Identity Management Engineer

Aurora Innovation, Inc.
Seattle, WA, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$162,000.0 - $235,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Cloud Computing Cyber Security Continuous Integration Human Resources Information System (HRIS) Identity and Access Management Python (Programming Language) Lightweight Directory Access Protocols (LDAP) OAuth OpenID
+14 more
Ping (Networking Utility) Role-Based Access Control Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Systems Integration Okta Software Security Kubernetes Infrastructure Automation Frameworks Information Technology SailPoint Terraform Workday

Job description

The Aurora Driver will create a new era in mobility and logistics, one that will bring a safer, more efficient, and more accessible future to everyone.

At Aurora, you will tackle massively complex problems alongside other passionate, intelligent individuals, growing as an expert while expanding your knowledge. For the latest news from Aurora, visit aurora.tech or follow us on LinkedIn.

We are seeking a hands-on IAM Engineer to support the technical execution of our modern identity ecosystem. You will be the primary ā€œlaborā€ engine responsible for implementing our newly licensed tools (Conductor One and Ping Directory). You will be working closely with the IAM Architect in this role.

We’ve moved past the basics; our stack is built on Zero Trust principles, featuring SPIRE, Open Policy Agent (OPA), and a custom-built group management engine. You will own the full IAM lifecycle, evolving our existing infrastructure into a scalable, modern ecosystem that serves as a competitive advantage for our operations.

In this role you will

  • Platform Implementation: Complete baseline environment configuration for Ping Directory and Conductor One across Dev and Prod tiers.

  • Workforce Automation: Integrate HRIS (Workday) with the IGA platform to automate Joiner-Mover-Leaver (JML) processes.
  • Technical Connectivity: Build and validate production-ready connectors for the core ecosystem, including Okta, AWS, Google, Slack, and Squad.
  • Compliance Hardening: Deploy ā€œJustify or Revokeā€ workflows and automated reporting to support SOX/ISO privileged access reviews.
  • Identity Isolation: Execute the migration of Workforce and Service identities to Ping Directory.
  • Operational Readiness: Define technical test plans, draft formal procedural documentation for audits, and create system runbooks for the permanent operations team.

Requirements

  • Experience: 4+ years in Information Security, with at least 2 years specifically focused on implementing IAM solutions in large enterprise environments.
  • Identity Expertise: Expert-level knowledge of at least one major Cloud Identity Provider (AWS IAM, Azure) and core protocols including SAML, OAuth 2.0, OIDC, SCIM, and LDAP.
  • Modern Principles: Deep understanding of Zero Trust principles and access models such as RBAC, ABAC, and PBAC.
  • Education: Bachelor’s or Master’s degree in Computer Science, IT, or equivalent practical experience.
  • Ability to develop code in either Python or Go., * Identity Providers: Experience with integration patterns with IdPs such as Okta, Auth0 or Microsoft Entra ID.
  • IGA/PAM: Experience with Conductor One, SailPoint, Saviynt or similar platforms.
  • Directory Services: Hands-on experience with Ping Directory or similar LDAP solutions. Including monitoring for performance and fine-tuning CPU, Memory and Storage.
  • Cloud Infrastructure: Understanding of AWS cloud infrastructure and security concepts. Comfortable with Kubernetes and Infrastructure-as-Code (IaC) such as Terraform and Helm and CI/CD platforms such as ArgoCD.
  • API Security: Experience protecting APIs using OAuth scopes and claims.
  • Troubleshoot and resolve complex integration and performance issues across the IAM stack.

About the company

Aurora’s mission is to deliver the benefits of self-driving technology safely, quickly, and broadly., Working at AuroraAt Aurora, we bring together extraordinarily talented and experienced people united by the strength of our values. We operate with integrity, set outrageous goals, and build a culture where we win together - all without any jerks.

We believe in-person work increases collaboration, empathy and our ability to lead effectively. As a result, we operate in a hybrid work environment where Aurorans are in office at least 3 days per week.

Our Careers page provides insight into what it is like to work at Aurora, and you can find all the latest updates in our Newsroom.

Our commitment to safety

At the core of everything we do is our commitment to safety. Building best-in-class self-driving technology will take time, and we believe that each employee at Aurora has a role in contributing to safety, every step of the way. Aurora expects commitment to our safety policies from every employee, and seeks candidates who take an active responsibility, can contribute to building an atmosphere of trust, and invest in the organization’s long-term success by prioritizing working safely, no matter what.

Our commitment to inclusion

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter Ā· WWC 2024

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo Ā· LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 Ā· LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz Ā· WWC Europe 2026

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter Ā· WWC 2024

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all