Jobs

Senior+ IAM Engineer

Verkada

Apply on Greenhouse
Location
San Mateo, CA United States
Level
Senior
Posted
September 18, 2026
Source
Greenhouse

Job description

About the Role

As a Senior IAM Engineer on the Security team, you will set the standard for identity and access across Verkada, owning how access is defined, granted, reviewed, and revoked throughout our infrastructure. From codifying identity boundaries in Terraform and Rego to driving least privilege across AWS roles and policies on zero trust principles, your work will turn access management from a manual ticket queue into a self-service system powered by scripts and agentic workflows.

What You'll Do

  • Manage identity and access infrastructure as code in Terraform, with peer-reviewed change control, drift detection, and policy-as-code.
  • Advance zero trust controls for engineering access: short-lived credentials, just-in-time elevation, and the elimination of standing privilege.
  • Own the access lifecycle for both human and non-human identities: joiner/mover/leaver flows, service accounts, and agents.
  • Operate access review and certification workflows that produce audit evidence.
  • Write tools to surface over-permissioned identities, unused credentials, and policy drift; then drive remediation to completion.
  • Build agentic workflows on a low-code orchestration platform to automate access requests, approvals, risk scoring, and access review campaigns.
  • Partner with security, infrastructure, and product engineering teams so that the secure path is the easy path, and consult on IAM design for new services.

What You'll Need

  • Bachelor of Science in Computer Science degree or equivalent practical experience
  • 3+ years working hands-on with identity and access management in a cloud-native engineering environment
  • Deep AWS IAM expertise: policy evaluation logic, permission boundaries, assume-role patterns, SCPs, and the ways they fail in practice and how to express them in Terraform
  • Fluency with identity protocols and access models (SAML, OIDC, OAuth 2.0, SCIM; RBAC, ABAC, or policy-based access), plus working knowledge of Okta administration and APIs: SSO, provisioning, group rules, and authentication policies
  • Ability to build automation for your own work, using either scripting or low-code/no-code orchestration platforms, including LLM or agent-driven steps
  • Excellent written and verbal communication skills — you can explain an access decision to an engineer, an auditor, and an executive

Estimated Annual Pay Range

$200,000 — $300,000 USD

Similar roles

Get roles like this in your inbox

New agentic AI jobs, curated every Thursday. No spam.

Apply on Greenhouse