> Markdown version of [/jobs/ext/3056697-information-security-engineer](https://www.wearedevelopers.com/jobs/ext/3056697-information-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer - **Company:** Match Group - **Location:** Los Angeles, CA, United States - **Experience:** Expert - **Salary:** $10,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Systems Engineering, User Authentication, Software as a Service, Cloud Computing Security, Data Security, Identity and Access Management, Python (Programming Language), OAuth, OpenID, PCI Data Security Standards, Role-Based Access Control, Zero Trust Network Access, Security Assertion Markup Language (SAML), Software Vulnerability Management, Okta, Infrastructure Automation Frameworks, No-code Tools, Cloudflare, Casper Suite, Virtual Agents, SailPoint, Terraform - **Published:** September 24, 2026 - **Apply:** https://www.thejobnetwork.com/job/05c7e156-0475-4a32-be18-2cecdedcc6ee/senior-information-security-engineer ## About the Role * 7+ years in security engineering, IT engineering, or infrastructure, with meaningful depth in identity and access * Strong hands-on experience with Okta: policy design, device assurance, FastPass, device trust, RBAC * Experience with Cloudflare Zero Trust or a comparable platform * Strong knowledge of SAML, OIDC, OAuth 2.0, and SCIM * Experience with IGA solutions (e.g., Okta Identity Governance, SailPoint), including a deep understanding of identity lifecycles and compliance requirements. * Experience securing non-human identities (service accounts, OAuth apps, tokens) and establishing guardrails for AI agents; we value your thought process and perspective on these emerging challenges. * Experience with using Terraform or other IaC tools to manage infrastructure changes, with a strong emphasis on GitOps fluency. * Practical view of least privilege. You can right-size access without introducing too much friction to the business. * Experience building automated solutions (e.g., Okta Workflows, Lambda, Windmill) using Python or similar; you know when to automate for high impact and when to avoid it to prevent over-engineering. * Practical use of AI tooling in your own workflow * Proven ability to influence cross-functional outcomes, even without direct formal authority. * Proactively identify, scope, and drive complex problems to completion. Nice to have * Endpoint management or EDR exposure (Jamf, CrowdStrike, or similar) * Audit and compliance experience with access controls (SOX, PCI-DSS, ISO 27001) * Experience working in global environments (EMEA/APAC) Factors such as scope and responsibilities of the position, candidate's work experience, education/training, job-related skills, internal peer equity, as well as market and business considerations may influence base pay offered. ## Description Match Group runs one unified security program across Tinder, Hinge, Match, Meetic, OkCupid, Plenty of Fish, Azar, Pairs, and the rest of the portfolio. Enterprise Security owns the corporate attack surface: who gets access to what, on which device, from where. Identity is the center of gravity for this role and where you will spend most of your time. Our Enterprise Security function is built on two core pillars-Identity & Access Security and CorpSec-and while this role is anchored in Identity & Access Security, you will work fluidly across boundaries. Because identity is so tightly coupled with other CorpSec domains-such as endpoint, SaaS, and data access-you will collaborate fluidly across both teams to drive a unified security strategy. What you'll do * Drive a comprehensive identity and access lifecycle strategy for our global portfolio, such as: + Authentication (AuthN): Drive identity security to the next level by enforcing device trust, post-auth detection, and DPoP. + Authorization (AuthZ): Enforce least privilege and right-size entitlement that balance security and velocity. + Non-Human & AI Agent Identity: Lead secure management for NHIs (e.g., OAuth tokens, service accounts, and API keys) and establish security guardrails for emerging AI agents and MCP connections. + Privileged Access Management (PAM) & Just-in-Time (JIT) Access: Modernize privileged access and implement JIT models to reduce standing privileges and secure high-risk administrative actions. * Own and harden Cloudflare ZTNA policies and support transitioning from traditional network-based access model. * Leverage your experience in broader enterprise security domains to ensure our identity strategy is integrated with our CorpSec efforts-device signals from endpoint posture (Fleet/EDR), SaaS security, and vulnerability management into our access controls to drive a unified security posture. * Eliminate manual toil and accelerate delivery by engineering automated solutions-using scripting, no-code tools, or AI-to solve problems at scale rather than manually managing repetitive tasks. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [How Much Does a Software Engineer Make? Realistic Software Engineering Salaries](https://www.wearedevelopers.com/magazine/425-how-much-does-a-software-engineer-make-realistic-software-engineering-salaries) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Highest Paying Tech Companies in Europe](https://www.wearedevelopers.com/magazine/162-highest-paying-tech-companies-in-europe)