About The Position

Moveworks is seeking a Senior Identity & Access Management Engineer to shape the future of their identity and access strategy. This role involves hands-on technical development, coding, designing, building, and scaling IAM solutions across cloud infrastructure, SaaS applications, and internal systems. The engineer will own IAM initiatives end-to-end, from defining requirements to architecting and implementing secure, automated solutions. Key responsibilities include developing access models for AWS, Azure, Kubernetes, and other platforms, reducing privilege sprawl, enhancing observability through logging and SIEM integration, modernizing access reviews, and continuously de-risking IAM threats. The work directly protects critical systems while enabling engineers to operate efficiently and safely.

Requirements

  • 5+ years of experience working in IAM, security engineering, or platform engineering with substantial IAM responsibilities in production environments.
  • Strong grasp of IAM best practices and common failure modes (e.g., least privilege, privilege escalation paths, separation of duties, breakglass, auditability).
  • Practical experience implementing and designing access control in AWS, Azure, GCP environments and partnering with teams who manage infrastructure at scale.
  • Experience with Okta administration and patterns (e.g., groups, app assignments, lifecycle/provisioning), or equivalent experience with a similar SSO product.
  • Ability to spot dangerous permissions and misuse paths (including insider-threat scenarios), assess risk, and identify suitable mitigations and controls.
  • Comfortable using scripting languages and AI coding tools to build reliable automation, and able to read/validate what the code is doing.
  • Working understanding of OAuth, OIDC, SAML, and SCIM, including when to use which, failure modes, and common pitfalls.
  • Proven ability to build long-lasting relationships with various technical teams, such as Engineering, Information Technology, Infrastructure, and DevOps teams.
  • BS+ in computer science or a related field, or equivalent relevant experience.

Nice To Haves

  • Experience configuring IAM in Teleport, Terraform and Kubernetes environments is a plus.

Responsibilities

  • Be the technical developer to drive IAM application development: Code, design, and implement solutions with extensive knowledge in AWS, Azure, Teleport, and Terraform. Enabling robust and reliable solutions to keep our engineering teams active.
  • Drive IAM projects end-to-end: Take ambiguous access problems, understand and have the ability to define requirements, architect solutions, and own the rollout/operationalization (not just the design).
  • Develop with secure access models in mind: Continuously develop role design improvements and access assignment patterns across AWS, Kubernetes, SaaS apps, and internal systems to reduce unnecessary privileges, minimize manual grants, and create scalable “safe baseline” access that covers routine work without daily elevation.
  • Develop on operationalizing logging and metrics: Ensure access changes are observable in our Security Information and Event Management (SIEM) tool; build repeatable reporting that surfaces risky access and drift.
  • Run and improve user access reviews (UAR): Develop, execute and design a UAR process & solution that meets compliance requirements while improving real security signal—minimizing approver burden through scoping, automation, and clear decision support.
  • Develop technology to continuously de-risk: Identify high-risk permissions and misuse paths, propose appropriate controls and mitigations, drive adoption with partner teams, and develop solutions to continuously de-risk.
  • Operate with strong security judgment and high signal: Reliably distinguish meaningful IAM risk from noise, gather context efficiently, and escalate with crisp rationale and actionable mitigations.
  • Document and standardize the paved road: Write lightweight procedures, runbooks, and automation so access decisions are consistent, scalable, and not dependent on tribal knowledge.

Benefits

  • ServiceNow is an equal opportunity employer.
  • Accommodations are available for candidates requiring reasonable accommodation.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service