Preferred: Experience architecting, developing, and deploying large-scale distributed systems at scale.
  • Preferred: Experience with cloud technologies, e.g., AWS, Azure, GCP.
  • Preferred: Experience building continuous integration and continuous development (CI/CD) pipelines.
  • Preferred: Familiarity with server-side web technologies (eg: Java, Python, Scala, C#, C++, Go).
  • Preferred: 4+ years of experience acting as a trusted technical decision-maker in a team setting, solving for short-term and long-term business value.
  • Preferred: Experience with health-tech systems, like Electronic Health Records, Clinical data, etc.
  • AI Identity & Access Management.
  • NHI Architecture: Design secure, scalable, and automated solutions for managing service accounts, machine identities, secrets, certificates, APIs, and cloud-native workloads.
  • AI/ML Security & Threat Modeling: Hands-on experience with AI/ML tools (e.g., Gemini, Claude, AWS Bedrock), conducting threat modeling for AI systems, or managing automated permission guardrails for AI agents.
  • AI/ML Security & Threat Modeling: Hands-on experience with AI/ML tools (e.g., Gemini, Claude, AWS Bedrock), conducting threat modeling for AI systems, or managing automated permission guardrails for AI agents.
  • Preferred: Familiarity with SPIFFE/SPIRE, zero-trust network architectures, or complex containerized identity frameworks.
  • Preferred: Experience orchestrating VPC flow logs and audit feeds into security analytics tools (e.g., Crowdstrike, Sumo Logic, Wiz, Zscaler).
  • Preferred: Experience with health-tech systems, clinical data environments (EHRs), and regulatory standards (HIPAA, SOC 2, ISO 27001).
  • Preferred: CISSP, OSCP, CEH, Certified AI Security Specialist (CAISS), or GIAC Machine Learning Security Engineer (GMSE).
  • Sitting for prolonged periods of time.
  • Extensive use of computers and keyboard.
  • Occasional walking and lifting may be required.

Benefits

  • Flexible work schedules and the ability to work remotely are available for many roles.
  • Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners.
  • Robust time-off plan (21 days of PTO in your first year).
  • Two paid volunteer days and 11 paid holidays.
  • 12 weeks paid parental leave for all new parents.
  • Six weeks paid sabbatical after six years of service.
  • Educational Assistant Program and Clinical Employee Reimbursement Program.
  • 401(k) with up to 4% match.
  • Stock options.
  • And much more!

Aledade PBC

Aledade PBC, a public benefit corporation, exists to empower independent primary care through value-based care contracts and support for practices, health centers and clinics.

Healthcare
Salary not disclosed