Staff Security Risk & Compliance Program Manager
confluentRemote (USA)Full Time3w ago
ReactAWSAzureGCPKubernetesAISecurityComplianceOperationsStrategyProgram ManagerEngineering
Job description
Staff Security Risk & Compliance Program Manager
About the role
This senior position focuses on managing Confluent's internal access controls, with a particular emphasis on evolving towards machine and workload identities. You will be instrumental in shaping how the company handles service-to-service authentication, non-human identities, and access for AI agents to enhance least-privilege security for the Confluent Cloud platform.
Key facts
What you'll do
- Guide the strategic direction and roadmap for Confluent's internal access management program, prioritizing machine and workload identity.
- Lead the initiative to formalize non-human identity management and establish access controls for AI agents.
- Own the Access Management Standard, ensuring it aligns with least privilege, separation of duties, and access review policies.
- Define and track key access metrics, managing reporting and executive review cadences.
- Collaborate with engineering, platform, and identity teams to drive cross-functional execution without direct authority.
- Integrate the access management program with other GRC domains and partner teams.
Requirements
- A minimum of 8 years in security program management, identity and access management, or a related security field.
- At least 3 years of experience managing an enterprise or platform-scale access program within a technology company.
- Deep understanding of identity and access management principles including least privilege, separation of duties, RBAC/ABAC, JIT, PAM, and access reviews.
- Familiarity with machine and workload identity concepts, such as service-to-service authentication, non-human identity, service accounts, and secrets management.
- Solid grasp of cloud infrastructure security controls in GCP, AWS, or Azure, including Kubernetes and cloud control plane access.
- Experience with identity platforms and access tooling like Okta.
- Demonstrated ability in project management, organization, and data-driven problem-solving.
- Proven experience running complex security programs that achieve measurable risk reduction.
- Excellent communication and influencing skills, with the ability to present technical information to executive audiences.
Nice to have
- Experience integrating access processes into GRC and access orchestration platforms.
- A preference for automating access decisions over manual processes.
Skills & tools
- Identity and Access Management (IAM)
- Least Privilege
- Separation of Duties
- RBAC/ABAC
- Just-in-Time (JIT) Access
- Privileged Access Management (PAM)
- Access Reviews
- Machine Identity
- Workload Identity
- Service-to-Service (S2S) Authentication
- Non-Human Identity (NHI)
- Service Accounts
- Secrets Management
- AI Agent Access
- GCP, AWS, Azure Security Controls
- Kubernetes Security
- Okta
- GRC Platforms
- Access Orchestration Tools
Practical notes
- Confluent is an IBM subsidiary. By applying, you acknowledge that your information may be shared with IBM affiliates involved in the recruitment process.