Senior Security Engineer, IAM

RelativityWashington, NV
$130,000 - $195,000Remote

About The Position

The Senior IAM Engineer is a technically authoritative leader who sets the direction for the enterprise IAM function and anchors identity as the primary control plane in a defense-in-depth program. This engineer owns the architecture, strategy, and operational maturity of AI-enabled identity technologies across the workforce, customer, and non-human (machine and agent) identity domains. Partnering with the Manager of Enterprise Security and leading cross-functional teams, the role reduces Relativity's identity attack surface, sets the standards others build against, mentors engineers, and elevates the organization's ability to detect and respond to identity-based threats.

Requirements

  • Bachelor's in Computer Science, Information Security, or equivalent experience.
  • 8+ years of hands-on experience in enterprise IAM or security engineering, with deep specialization in identity, authentication, and access domains, or a Master's degree in Cybersecurity or a relevant field with 6+ years of experience.
  • Expert, hands-on experience architecting and operating identity platforms across IdP/SSO (Okta, Entra ID/Azure AD, Ping), IGA (SailPoint, Saviynt), and PAM (CyberArk, BeyondTrust), with advanced knowledge of authentication and federation protocols (SAML, OIDC, OAuth 2.0, SCIM, LDAP, Kerberos).
  • Demonstrated experience leading identity threat detection, complex access investigations, and detection-engineering efforts, including designing automation for access enforcement and observability.
  • Working command of industry-standard security benchmarks and frameworks (MITRE, NIST 800-63, Zero Trust) and the ability to translate them into technical controls.
  • Proficiency in at least one scripting/automation language (Python, Bash, or PowerShell) applied to containerized services, CLI-based commands, and identity-specific use cases (API-driven provisioning, policy-as-code).
  • Proven ability to mentor engineers and communicate technical strategy and findings clearly to engineering peers, leadership, and non-technical stakeholders.
  • Access Management
  • Application Security
  • Endpoint Security
  • Network Security
  • Penetration Testing
  • Security Architecture Design
  • Security Information
  • Security Information and Event Management (SIEM)
  • Security Operations
  • Vulnerability Management

Nice To Haves

  • Experience securing SaaS, cloud-native, or globally distributed regulated environments.
  • Cloud IAM experience across AWS, Azure, or GCP, and securing non-human/workload identities at scale.
  • Experience with AI-augmented security and governance for AI-assisted and agentic identity workflows (UEBA, ML-based access-risk scoring, agentic identity).
  • Experience embedding identity and access controls (secrets management, workload identity, policy-as-code) into CI/CD pipelines and infrastructure-as-code environments.
  • Familiarity with legal technology, e-discovery, litigation holds, and digital forensics chain-of-custody requirements.
  • Experience leading compliance and audit engagements (SOX, SOC 2, ISO 27001, FedRAMP, HIPAA, GDPR, CCPA) from an identity and access control perspective.
  • Certifications such as CISSP, CISM, GCIH, GCFA, CCSP, AWS Security Specialty, SC-300, or AZ-500.

Responsibilities

  • Design identity architecture spanning workforce, machine, and workload identity, mapping layered controls to relevant frameworks as a core tier of defense-in-depth.
  • Design and advance continuous adaptive trust capabilities (continuous access evaluation (CAE), risk-based and phishing-resistant authentication, and signal-driven session revocation) as the maturation of the enterprise Zero Trust architecture.
  • Engineer and optimize ZTNA, least-privilege micro-segmentation, MFA/FIDO2, and JIT access across access paths.
  • Design and optimize SSO, federation, and authentication standards (SAML, OAuth 2.0, OIDC, SCIM, Kerberos, LDAP) across SaaS and multi-cloud environments.
  • Define and tune hardening standards using CIS Benchmarks/DISA STIGs with automated compliance validation.
  • Design and optimize identity lifecycle automation (joiner/mover/leaver) integrating HR systems, directories, and downstream applications.
  • Engineer identity governance and administration (IGA) capabilities: access reviews, certification campaigns, and segregation-of-duties enforcement.
  • Lead implementation and optimization of privileged access management (PAM) including credential vaulting, JIT elevation, and session monitoring.
  • Design governance for non-human identities (service accounts, workloads, secrets) with automated drift detection and policy-as-code enforcement.
  • Lead integration of identity telemetry into the detection stack (SIEM/SOAR, UEBA) to detect credential abuse, privilege escalation, and lateral movement, reducing MTTD and MTTR.
  • Develop identity-focused IR playbooks covering account takeover, credential compromise, federation abuse, and session hijacking.
  • Apply threat intelligence context to prioritize identity exposure remediation and lead identity-focused purple team engagements.
  • Design identity controls embedded in AI-augmented CI/CD pipelines (secret scanning, IaC identity policy, workload identity) with AI-generated fix recommendations surfaced in PR workflows.
  • Define and track identity KPIs: privileged access coverage, certification completion, authentication anomaly rates, and entitlement drift.
  • Partner with GRC on identity controls aligned to SOX, SOC 2, ISO 27001, HIPAA, GDPR, and CCPA, and support audits, certifications, e-discovery, and forensic integrity requirements.
  • Provide technical guidance and mentorship to Advanced and Engineer-level identity engineers.

Benefits

  • Comprehensive health, dental, and vision plans
  • Parental leave for primary and secondary caregivers
  • Flexible work arrangements
  • Two, week-long company breaks per year
  • Additional time off
  • Long-term incentive program
  • Training investment program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service