Skip to main content

Senior+ IAM Engineer

Verkada
San Mateo, CAUpdated 3d ago
Compensation
$200k–$300k
Published range
Location
San Mateo, CA
Remote eligibility
Employment
Full-time
Senior
Role family
Security
Cybersecurity
Apply on job-boards.greenhouse.io
Job actionsApply now
Job actionsApply now

About the job

About the Role

As a Senior IAM Engineer on the Security team, you will set the standard for identity and access across Verkada, owning how access is defined, granted, reviewed, and revoked throughout our infrastructure. From codifying identity boundaries in Terraform and Rego to driving least privilege across AWS roles and policies on zero trust principles, your work will turn access management from a manual ticket queue into a self-service system powered by scripts and agentic workflows.

What You'll Do

  • Manage identity and access infrastructure as code in Terraform, with peer-reviewed change control, drift detection, and policy-as-code.
  • Advance zero trust controls for engineering access: short-lived credentials, just-in-time elevation, and the elimination of standing privilege.
  • Own the access lifecycle for both human and non-human identities: joiner/mover/leaver flows, service accounts, and agents.
  • Operate access review and certification workflows that produce audit evidence.
  • Write tools to surface over-permissioned identities, unused credentials, and policy drift; then drive remediation to completion.
  • Build agentic workflows on a low-code orchestration platform to automate access requests, approvals, risk scoring, and access review campaigns.
  • Partner with security, infrastructure, and product engineering teams so that the secure path is the easy path, and consult on IAM design for new services.

What You'll Need

  • Bachelor of Science in Computer Science degree or equivalent practical experience
  • 3+ years working hands-on with identity and access management in a cloud-native engineering environment
  • Deep AWS IAM expertise: policy evaluation logic, permission boundaries, assume-role patterns, SCPs, and the ways they fail in practice and how to express them in Terraform
  • Fluency with identity protocols and access models (SAML, OIDC, OAuth 2.0, SCIM; RBAC, ABAC, or policy-based access), plus working knowledge of Okta administration and APIs: SSO, provisioning, group rules, and authentication policies
  • Ability to build automation for your own work, using either scripting or low-code/no-code orchestration platforms, including LLM or agent-driven steps
  • Excellent written and verbal communication skills — you can explain an access decision to an engineer, an auditor, and an executive

Benefits

Verkada offers comprehensive wellness perks, benefits, and resources, including healthcare programs with 100% covered employee premiums under at least one plan, nationwide medical, vision and dental coverage, HSA with annual employer contributions, expanded mental health support, paid parental leave, fertility benefits, paid holidays, firmwide extended holidays, flexible PTO, personal sick time, professional development stipend, wellness/fitness benefits, healthy lunches, and commuter benefits.

Additional Information

We do sponsor and take over sponsorship of employment visas for this role. If we make you an offer, we will make every reasonable effort to get you a visa.

Pay Range

Estimated Annual Pay Range: $200,000—$300,000 USD

Skills & tags

What you can verify before applying

Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.