Jobs Companies Handshake Senior Security Engineer, IAM

Sobre esta vaga de Senior Security Engineer, IAM na Handshake

Handshake · San Francisco, CA

About Handshake

Handshake was founded on a simple belief that everyone deserves a path to a great career, regardless of where they went to school or who they know. Today, we power 25 million job seekers, 1 million+ employers, and 1,600 educational institutions.

In 2025, we started Handshake AI and built the fastest-growing AI data business in history. We work directly with frontier AI lab researchers to create evaluations, publish benchmarks, and push the boundary of data. We’ve grown from $0 to ~$1B run rate and pay ~$60M to over 30K individuals every month.

Why join Handshake now:

  • Shape how every career evolves in the AI economy, at global scale, with impact your friends, family and peers can see and feel

  • Partner hand-in-hand with world-class AI labs, Fortune 500 partners and the world’s top educational institutions

  • Work together with engineers, scientists, operators, and more from Palantir, Meta, Scale AI, and former YC founders

  • Build a massive, fast-growing business with billions in revenue

About the Role

Handshake is seeking a Senior Security Engineer to own the architecture, design, and implementation of our enterprise identity automation and governance ecosystem. You’ll define the long-term IAM automation strategy, build resilient and scalable lifecycle workflows, and enable secure-by-default identity operations across SaaS, cloud, and internal platforms.
You’ll partner closely with Security, IT Engineering, People Operations, and Product/Platform Engineering to deliver highly automated, auditable, and reliable identity solutions.

In this role, you will:

  • Architect, build, and own automated onboarding, offboarding, and access-change workflows across Okta, Workday, SCIM, and event-driven systems.

  • Engineer integration layers between identity platforms and internal applications using Python, REST APIs, Webhooks, and Terraform.

  • Implement error-handling, reconciliation logic, telemetry, and monitoring to ensure reliability and determinism in identity lifecycle events.

  • Modernize existing provisioning logic and replace manual processes with scalable automation frameworks.

  • Develop tooling and pipelines enabling version-controlled, testable, observable IAM automation.

  • Act as a technical owner for Handshake’s IAM ecosystem, including Okta, Google Workspace, GCP, AWS IAM, and internal access systems.

  • Engineer and optimize authentication & authorization protocols (OIDC, OAuth2, SAML, JWT), fine-grained access policies, and scalable RBAC/ABAC models.

  • Build custom automation using Okta Workflows or API-driven orchestration.

  • Design SOC2-compliant access controls, approvals, attestations, and auditability mechanisms.

  • Build automated access certification systems with full data lineage.

  • Conduct identity-related incident forensics and implement preventative automation.

  • Provide cross-functional leadership, setting standards, best practices, and reference architectures for identity automation.

  • Serve as service owner for IAM automation platforms with accountability for uptime, consistency, and continuous improvement.

Desired Capabilities

  • 4–7+ years of hands-on IAM engineering, identity automation, or identity governance experience.

  • Strong scripting/automation skills in Python, Node.js, and REST-based integrations.

  • Experience with IAM platforms such as Okta, Google Workspace/GCP, Azure AD, or similar.

  • Deep understanding of identity protocols, token flows, SCIM, and distributed lifecycle orchestration.

  • Experience with Terraform or other infrastructure-as-code frameworks.

  • Ability to diagnose complex identity issues across SaaS, cloud, and distributed systems.

  • Strong understanding of DevOps practices, observability, and secure engineering principles.

  • Demonstrated ownership mindset across architecture, implementation, monitoring, and iterative improvement.

Extra Credit

  • Advanced experience with GCP IAM, Google Workspace IAM, AWS IAM, cross-account access patterns, and policy automation.

  • Experience with Okta Workflows, SailPoint/IGA, or Privileged Access Management (PAM) solutions.

  • Experience designing scalable authorization models for high-growth or distributed organizations.

  • Certifications such as Okta Architect, Azure Identity Engineer, CISSP.

