Senior Identity Management Engineer

Aurora InnovationSan Francisco, CA
Hybrid

About The Position

Aurora is seeking a hands-on IAM Engineer to support the technical execution of its modern identity ecosystem. The role involves implementing newly licensed tools (Conductor One and Ping Directory) and working closely with the IAM Architect. The position focuses on owning the full IAM lifecycle, evolving existing infrastructure into a scalable, modern ecosystem based on Zero Trust principles, SPIRE, Open Policy Agent (OPA), and a custom-built group management engine. The goal is to create a competitive advantage for operations.

Requirements

  • 4+ years in Information Security, with at least 2 years specifically focused on implementing IAM solutions in large enterprise environments.
  • Expert-level knowledge of at least one major Cloud Identity Provider (AWS IAM, Azure) and core protocols including SAML, OAuth 2.0, OIDC, SCIM, and LDAP.
  • Deep understanding of Zero Trust principles and access models such as RBAC, ABAC, and PBAC.
  • Bachelor’s or Master’s degree in Computer Science, IT, or equivalent practical experience.
  • Ability to develop code in either Python or Go.

Nice To Haves

  • Experience with integration patterns with IdPs such as Okta, Auth0 or Microsoft Entra ID.
  • Experience with Conductor One, SailPoint, Saviynt or similar platforms.
  • Hands-on experience with Ping Directory or similar LDAP solutions. Including monitoring for performance and fine-tuning CPU, Memory and Storage.
  • Understanding of AWS cloud infrastructure and security concepts.
  • Comfortable with Kubernetes and Infrastructure-as-Code (IaC) such as Terraform and Helm and CI/CD platforms such as ArgoCD.
  • Experience protecting APIs using OAuth scopes and claims.

Responsibilities

  • Complete baseline environment configuration for Ping Directory and Conductor One across Dev and Prod tiers.
  • Integrate HRIS (Workday) with the IGA platform to automate Joiner-Mover-Leaver (JML) processes.
  • Build and validate production-ready connectors for the core ecosystem, including Okta, AWS, Google, Slack, and Squad.
  • Deploy "Justify or Revoke" workflows and automated reporting to support SOX/ISO privileged access reviews.
  • Execute the migration of Workforce and Service identities to Ping Directory.
  • Define technical test plans, draft formal procedural documentation for audits, and create system runbooks for the permanent operations team.
  • Own the full IAM lifecycle, evolving existing infrastructure into a scalable, modern ecosystem.
  • Troubleshoot and resolve complex integration and performance issues across the IAM stack.

Benefits

  • Annual bonus
  • Equity compensation
  • Health insurance
  • Dental insurance
  • Vision insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service