Senior Security Software Engineer, IAM - Moveworks

ServiceNowWashington, DC
Hybrid

About The Position

Moveworks is seeking a Senior Identity & Access Management (IAM) Engineer to shape the future of their identity and access strategy. This role involves hands-on technical development, coding, designing, building, and scaling IAM solutions across cloud infrastructure, SaaS applications, and internal systems. The engineer will own IAM initiatives end-to-end, from defining requirements and architecting solutions to driving them into production. Key responsibilities include developing access models for AWS, Azure, Kubernetes, and other systems; reducing privilege sprawl; building observability through logging and metrics in SIEM; modernizing access reviews; and continuously de-risking IAM threats. The work directly protects Moveworks' critical systems while enabling engineers to move fast and confidently.

Requirements

  • 5+ years of experience developing and maintaining IAM products/tools.
  • Automation-first mindset: Experience writing production-ready scalable software, Infrastructure as Code, and using AI coding tools to build reliable automation.
  • IAM Expertise: Strong grasp of IAM best practices, techniques, and common failure modes (e.g., least privilege, privilege escalation paths, separation of duties, breakglass, auditability). Ability to spot dangerous permissions and identify suitable mitigations and controls.
  • BS+ in computer science or a related field, or equivalent relevant experience.
  • US Citizenship preferred

Responsibilities

  • Be the technical developer to drive IAM application development: Code, design, and implement solutions with extensive knowledge in AWS, Azure, Teleport, and Terraform. Enabling robust and reliable solutions to keep our engineering teams active.
  • Drive IAM projects end-to-end: Take ambiguous access problems, understand and have the ability to define requirements, architect solutions, and own the rollout/operationalization (not just the design).
  • Develop with secure access models in mind: Continuously develop role design improvements and access assignment patterns across AWS, Kubernetes, SaaS apps, and internal systems to reduce unnecessary privileges, minimize manual grants, and create scalable “safe baseline” access that covers routine work without daily elevation.
  • Develop on operationalizing logging and metrics: Ensure access changes are observable in our Security Information and Event Management (SIEM) tool; build repeatable reporting that surfaces risky access and drift.
  • Run and improve user access reviews (UAR): Develop, execute and design a UAR process & solution that meets compliance requirements while improving real security signal—minimizing approver burden through scoping, automation, and clear decision support.
  • Develop technology to continuously de-risk: Identify high-risk permissions and misuse paths, propose appropriate controls and mitigations, drive adoption with partner teams, and develop solutions to continuously de-risk.
  • Operate with strong security judgment and high signal: Reliably distinguish meaningful IAM risk from noise, gather context efficiently, and escalate with crisp rationale and actionable mitigations.
  • Document and standardize the paved road: Write lightweight procedures, runbooks, and automation so access decisions are consistent, scalable, and not dependent on tribal knowledge.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service