  • Prior experience in SaaS, high-growth, or distributed engineering environments.

Perks

Handshake delivers benefits that help you feel supported—and thrive at work and in life.
The below benefits are for full-time US employees.

🎯 Ownership: Equity in a fast-growing company
💰 Financial Wellness: 401(k) match, competitive compensation, financial coaching
🍼 Family Support: Paid parental leave, fertility benefits, parental coaching
💝 Wellbeing: Medical, dental, and vision, mental health support, wellness stipend
📚 Growth: Learning stipend, ongoing development
💻 Remote & Office: Internet, commuting, and free lunch/gym in our SF office
🏝 Time Off: Flexible PTO, 15 holidays + 2 flex days
🤝 Connection: Team outings & referral bonuses

Explore our mission, values, and comprehensive US benefits at joinhandshake.com/careers.

Pronto para se candidatar à Handshake?
Candidatar-se à Handshake

Como este salário de Security Engineer se compara

Esta vaga paga $198,000/yrem linha com da faixa típica para vagas de Security Engineer.

$187,020 a mediana $237,500 $362,500

Faixa típica $197,875–$269,375/yr, com base em 84 vagas de Security Engineer comparáveis na JobsRadar (pagamento anualizado em USD). Ver insights salariais de Security Engineer →

Vagas semelhantes

SA
Security Engineer, Detection & Response
Scale AI
⚡ Candidate-se cedo New York, NY; San Francisco, C... Presencial $237,600–$297,000
● Nova 👁 Vista ✓ Candidatada há 12h
Fastly
Senior Engineer - Security Products (Backend APIs)
Fastly
⚡ Candidate-se cedo San Francisco, CA Híbrido
● Nova 👁 Vista ✓ Candidatada há 19h
Chime Financial, Inc
Product Security Engineer
Chime Financial, Inc
⚡ Candidate-se cedo San Francisco, CA, USA Presencial
● Nova 👁 Vista ✓ Candidatada há 21h
Stripe
Security Engineer
Stripe
⚡ Candidate-se cedo South San Francisco, CA and US... · local restrito $194,251–$268,400
● Nova 👁 Vista ✓ Candidatada há 22h
Figma
Security Engineer
Figma
⚡ Candidate-se cedo San Francisco, CA • New York,... Presencial $153,000–$376,000
● Nova 👁 Vista ✓ Candidatada há 1d
Fluidstack
Information Security Engineer, Bare Metal
Fluidstack
⚡ Candidate-se cedo New York, NY Presencial $269,000–$330,000
● Nova 👁 Vista ✓ Candidatada há 1d
Fluidstack
Security Engineer, Infrastructure
Fluidstack
⚡ Candidate-se cedo New York, NY Presencial $218,000–$252,000
● Nova 👁 Vista ✓ Candidatada há 1d
AN
Lead Security & IT Engineer
Anodize
⚡ Candidate-se cedo San Francisco or Los Altos, CA Presencial
● Nova 👁 Vista ✓ Candidatada há 2d
Block
Principal Security Engineer
Block
⚡ Candidate-se cedo Bay Area, CA, United States of... Presencial $319,000–$478,600
● Nova 👁 Vista ✓ Candidatada há 2d

Cadastre-se para receber sugestões sob medida com base nas vagas que você abre e nas buscas que você salva.

Mais vagas na Handshake

Ver todas as vagas na Handshake →

Candidatar-se agora
🤖

Opa — calma aí

A JobsRadar foi feita para pessoas de verdade passando por um momento difícil na busca por emprego — não para requisições automatizadas. Você está clicando rápido demais e agora está temporariamente bloqueado.

Volte mais tarde. Se você está mesmo procurando emprego, estamos com você — apenas aja como um ser humano.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Ganhe vantagem na sua busca por emprego.

Entre no nosso canal do Telegram para o que ajuda você a conseguir a vaga — referências salariais, o pulso semanal do mercado e avisos de novos recursos. Sem spam, só sinal.

Entre no canal — é grátis