> Markdown version of [/jobs/ext/1781288-identity-and-access-management-engineer](https://www.wearedevelopers.com/jobs/ext/1781288-identity-and-access-management-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity and Access Management Engineer - **Company:** Hi, We're Oscar - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $163,944.0 - $215,176.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, User Authentication, BigQuery, Software as a Service, Custom Software, Identity and Access Management, Intrusion Detection and Prevention, Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Role-Based Access Control, Security Assertion Markup Language (SAML), Security Information and Event Management, Software Engineering, Google Cloud, Enterprise Software Applications, Cloud Platform System, Okta, Data Lakes, Enterprise Integration, Data Management, Gsuite - **Published:** July 2, 2026 - **Apply:** https://www.dice.com/job-detail/26fc8055-68fa-42f8-b4dd-026f737bd13f ## About the Role * 4+ years of relevant experience in Identity engineering. * Experience designing or implementing identity and access management controls for enterprise systems, cloud environments, SaaS platforms, or internally built applications. * Strong understanding of least privilege, role-based and attribute-based access control, privileged access patterns, identity lifecycle management, and access review processes. * Hands-on experience with identity platforms such as Okta, Google Workspace Identity, and Google Cloud permission models. * Working knowledge of authentication and authorization protocols such as SAML, OAuth, OIDC, SCIM, LDAP, and related session, token, and federation patterns. * Experience partnering with software engineering teams to review permission models, design secure authorization patterns, and improve access controls in custom applications. * Ability to reason about identity telemetry, detection logic, high-risk configuration states, and incident response workflows. * Strong written and verbal communication skills, including the ability to explain identity risk and architecture tradeoffs to technical and non-technical audiences. Bonus Points: * Experience building identity controls in AWS environments and data platforms such as BigQuery. * Experience building or operating ITDR, UEBA, SIEM, SOAR, or other security detection and response capabilities. * Experience in healthcare, insurance, fintech, or another regulated technology environment. * Experience writing automation, queries, or production-quality code to support identity workflows, detections, or platform integrations. ## Description As an Identity and Access Management Engineer, you will build Oscar's identity and access management disciplines across internally built applications, standard identity platforms such as Okta and Google Workspace Identity, AWS-hosted systems, and the BigQuery data lake. You will design least privilege access models, create enterprise identity architectures, and build identity threat detection and response capabilities that protect workforce, internal application, and customer identity surfaces. You will report to the Associate Director, Platform Security. Work Location: This position is based in our New York City office, requiring a hybrid work schedule with 3 days of in-office work per week. Thursdays are a required in-office day for team meetings and events, while your other two office days are flexible to suit your schedule. Pay Transparency: The base pay for this role is: $163,944 per year - $215,176 per year. You are also eligible for employee benefits, participation in Oscar's unlimited vacation program, company equity grants and annual performance bonuses. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) - [No More Post-its: Boost your login security with APIs](https://www.wearedevelopers.com/videos/1043-no-more-post-its-boost-your-login-security-with-apis) ## Related Articles - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 119 - ❤️ === ❤️](https://www.wearedevelopers.com/magazine/454-dev-digest-119) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)