> Markdown version of [/jobs/ext/519876-senior-security-engineer-iam](https://www.wearedevelopers.com/jobs/ext/519876-senior-security-engineer-iam). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer, IAM - **Company:** Handshake - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $176,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Systems Engineering, Microsoft Azure, Software as a Service, Cloud Computing, DevOps, Distributed Systems, Identity and Access Management, Python (Programming Language), Node.Js, OAuth, OpenID, Role-Based Access Control, Azure Active Directory, JSON Web Token, Security Assertion Markup Language (SAML), Systems Integration, Google Cloud, Okta, Event Driven Architecture, Data Lineage, Gsuite, Api Design, SailPoint, Restful APIs, Terraform, Webhooks, Workday - **Published:** June 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b8cf90e235b3fa2f ## About the Role Do you have experience in Workday?, * 4-7+ years of hands-on IAM engineering, identity automation, or identity governance experience. * Strong scripting/automation skills in Python, Node.js, and REST-based integrations. * Experience with IAM platforms such as Okta, Google Workspace/GCP, Azure AD, or similar. * Deep understanding of identity protocols, token flows, SCIM, and distributed lifecycle orchestration. * Experience with Terraform or other infrastructure-as-code frameworks. * Ability to diagnose complex identity issues across SaaS, cloud, and distributed systems. * Strong understanding of DevOps practices, observability, and secure engineering principles. * Demonstrated ownership mindset across architecture, implementation, monitoring, and iterative improvement. Extra Credit * Advanced experience with GCP IAM, Google Workspace IAM, AWS IAM, cross-account access patterns, and policy automation. * Experience with Okta Workflows, SailPoint/IGA, or Privileged Access Management (PAM) solutions. * Experience designing scalable authorization models for high-growth or distributed organizations. * Certifications such as Okta Architect, Azure Identity Engineer, CISSP. * Prior experience in SaaS, high-growth, or distributed engineering environments. ## Description For cash compensation, we set standard ranges for all U.S.-based roles based on function, level, and geographic location, benchmarked against similar stage growth companies. In order to be compliant with local legislation, as well as to provide greater transparency to candidates, we share salary ranges on all job postings regardless of desired hiring location. Final offer amounts are determined by multiple factors, including geographic location as well as candidate experience and expertise, and may vary from the amounts listed above., Handshake is seeking a Senior Security Engineer to own the architecture, design, and implementation of our enterprise identity automation and governance ecosystem. You'll define the long-term IAM automation strategy, build resilient and scalable lifecycle workflows, and enable secure-by-default identity operations across SaaS, cloud, and internal platforms. You'll partner closely with Security, IT Engineering, People Operations, and Product/Platform Engineering to deliver highly automated, auditable, and reliable identity solutions. In this role, you will: * Architect, build, and own automated onboarding, offboarding, and access-change workflows across Okta, Workday, SCIM, and event-driven systems. * Engineer integration layers between identity platforms and internal applications using Python, REST APIs, Webhooks, and Terraform. * Implement error-handling, reconciliation logic, telemetry, and monitoring to ensure reliability and determinism in identity lifecycle events. * Modernize existing provisioning logic and replace manual processes with scalable automation frameworks. * Develop tooling and pipelines enabling version-controlled, testable, observable IAM automation. * Act as a technical owner for Handshake's IAM ecosystem, including Okta, Google Workspace, GCP, AWS IAM, and internal access systems. * Engineer and optimize authentication & authorization protocols (OIDC, OAuth2, SAML, JWT), fine-grained access policies, and scalable RBAC/ABAC models. * Build custom automation using Okta Workflows or API-driven orchestration. * Design SOC2-compliant access controls, approvals, attestations, and auditability mechanisms. * Build automated access certification systems with full data lineage. * Conduct identity-related incident forensics and implement preventative automation. * Provide cross-functional leadership, setting standards, best practices, and reference architectures for identity automation. * Serve as service owner for IAM automation platforms with accountability for uptime, consistency, and continuous improvement. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)