
Senior Identity Access Management Engineer
Job description
About the role
Roku is on the lookout for a seasoned Identity Engineer who will play a pivotal role in enhancing our Zero-Trust architecture and leading standardization efforts across our identity management systems. This position is crucial for optimizing our Microsoft-focused identity platform, which supports a globally distributed workforce. The ideal candidate will possess extensive practical experience in identity and access management (IAM), particularly within cloud environments, with a strong emphasis on Azure Entra ID. A key aspect of this role is the ability to automate processes and communicate intricate technical ideas effectively to a variety of audiences.
Key facts
What you'll do
- Spearhead the standardization of identity and access management across the enterprise, focusing on identity lifecycle management, access governance, and policy enforcement in multiple regions around the globe.
- Implement automation solutions within IAM to simplify administrative tasks and enhance the overall user experience.
- Facilitate the onboarding of enterprise applications into Azure Entra ID, which includes managing Single Sign-On (SSO), Conditional Access, and role-based access control (RBAC).
- Improve privileged access management and create scalable solutions for monitoring, alerting, and auditing to ensure a secure environment for our distributed workforce.
- Collaborate with teams in IT, Networking, and Security to address identity-related challenges and support global infrastructure projects.
- Promote the principles of Zero Trust Identity Fabric, which include continuous verification, least-privilege access, and identity-aware policy enforcement across users, devices, workloads, and non-human identities.
- Develop identity automation solutions with a DevOps approach, focusing on scripting, pipeline development, and creating tools from the ground up rather than merely configuring existing ones.
Requirements
- A minimum of 8 years of direct experience in identity and access management, with a strong focus on automating cloud technologies, especially within the Microsoft ecosystem.
- Exceptional analytical capabilities and meticulous attention to detail, coupled with the ability to resolve complex identity and infrastructure-related issues.
- Strong communication skills, enabling the clear explanation of technical concepts to both technical and non-technical stakeholders.
- Extensive experience with Microsoft Entra ID, including its features such as Conditional Access, Identity Governance, and Privileged Identity Management.
- Familiarity with Microsoft 365 services, including Exchange Online, Defender, Purview, Sentinel, Intune, and other related platforms.
- Proficiency in automation and scripting using tools such as PowerShell, Azure CLI, and Microsoft Graph API, along with a working knowledge of Azure services like Function Apps and Logic Apps.
- Proven experience in onboarding and managing enterprise applications within Azure Entra ID.
- Advanced understanding of Azure Single Sign-On (SSO) methods, including OAuth2, OpenID Connect, and SAML, and their integration with enterprise applications.
- Knowledge of privileged access management tools (e.g., Azure PIM, CyberArk), secrets management solutions (e.g., HashiCorp or Azure Key Vault), and workload identity patterns like SPIFEE and SPIRE.
- Familiarity with governance concepts related to service accounts and AI agents, as well as exposure to policy-as-code frameworks such as OPA/Rego.
- Understanding of multi-factor authentication and FIDO2 standards.
- Awareness of IT security frameworks and compliance standards.
- Knowledge of logging, monitoring, and alerting practices related to identity and access events.
- Basic understanding of email security and DNS.
- Experience with backup and recovery strategies for identity services.
- Familiarity with Zero Trust Architecture principles.
- Experience using tools like Jira and Confluence.
- A Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field, or equivalent professional experience.
What's Roku's approach to hybrid working?
At Roku, we cultivate an inclusive and collaborative work environment. Our teams typically work in the office from Monday to Thursday, while Fridays are generally flexible for remote work, with some exceptions for roles that require full-time office attendance.
What are some of the benefits?
Roku is dedicated to providing a comprehensive benefits package that supports our employees and their families. Our offerings include global access to mental health resources and financial wellness support. Local benefits may encompass healthcare options (medical, dental, and vision), life insurance, disability coverage, commuter benefits, and retirement plans (401(k) or pension). We encourage employees to take time off in accordance with local policies to support their work-life balance. Specific benefits may vary by location and role, so candidates are encouraged to consult with their recruiter for details.
Accommodations
Roku is committed to welcoming applicants from diverse backgrounds and provides reasonable accommodations in accordance with applicable laws. If you require assistance during the hiring process, please reach out to EmployeeRelations@Roku.com.
What should I know about Roku's culture?
Roku thrives in a fast-paced environment where the focus is on collective success rather than individual accolades. We value collaboration and surround ourselves with talented individuals who are approachable and grounded. A sense of humor is appreciated, and we believe that a smaller team of highly skilled professionals can achieve more than a larger team with less talent. Our culture emphasizes independent thinking, bold actions, and collaborative problem-solving, all of which contribute to our mission of transforming the way the world experiences television.
To learn more about Roku and our global presence, please visit https://www.weareroku.com/factsheet.