> Markdown version of [/jobs/ext/1384417-senior-security-engineer-iam](https://www.wearedevelopers.com/jobs/ext/1384417-senior-security-engineer-iam). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - IAM - **Company:** TENEX SECURITY, INC. - **Location:** Sarasota, FL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Amazon Web Services, Microsoft Azure, Cyber Security, Identity and Access Management, Kerberos (Protocol), OAuth, OpenID, Security Assertion Markup Language (SAML), Google Cloud, Okta, Information Technology - **Published:** July 22, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7e7b2bb722e411e0 ## About the Role * 7+ years deep in identity, hands-on across Entra ID and Active Directory, Okta, and cloud IAM (AWS, GCP, Azure), with real command of authentication, authorization, federation and trust, and privileged access. * The attacker's view of identity: how Kerberos, SAML, OAuth, and OIDC break in practice, and how a single foothold becomes privilege and then persistence. * A track record of hardening real identity environments and getting the fixes shipped, not just writing up the gaps. * The depth and credibility to be the authority on identity risk in any room, including across the table from a customer's own IAM architects., * Bachelor's degree in Computer Science, Cybersecurity, or Engineering, or a related field (or equivalent experience). * Relevant certifications such as Microsoft SC-300, Okta certifications, a cloud identity or security specialty, CISSP, or an offensive cert like CRTP or OSCP are a plus. ## Description * Define what hardened identity looks like. Build and maintain the configuration and hardening standards for Entra ID and Active Directory, Okta, and cloud IAM, grounded in how these platforms actually get attacked rather than a generic checklist. Keep them current as the vendors ship changes and attackers find new paths. * Reduce IAM risk for customers. Work through customer identity environments and map the attack paths: excessive privilege and shadow admin, weak or bypassable authentication, loose federation and trust, stale access, and the tier-0 exposure that turns one foothold into full tenant or domain compromise. Then drive the remediation that actually closes them. * Work alongside customer identity teams. Sit across from client IAM engineers and architects as a peer, review their designs, and push back where the risk warrants it. Give clear, prioritized recommendations they can put into production. * Advise the SOC and IR. Be the identity expert our analysts and responders reach for when something looks off: anomalous token use, a suspicious OAuth consent grant, a golden SAML, lateral movement across trust relationships. Help them scope identity-driven incidents fast and know what to pull and what to contain. * Mature how the SOC handles identity. Assess how well the SOC can respond to and contain identity attacks today, then close the gaps: the detections that need to fire, the containment actions that should be fast and repeatable (revoking sessions and tokens, disabling accounts, killing malicious app grants, cutting an abused trust), and the playbooks that hold up under pressure. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions)