Senior IAM Engineer

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.

ABOUT THE ROLE:

We are looking for a Senior Identity and Access Management (IAM) Engineer to play a critical role in designing, implementing, and maturing our enterprise IAM ecosystem. As a Senior IAM Engineer, you will serve as a key subject matter expert (SME) within the broader Information Security organization, driving secure, scalable, and user-friendly identity solutions in a fast-paced, high-growth environment. You will own complex IAM initiatives end-to-end — from strategy and architecture to implementation and optimization — while collaborating closely with Security, Infrastructure, Application, and Engineering teams. This is a high-impact, hands-on role suited for someone who thrives in ambiguity and takes extreme ownership of outcomes.

RESPONSIBILITIES:

  • Design and implement enterprise-grade IAM solutions across on-prem, cloud, and SaaS environments.
  • Architect and deliver end-to-end federation strategies using modern protocols (SAML, OIDC, OAuth 2.0, SCIM).
  • Lead integration and optimization of key IAM platforms including SailPoint, Okta, PingOne, Microsoft Entra ID, and other tools.
  • Drive Identity Lifecycle Management (LCM), Role-Based Access Control (RBAC), Privileged Access Management (PAM), and Just-In-Time access initiatives.
  • Develop automation scripts and Infrastructure as Code (Terraform) to improve provisioning, governance, and operational efficiency.
  • Serve as the primary IAM SME, providing technical guidance, troubleshooting complex issues, and mentoring other team members.
  • Work closely with InfoSec, Compliance, and Engineering teams to meet audit, regulatory, and security requirements.
  • Continuously improve IAM architecture, processes, and capabilities in a dynamic, fast-moving organization.
  • Support cloud IAM strategies across AWS, GCP, and other platforms.
  • Participate in on-call rotation and incident response related to identity systems.

BASIC QUALIFICATIONS:

  • 6+ years of hands-on experience in Identity and Access Management.
  • Thorough understanding of IAM principles and modern security concepts, including Zero Trust, Least Privilege, Adaptive/Risk-Based Authentication, Attribute-Based Access Control (ABAC), Continuous Access Evaluation, and Identity Threat Detection and Response (ITDR).
  • Strong expertise in IAM protocols and standards: SAML, OIDC, OAuth 2.0, SCIM, and other federation protocols.
  • Strong expertise in IAM and federation protocols, with proven experience in architecting and implementing end-to-end federation solutions.
  • Hands-on experience with major IAM platforms, particularly SailPoint, Okta, PingOne, and Microsoft identity solutions.
  • Strong working knowledge of cloud platforms (AWS and GCP), Cloud IAM services, Terraform, and CI/CD practices.
  • Strong scripting and programming skills in Python and JavaScript/TypeScript, with extensive experience developing IAM workflows, automation, and integrations.
  • Demonstrated ability to lead technical initiatives and drive projects from design through implementation.

This high-visibility role requires the ability to thrive in a fast-paced and ambiguous environment. The ideal candidate demonstrates extreme ownership, a collaborative no-ego mindset, and is comfortable taking the lead. This is a significant opportunity to shape the future of identity and security at the company.

COMPENSATION AND BENEFITS

$100,000 - $258,000 USD

Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.

SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.

What this application asks

greenhouse

First Name, Last Name, Email, Phone, Resume/CV

  • Full Legal Name
  • Full Legal Name in Native Language (e.g. Chinese Characters, Cyrillic, Farsi etc)
  • Current Company optional
  • Current title optional
  • LinkedIn Profile optional
  • GitHub Profile optional
  • Github optional
  • X Profile optional
  • Your Location
  • Please select if you are a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or (v) eligible to obtain the required authorizations from the U.S. Department of State. choose one
  • If working in the US, will you now, or in the future, require sponsorship for employment visa status (e.g., H-1B visa) to legally work in the US? choose one
  • Please indicate your SpaceXAI employment history. choose one
  • What exceptional work have you done? written answer
  • How did you hear about us? choose one
  • Are you located in the US? choose one
  • If you are not currently residing near one of our office locations, are you willing to relocate to support full-time on-site work (5 days per week) in our office? choose one

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available