Senior Security Engineer, Identity and Access Management

HackerOne•Seattle, WA
•$180,000 - $220,000•Remote

About The Position

At HackerOne, identity is at the heart of how we protect the data we are trusted with most, our customers' vulnerabilities. We are building our Identity and Access Management capability with an AI-first approach, focused on engineering and not administration alone. As a Senior Security Engineer, you will design and deliver the access models and the automation behind them, so that people and systems can access only the right data, at the right time, in the right way. This role operates across the full identity lifecycle, from onboarding and creation through change and removal, for people, service accounts, and AI agents alike. You will help scale what a small team can accomplish by embedding automation, intelligence, and AI into how access is granted, reviewed, and removed, working toward least privilege for humans and least agency for AI. HackerOne embraces a Flexible Work approach that gives us the freedom to do our best work while also fostering the connections and community that make us stronger. Reflecting this philosophy, this is a remote role targeted for candidates within ~50 miles of Austin TX, Seattle WA, Washington DC, San Francisco CA, or Boston MA, or within commuting distance of our London or Netherlands locations. We believe this balance of proximity and flexibility gives Hackeronies the chance to occasionally come together, fostering collaboration, connection, and in-person moments that enrich our culture, while still preserving the benefits of remote work.

Requirements

  • 5+ years of experience in identity and access management, security engineering, or software engineering with substantial ownership of identity systems
  • Hands-on experience operating an enterprise identity provider such as Okta, including SAML, OIDC, SCIM, and lifecycle automation
  • Experience managing identity across an enterprise SaaS estate such as Google Workspace, Salesforce and Workday, including SCIM provisioning and group-driven entitlements
  • Experience with cloud IAM, ideally AWS, including policy design and short-lived credentials
  • Strong software engineering fundamentals with proficiency in Python, Go, or a similar language, and hands-on use of AI and LLM tooling and agentic coding tools in production engineering work

Nice To Haves

  • Identity work in a regulated sector such as financial services, healthcare, or government, and producing access control evidence for audit against requirements such as PCI DSS, HIPAA, SOC 2, or ISO 27001
  • Managing identity infrastructure as code, and access request or governance tooling, for example Terraform and Lumos
  • Mobile device management (MDM) alongside identity, for example Kandji integrated with Okta: device trust policies, platform SSO, and endpoint enrollment
  • Non-human, workload, and privileged access: secrets management, short-lived credentials, and service-to-service authentication
  • Building AI or LLM-powered tooling for security or identity workflows
  • Detection and incident response for identity-centered incidents such as credential compromise, session abuse, or entitlement misuse
  • Industry certification in identity or security, such as IDPro CIDPRO, Okta certifications, AWS Certified Security – Specialty, or CISSP

Responsibilities

  • Own the identity lifecycle end to end, from onboarding and creation through change to removal, for people, service accounts, and AI agents alike, building the automation that grants entitlements on evidence of legitimate need and removes them seamlessly and automatically
  • Design and build the access models on top of data classification, so that what an identity can reach follows from what the data is rather than from who asked
  • Make time-bound access the default for critical data, so that the secure path is the easy path
  • Engineer identity as code, keeping provisioning logic, entitlement policy, and access review rules in version control and under test across systems such as Okta, Lumos, and AWS IAM, applying First Principles Problem Solving rather than configuring by hand in consoles
  • Build AI and LLM-powered tooling that makes access review and entitlement anomaly detection continuous rather than periodic, embedding AI First practices so unusual patterns surface when they happen rather than at audit, and decide where AI is trusted to carry an access decision and where a person still signs it off
  • Bring non-human identities under the same discipline as human ones. Service accounts, workload identities, integrations, and AI agents each get an owner, a purpose, and an expiry, treated as the default rather than a cleanup project
  • Continuously measure access and report the opportunity to reduce unnecessary entitlement, using Data-Driven Decision Making to prioritize where reduction matters most
  • Partner with Engineering, Enterprise IT, and Compliance to embed identity controls into the systems they own, and support detection and incident response as the identity responder, containing access, reconstructing what an identity reached, and contributing to blameless retrospectives, demonstrating Change Agility as threats and tooling evolve

Benefits

  • Health (medical, vision, dental), life, and disability insurance
  • Equity stock options
  • Retirement plans
  • Paid public holidays and unlimited PTO
  • Paid maternity and parental leave
  • Leaves of absence (including caregiver leave and leave under CO's Healthy Families and Workplaces Act)
  • Employee Assistance Program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service