Software Engineer II, Security

GitHub
United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$221,400.0
Working hours
Regular working hours
Job source

Tech stack

C (Programming Language) Java (Programming Language) JavaScript (Programming Language) Amazon Web Services User Authentication Microsoft Azure C Sharp (Programming Language) C++ (Programming Language) Cyber Security Computer Engineering Multi-Factor Authentication Github
+14 more
Identity and Access Management Python (Programming Language) OAuth OpenID Role-Based Access Control Azure Active Directory Ruby Security Assertion Markup Language (SAML) Software Engineering Rust (Programming Language) Cloud Platform System Okta Information Technology Golang

Job description

GitHub is changing the way the world builds software, and we want you to help secure GitHub. We’re looking for an Identity & Access Security Operations Engineer to ensure the right Hubbers get the right access at the right time for the right reasons and to strengthen the security and availability of GitHub’s internal systems.

As part of Secure Access Engineering - Identity & Access Management, you will enable secure access to GitHub’s internal infrastructure and the sensitive data stored therein. In this position, you will maintain and improve IAM control processes, develop automation to improve efficiency, and collaborate across teams to ensure secure access patterns.

Responsibilities

  • Provide guidance and support to Hubbers using GitHub’s internal identity and access management platform

  • Develop, maintain, and improve services that support identity lifecycle, access workflows, and paved-path processes for Hubbers

  • Work with technical and non technical partner teams to drive consistent IAM practices

  • Monitor and maintain IAM services, participate in an on-call rotation, respond to incidents, and enhance operational processes

  • Manage services and processes that play a critical role in compliance to several audit frameworks

Requirements

  • 2+ years experience in Software Engineering, Computer Science, or related technical discipline with proven experience maintaining production software coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, Go, Ruby, Rust, or Python
  • OR Associate’s Degree in Computer Science, Electrical Engineering, Electronics Engineering, Math, Physics, Computer Engineering, Computer Science, or related field AND 1+ year(s) experience
  • OR Bachelor’s Degree in Computer Science or related field
  • OR equivalent experience.
  • 1+ years of experience in Security Operations, Identity & Access Management, Security Engineering, or a related technical field.
  • 1+ years experience implementing or operating IAM technologies (e.g., SSO/MFA, directory services, RBAC/ABAC models).
  • 1+ years professional experience working with Ruby

Preferred Qualifications:

  • Experience operating identity or access management systems at scale.

  • Familiarity with identity directories (e.g., Okta, Azure AD), authentication/authorization protocols (OAuth, SAML, OIDC)

  • Experience supporting production services in an on-call capacity.

  • Experience with cloud environments such as AWS, Azure, or GCP.

  • Experience designing paved-path processes for identity lifecycle, access reviews, or entitlements management.

Benefits & conditions

The base salary range for this job is USD $83,400.00 - USD $221,400.00 /Yr.

These pay ranges are intended to cover roles based across the United States. An individual’s base pay depends on various factors including geographical location and review of experience, knowledge, skills, abilities of the applicant. At GitHub certain roles are eligible for benefits and additional rewards, including annual bonus and stock. These rewards are allocated based on individual impact in role. In addition, certain roles also have the opportunity to earn sales incentives based on revenue or utilization, depending on the terms of the plan and the employee’s role.

GitHub values

  • Customer-obsessed
  • Ship to learn
  • Growth mindset
  • Own the outcome
  • Better together
  • Diverse and inclusive

Manager fundamentals

  • Model
  • Coach
  • Care

Leadership principles

  • Create clarity
  • Generate energy
  • Deliver success

About the company

GitHub is the world’s leading platform for agentic software development - powered by Copilot to build, scale, and deliver secure software. Over 180 million developers, including more than 90% of the Fortune 100 companies, use GitHub to collaborate, and more than 77,000 organisations have adopted GitHub Copilot., GitHub is the world’s leading AI-powered developer platform with 150 million developers and counting. We’re also home to the biggest open-source community on earth (and 99% of the world’s software has open-source code in its DNA). Many of the apps and programs you use every day are built on GitHub.

Our teams are dreamers, doers, and pioneers, leading the way in AI, driving humanitarian efforts around the globe, and even sending open source to Mars (and beyond!). At GitHub, our goal is to create the space you need to do your best work. We’re remote-first and offer competitive pay, generous learning and growth opportunities, and excellent benefits to support you, wherever you are-because we know that people flourish when they can work on their own terms.

Join us, and let’s change the world, together.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

3:30 min

Falling in love with Ruby and creating Basecamp

David Heinemeier Hansson David Heinemeier Hansson +1 · Coffee With Developers

Videos

See all

Related articles

See all