Moveworks
Information Technology And Services
SeniorIdentity&AccessManagementEngineer
“Senior Identity & Access Management Engineer at Moveworks. Skills: Identity and Access Management (IAM), Cloud Infrastructure IAM (AWS, Azure, GCP), SSO administration (Okta), Automation, Security best practices. Drive IAM application development: Code, design, and implement solutions. Drive IAM projects end-to-end: Take ambiguous access problems, understand and have the ability to define requirements, architect solutions, and own the rollout/operationalization”
What You'll Achieve.
Deliver real security impact with minimal friction; Continuously de-risk IAM threats; Enable our engineers to move fast, safely, and confidently; Meet compliance requirements; Improving real security signal
Industry & Context.
Untangling ambiguous access challenges; Architecting secure, automated solutions; Define requirements; Identify high-risk permissions and misuse paths; Propose appropriate controls and mitigations
Some responsibilities in this role involve working with U. S. government customer environments subject to regulatory access requirements. Eligibility may be contingent on the ability to satisfy applicable export control or government contract obligations.
What They're Looking For.
Must Have
5+ years of experience working in IAM, security engineering, or platform engineering with substantial IAM responsibilities in production environments, Grasp of IAM best practices and common failure modes (e.g., least privilege, privilege escalation paths, separation of duties, breakglass, auditability), Practical experience implementing and designing access control in AWS, Azure, GCP environments and partnering with teams who manage infrastructure at scale, Experience with Okta administration and patterns (e.g., groups, app assignments, lifecycle/provisioning), or equivalent experience with a similar SSO product, Ability to spot dangerous permissions and misuse paths (including insider-threat scenarios), assess risk, and identify suitable mitigations and controls, Comfortable using scripting languages and AI coding tools to build reliable automation, and able to read/validate what the code is doing, Working understanding of OAuth, OIDC, SAML, and SCIM, including when to use which, failure modes, and common pitfalls, Proven ability to build long-lasting relationships with various technical teams, such as Engineering, Information Technology, Infrastructure, and DevOps teams
Nice to Have
US Citizenship preferred, Experience configuring IAM in Teleport, Terraform and Kubernetes environments is a plus
What You'll Do.
Drive IAM application development: Code
and implement solutions
Drive IAM projects end-to-end: Take ambiguous access problems
understand and have the ability to define requirements
and own the rollout/operationalization
Develop with secure access models in mind: Continuously develop role design improvements and access assignment patterns across AWS
and internal systems to reduce unnecessary privileges
minimize manual grants
and create scalable “safe baseline” access
Develop on operationalizing logging and metrics: Ensure access changes are observable in our SIEM build repeatable reporting that surfaces risky access and drift
Run and improve user access reviews (UAR): Develop
execute and design a UAR process & solution that meets compliance requirements while improving real security signal—minimizing approver burden through scoping
and clear decision support
Develop technology to continuously de-risk: Identify high-risk permissions and misuse paths
propose appropriate controls and mitigations
drive adoption with partner teams
and develop solutions to continuously de-risk
Operate with security judgment and high signal
Document and standardize the paved road: Write lightweight procedures
and automation so access decisions are consistent
and not dependent on tribal knowledge
How You'll Work.
Team & Collaboration
Partner closely with teams to drive adoption of secure-by-default patterns; Build long-lasting relationships with various technical teams, such as Engineering, Information Technology, Infrastructure, and DevOps teams
Process & Methodology
Own the development of IAM initiatives end-to-end, Own the rollout/operationalization (not just the design)
Applying for this Senior Identity & Access Management Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on SmartRecruiters
- SmartRecruiters often includes a video screening step — check camera and mic permissions.
- Link your GitHub or portfolio directly in the profile section for technical roles.
- Applications may be reviewed by AI scoring before reaching a recruiter — use keywords from the job description.
ANONYMOUS · UNFILTERED
What do employees actually say about Moveworks?
Real rants from real employees. Read before you apply.