> Markdown version of [/jobs/ext/2196538-security-engineer-identity-and-access-management-iam](https://www.wearedevelopers.com/jobs/ext/2196538-security-engineer-identity-and-access-management-iam). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Identity and Access Management (IAM) - **Company:** K2 Space - **Location:** Los Angeles, CA, United States - **Experience:** Expert - **Salary:** $150,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Active Directory, Amazon Web Services, Systems Engineering, Microsoft Azure, C++ (Programming Language), Software as a Service, Cyber Security, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Kerberos (Protocol), Key Management, Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Ping (Networking Utility), Role-Based Access Control, Azure Active Directory, Phishing, Security Assertion Markup Language (SAML), Single Sign-On, Rust (Programming Language), Policy as Code, Google Cloud, Okta, Delivery Pipeline, Cloudformation, Information Technology, Hashicorp, Restful APIs, Terraform, Webhooks, Golang - **Published:** August 23, 2026 - **Apply:** https://www.dice.com/job-detail/bc178a86-c1d9-4893-ae7f-c86088743d93 ## About the Role With multiple launches planned through 2026 and 2027, we're Building Bigger to develop the solar system and become a Kardashev Type II (K2) civilization. If you are a motivated individual who thrives in a fast-paced environment and you're excited about contributing to the success of a groundbreaking Series C space startup, we'd love for you to apply., * 5+ years of experience in identity and access management, security engineering, or infrastructure engineering, preferably in a fast-paced startup or technology environment * Hands-on experience administering an enterprise identity provider (e.g., Okta, Microsoft Entra ID, Ping, or Google Identity), including SSO, MFA, and conditional access * Strong working knowledge of identity protocols and standards, including SAML, OIDC, OAuth 2.0, SCIM, LDAP, and Kerberos * Experience designing and implementing identity lifecycle automation, RBAC or ABAC access models, and access review processes * Experience with privileged access management and secrets management for both human and machine identities, such as HashiCorp Vault or equivalent * Experience with cloud IAM in AWS, Azure, or Google Cloud Platform, including least-privilege role and policy design * 2+ years of development experience with any modern programming language (including but not limited to Python, Go, C++, Rust) used to automate identity workflows and integrations, in lieu of a degree; OR a bachelor's degree in security engineering, cyber security, computer science, engineering, math, or other STEM discipline * Comfortable working with mission critical and sensitive systems, with a sense of urgency appropriate with responsibilities * Due to the high visibility of this position, excellent interpersonal skills, attention to detail, and problem-solving skills Nice to Have * Bachelor's degree (or equivalent) in computer science or engineering * Identity certifications such as Okta Certified Administrator, Microsoft Identity and Access Administrator (SC-300), or CISSP, or equivalent hands-on experience * Experience managing identity resources with infrastructure as code (Terraform, CloudFormation, or CDK) * Experience with policy-as-code frameworks such as OPA or Cedar * Experience with identity threat detection and response (ITDR) and building identity-focused detections * Experience integrating modern identity with legacy or on-premise systems, including Active Directory modernization * Experience with identity and access control for engineering, manufacturing, OT, or mission and ground segment environments * Prior experience in a defense, aerospace, or other ITAR-regulated environment ## Description Identity is the perimeter at K2. Every engineer, every ground and mission system, every SaaS tool and automated pipeline depends on the right people and services holding exactly the access they need and nothing more. This role owns that problem end to end: you'll design, build, and run the identity platform that governs authentication and authorization across our corporate, engineering, and mission environments. You'll be deeply hands-on with our identity provider, SSO and federation, phishing-resistant MFA, lifecycle automation, privileged access, and secrets management, and you'll retire the standing access and shared credentials that accumulate in any fast-growing company. This is a role for someone who thrives on real-world impact: making least privilege the default without slowing down the teams building spacecraft. Every access path you close and every workflow you automate directly supports our ability to move fast, operate confidently, and deliver breakthrough satellite capabilities., * Own and mature the enterprise identity platform, including the identity provider, single sign-on, federation, and directory services across corporate, engineering, and mission environments * Design and implement authentication standards using modern protocols such as SAML, OIDC, OAuth 2.0, and SCIM, and drive adoption of phishing-resistant MFA including FIDO2 and WebAuthn * Build and automate identity lifecycle management, including joiner, mover, and leaver workflows, provisioning and deprovisioning, and just-in-time access * Design and maintain role-based and attribute-based access models, entitlement structures, and least-privilege standards for corporate and engineering systems * Implement and operate privileged access management for administrators, service accounts, and break-glass credentials * Manage machine and workload identity, including secrets management, credential rotation, and the non-human accounts used by automated pipelines and mission systems * Onboard SaaS and internal applications to SSO and automated provisioning using SCIM, REST APIs, and webhooks, retiring local accounts and shared credentials as you go * Implement conditional access and risk-based authentication policies, then tune them against real access patterns * Build and run access review and certification campaigns, producing the evidence auditors and customers require * Harden cloud IAM across AWS, Azure, or Google Cloud Platform, including roles, trust policies, and permission boundaries * Write code and infrastructure as code to automate identity operations rather than resolving them ticket by ticket * Partner with security operations on identity threat detection and response, including credential abuse, session hijacking, and MFA fatigue attacks, and support investigations involving identity * Serve as the identity subject matter expert in architecture and design reviews, acting as a liaison between the security team and engineering * Maintain identity documentation, runbooks, and standards, and mentor junior team members on identity engineering practices ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Un-complicate authorization maintenance](https://www.wearedevelopers.com/videos/889-un-complicate-authorization-maintenance) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)