Senior Security Engineer, Identity and Access Management

HackerOne

2h ago • 1 views • 0 applications
Full-time Remote
Seattle
$180,000 - $220,000
Full-time
Security Engineer

Job Description

Senior Security Engineer, Identity and Access Management

Are you a visionary Senior Security Engineer ready to redefine Identity and Access Management (IAM) in the age of AI?
HackerOne, a global leader in Continuous Threat Exposure Management (CTEM), is at the forefront of combining human ingenuity
with agentic AI to safeguard the world’s digital ecosystems. We're trusted by industry giants like Anthropic, Crypto.com,
General Motors, and the U.S. Department of Defense to protect their most sensitive data.

At HackerOne, offensive security isn't just an option—it's the standard. We’re pioneering an AI-first approach to
IAM, focusing on engineering robust solutions, not just administration. If you're passionate about designing and
delivering cutting-edge access models and automation that ensure the right people and systems have the right access,
at the right time, in the right way, then this role is for you.

About HackerOne

HackerOne unites agentic AI solutions with the world’s largest community of security researchers to continuously discover,
validate, prioritize, and remediate exposures across code, cloud, and AI systems. Through innovative solutions like bug bounty,
vulnerability disclosure, agentic pentesting, AI red teaming, and code security, we deliver measurable, continuous reduction
of cyber risk for leading enterprises globally. Recognized in Gartner’s Emerging Tech Impact Radar for AI Security Testing
and named a Most Loved Workplace for Young Professionals (2024), we are building trust and resilience in a world where
AI-driven innovation and adversaries move faster than ever.

Our Values

Customer Obsessed: We prioritize customer outcomes in every decision and action.
Default to Disclosure: We operate with transparency and integrity, fostering trust and accountability.
Win Together: We empower employees, researchers, customers, and partners through inclusion, respect, and accountability.

The Opportunity: Senior Security Engineer, Identity and Access Management

Location: Remote (within ~50 miles of Austin TX, Seattle WA, Washington DC, San Francisco CA, or Boston MA, or within commuting distance of our London or Netherlands locations)

Targeted Hubs: Seattle, WA or Washington, DC

As a Senior Security Engineer specializing in Identity and Access Management, you will be pivotal in shaping how HackerOne protects the sensitive vulnerability data entrusted to us by our customers. We are building a truly AI-first IAM capability, where your expertise will drive the engineering behind access models and automation. You'll master the full identity lifecycle, from onboarding to removal, for human users, service accounts, and AI agents alike. Your work will directly enable a small team to achieve massive scale by embedding automation, intelligence, and AI into every aspect of access, striving for least privilege for humans and least agency for AI.

What You Will Do
In this role, you will:

Own the Identity Lifecycle: End-to-end management of the identity lifecycle for people, service accounts, and AI agents, building automation that grants entitlements based on legitimate need and removes them seamlessly.
Design Intelligent Access Models: Develop sophisticated access models leveraging data classification, ensuring access follows data sensitivity rather than arbitrary requests.
Champion Time-Bound Access: Implement time-bound access as the default for critical data, making the secure path the easiest and most intuitive.
Engineer Identity as Code: Practice First Principles Problem Solving by managing provisioning logic, entitlement policy, and access review rules in version control. Apply rigorous testing across systems like Okta, Lumos, and AWS IAM, moving beyond manual console configurations.
Pioneer AI-Powered IAM: Build AI and LLM-powered tooling to enable continuous access review and entitlement anomaly detection. Embed AI First practices to surface unusual patterns in real-time, determining where AI can make autonomous access decisions and where human oversight is required.
Standardize Non-Human Identity Management: Bring service accounts, workload identities, integrations, and AI agents under the same rigorous discipline as human identities, ensuring each has an owner, purpose, and expiry by default.
Drive Data-Driven Optimization: Continuously measure access and identify opportunities to reduce unnecessary entitlements, using Data-Driven Decision Making to prioritize impactful reductions.
Collaborate and Respond: Partner with Engineering, Enterprise IT, and Compliance to embed identity controls into their systems. Act as the primary identity responder for detection and incident response, containing access, reconstructing identity actions, and contributing to blameless retrospectives, demonstrating Change Agility as threats and tooling evolve.

Minimum Qualifications

5+ years of experience in identity and access management, security engineering, or software engineering with substantial ownership of identity systems.
Hands-on experience operating an enterprise identity provider such as Okta, including SAML, OIDC, SCIM, and lifecycle automation.
Experience managing identity across an enterprise SaaS estate (e.g., Google Workspace, Salesforce, Workday), including SCIM provisioning and group-driven entitlements.
Experience with cloud IAM, ideally AWS, including policy design and short-lived credentials.
Strong software engineering fundamentals with proficiency in Python, Go, or a similar language, and hands-on use of AI, LLM tooling, and agentic coding tools in production engineering work.

Preferred Qualifications

Identity work in a regulated sector such as financial services, healthcare, or government, including producing access control evidence for audits (PCI DSS, HIPAA, SOC 2, ISO 27001).
Managing identity infrastructure as code, and access request or governance tooling (e.g., Terraform, Lumos).
Experience with Mobile Device Management (MDM) integrated with identity (e.g., Kandji with Okta): device trust policies, platform SSO, and endpoint enrollment.
Expertise in non-human, workload, and privileged access: secrets management, short-lived credentials, and service-to-service authentication.
Building AI or LLM-powered tooling for security or identity workflows.
Experience with detection and incident response for identity-centered incidents (credential compromise, session abuse, entitlement misuse).
Industry certifications in identity or security, such as IDPro CIDPRO, Okta certifications, AWS Certified Security – Specialty, or CISSP.

Compensation

Seattle or Washington DC: $180K – $220K

Offers Equity Options

View our Compensation Tier Guide

Benefits

Health (medical, vision, dental), life, and disability insurance*
Equity stock options
Retirement plans
Paid public holidays and unlimited PTO
Paid maternity and parental leave
Leaves of absence (including caregiver leave and leave under CO's Healthy Families and Workplaces Act)
Employee Assistance Program

*Eligibility may differ by country

We embrace a Flexible Work approach that gives us the freedom to do our best work while fostering strong connections and community. For certain roles outside the United States, India, the U.K., and the Netherlands, we partner with
Remote.com as our Employer of Record (EOR).

Visa/work permit sponsorship is not available for this role.
Employment at HackerOne is contingent on a background check.

HackerOne is an Equal Opportunity Employer and is committed to creating an inclusive environment for all employees and applicants.
We make hiring decisions based solely on qualifications, merit, and business needs. Pursuant to the San Francisco Fair Chance Ordinance,
all qualified applicants with arrest and conviction records will be considered for the position.