Senior Security Engineer, Identity & Access Management
Job description
About the role
You will design and support the end-to-end lifecycle of workforce identity systems at Valon, including identity automation, access management, and least-privilege enforcement across internal systems and infrastructure. You will support the design of secure identity design patterns for product teams building on ValonOS, ensuring every identity, human or machine, is governed consistently and securely. You will manage and evolve Valon's Identity Provider in conjunction with IT, handling SSO integrations, MFA policies, conditional access rules, and directory synchronization to maintain a robust security posture. You will define and enforce RBAC and group-based access policies for internal applications, cloud environments, and development tooling to control access effectively. You will support privileged access management for internal infrastructure in collaboration with Engineering teams, safeguarding critical systems and sensitive operations. You will design and build AI-assisted workflows that automate and accelerate core IAM operations, improving efficiency and reducing manual overhead. You will evaluate AI risks across IAM pipelines, ensuring appropriate security controls around data exposure, prompt injection, and other emerging threats to maintain system integrity. You will collaborate with Product, Engineering, Data, Compliance, Legal, and other teams to identify and drive mitigation for data security risks across the organization. You will support other operational and on-call duties such as vulnerability management, regulatory compliance (SOC 2, CCPA, NYDFS, FTC), policy development, incident response, and security reviews to ensure ongoing protection.
Key facts
What you'll do
- Design and support end-to-end lifecycle of workforce identity systems including identity automation, access management, and least-privilege enforcement across internal systems.
- Support design of secure identity design patterns for product teams building on ValonOS to ensure secure implementation and architecture.
- Manage and evolve Valon's Identity Provider in conjunction with IT, including SSO integrations, MFA policies, conditional access rules, and directory synchronization.
- Define and enforce RBAC and group-based access policies for internal applications, cloud environments, and development tooling.
- Support privileged access management (PAM) for internal infrastructure in conjunction with Engineering teams to protect critical systems.
- Design and build AI-assisted workflows that automate and accelerate core IAM operations, reducing manual effort and improving scalability.
- Evaluate AI risks across IAM pipelines, ensuring appropriate security controls around data exposure, prompt injection, and other AI-related threats.
- Collaborate with Product, Engineering, Data, Compliance, Legal, and other teams to identify and drive mitigation for data security risks across the organization.
- Support vulnerability management activities, including triage, remediation tracking, and ensuring timely resolution of security findings.
- Contribute to the development and maintenance of security policies, standards, and procedures to align with industry best practices.
- Participate in incident response efforts, including identification, containment, eradication, and post-incident analysis to improve resilience.
- Perform security reviews of architecture and configurations to ensure compliance with regulatory requirements such as SOC 2, CCPA, NYDFS, and FTC.
- Engage with external security auditors, pentesting firms, and partners to evaluate Valon's security posture and support continuous improvement.
- Implement and manage identity and access controls within cloud environments, focusing on GCP and other platforms to enforce least privilege.
- Leverage automation and policy-as-code approaches to streamline identity and access management processes and improve operational efficiency.
Requirements
- Extensive hands-on IAM security engineer with proven ownership of enterprise identity solutions, able to operate autonomously, drive complex cross-functional efforts, and influence across teams without direct oversight.
- Deep expertise in modern identity protocols and standards including SAML 2.0, OIDC/OAuth 2.0, SCIM, LDAP, and related specifications to design and implement secure identity flows.
- Proven experience administering and scaling Identity Provider platforms such as Okta, Azure AD / Entra ID, and Google Workspace, including SSO, MFA, conditional access, and directory synchronization.
- Solid background in cloud IAM with a preference for GCP, including service accounts, workload identity federation, and policy-as-code approaches to enforce security at scale.
- Strong expertise in building and managing Privileged Access Management solutions and identity vaults, with a focus on enforcing least-privilege for both human and non-human identities across systems.
- Experience building AI/LLM-powered workflows, ideally within a security or operations context, with a practical understanding of how these tools integrate into secure pipelines.
- Understanding of AI risk evaluation in IAM contexts, including data exposure, prompt injection, and other threats that may arise from AI-assisted operations.
- Demonstrated ability to collaborate effectively with cross-functional stakeholders such as Product, Engineering, Data, Compliance, Legal, and Security to drive security outcomes.
- Knowledge of regulatory compliance relevant to financial services, including SOC 2, CCPA, NYDFS, and FTC requirements, and experience ensuring controls meet these standards.
- Experience working in a fast-paced, mission-critical environment where systems directly support regulated financial services and customer trust is paramount.
- Strong problem-solving skills and the ability to troubleshoot complex identity and access management issues in distributed systems.
- Excellent communication skills, both written and verbal, to articulate technical concepts to both technical and non-technical audiences.
- Commitment to maintaining and improving security best practices, including staying current with evolving threats, tools, and identity standards.
- Willingness to participate in on-call rotations and respond to security incidents, vulnerabilities, and compliance findings as needed.
Nice to have
- Experience with mortgage servicing or regulated financial services is preferred.
- Familiarity with AI security tooling and emerging standards for AI governance in identity and access management.
- Background with policy-as-code frameworks and infrastructure-as-code tools relevant to identity and security operations.
Practical notes
Full-time position; remote work is fully supported.
Office locations include New York City and San Francisco.